X-Git-Url: http://git.polytechnique.org/?a=blobdiff_plain;f=modules%2Fxnetgrp.php;h=5ce2c228482f38e4d9d73ff834b6695357a63d46;hb=b270577e919c58455a3629a4d9d61bd38ea49e11;hp=1b17bf6d6dc41cf359d0d1dca216d394474faa4d;hpb=d24c8a1195dce2641e62477fc4618786d931ebce;p=platal.git diff --git a/modules/xnetgrp.php b/modules/xnetgrp.php index 1b17bf6..5ce2c22 100644 --- a/modules/xnetgrp.php +++ b/modules/xnetgrp.php @@ -1,6 +1,6 @@ asso('id')); - - if ($res->numRows()) { - $user = $res->fetchOneAssoc(); - if ($user['origine'] == 'X') { - $res = XDB::query("SELECT nom, prenom, promo, FIND_IN_SET(flags, 'femme') AS sexe - FROM auth_user_md5 - WHERE user_id = {?}", $user['uid']); - $user = array_merge($user, $res->fetchOneAssoc()); - } - return $user; - } elseif ($dom == 'polytechnique.org' || $dom == 'm4x.org') { - $res = XDB::query( - "SELECT user_id AS uid, u.promo, - IF(u.nom_usage<>'', u.nom_usage, u.nom) AS nom, - u.prenom, b.alias, - CONCAT(b.alias, '@m4x.org') AS email, - CONCAT(b.alias, '@polytechnique.org') AS email2, - m.perms='admin' AS perms, m.origine, - FIND_IN_SET(u.flags, 'femme') AS sexe - FROM auth_user_md5 AS u - INNER JOIN aliases AS a ON ( u.user_id = a.id AND a.type != 'homonyme' ) - INNER JOIN aliases AS b ON ( u.user_id = b.id AND b.type = 'a_vie' ) - INNER JOIN groupex.membres AS m ON ( m.uid = u.user_id AND asso_id={?}) - WHERE a.alias = {?} AND u.user_id < 50000", $globals->asso('id'), $mbox); - return $res->fetchOneAssoc(); - } - - return null; -} - class XnetGrpModule extends PLModule { function handlers() { return array( - '%grp' => $this->make_hook('index', AUTH_PUBLIC), - '%grp/asso.php' => $this->make_hook('index', AUTH_PUBLIC), - '%grp/logo' => $this->make_hook('logo', AUTH_PUBLIC), - '%grp/edit' => $this->make_hook('edit', AUTH_MDP), - '%grp/mail' => $this->make_hook('mail', AUTH_MDP), - '%grp/annuaire' => $this->make_hook('annuaire', AUTH_MDP), - '%grp/annuaire/vcard' => $this->make_hook('vcard', AUTH_MDP), - '%grp/trombi' => $this->make_hook('trombi', AUTH_MDP), - '%grp/subscribe' => $this->make_hook('subscribe', AUTH_MDP), - '%grp/paiement' => $this->make_hook('paiement', AUTH_MDP), - - '%grp/admin/annuaire' - => $this->make_hook('admin_annuaire', AUTH_MDP), - - '%grp/member' - => $this->make_hook('admin_member', AUTH_MDP), - '%grp/member/new' - => $this->make_hook('admin_member_new', AUTH_MDP), - '%grp/member/new/ajax' - => $this->make_hook('admin_member_new_ajax', AUTH_MDP, '', NO_AUTH), - '%grp/member/del' - => $this->make_hook('admin_member_del', AUTH_MDP), - - '%grp/rss' => $this->make_hook('rss', AUTH_PUBLIC), - '%grp/announce/new' => $this->make_hook('edit_announce', AUTH_MDP), - '%grp/announce/edit' => $this->make_hook('edit_announce', AUTH_MDP), - '%grp/admin/announces' => $this->make_hook('admin_announce', AUTH_MDP), + '%grp' => $this->make_hook('index', AUTH_PUBLIC), + '%grp/asso.php' => $this->make_hook('index', AUTH_PUBLIC), + '%grp/logo' => $this->make_hook('logo', AUTH_PUBLIC), + '%grp/site' => $this->make_hook('site', AUTH_PUBLIC), + '%grp/edit' => $this->make_hook('edit', AUTH_MDP, 'groupadmin'), + '%grp/mail' => $this->make_hook('mail', AUTH_MDP, 'groupadmin'), + '%grp/forum' => $this->make_hook('forum', AUTH_MDP, 'groupmember'), + '%grp/annuaire' => $this->make_hook('annuaire', AUTH_MDP, 'groupannu'), + '%grp/annuaire/vcard' => $this->make_hook('vcard', AUTH_MDP, 'groupmember:groupannu'), + '%grp/annuaire/csv' => $this->make_hook('csv', AUTH_MDP, 'groupmember:groupannu'), + '%grp/trombi' => $this->make_hook('trombi', AUTH_MDP, 'groupannu'), + '%grp/geoloc' => $this->make_hook('geoloc', AUTH_MDP, 'groupannu'), + '%grp/subscribe' => $this->make_hook('subscribe', AUTH_MDP), + '%grp/subscribe/valid' => $this->make_hook('subscribe_valid', AUTH_MDP, 'groupadmin'), + '%grp/unsubscribe' => $this->make_hook('unsubscribe', AUTH_MDP, 'groupmember'), + + '%grp/change_rights' => $this->make_hook('change_rights', AUTH_MDP), + '%grp/admin/annuaire' => $this->make_hook('admin_annuaire', AUTH_MDP, 'groupadmin'), + '%grp/member' => $this->make_hook('admin_member', AUTH_MDP, 'groupadmin'), + '%grp/member/new' => $this->make_hook('admin_member_new', AUTH_MDP, 'groupadmin'), + '%grp/member/new/ajax' => $this->make_hook('admin_member_new_ajax', AUTH_MDP, 'user', NO_AUTH), + '%grp/member/del' => $this->make_hook('admin_member_del', AUTH_MDP, 'groupadmin'), + + '%grp/rss' => $this->make_hook('rss', AUTH_PUBLIC, 'user', NO_HTTPS), + '%grp/announce/new' => $this->make_hook('edit_announce', AUTH_MDP, 'groupadmin'), + '%grp/announce/edit' => $this->make_hook('edit_announce', AUTH_MDP, 'groupadmin'), + '%grp/announce/photo' => $this->make_hook('photo_announce', AUTH_PUBLIC), + '%grp/admin/announces' => $this->make_hook('admin_announce', AUTH_MDP, 'groupadmin'), ); } function handler_index(&$page, $arg = null) { global $globals, $platal; - if (!is_null($arg)) { return PL_NOT_FOUND; } - - new_group_open_page('xnet/groupe/asso.tpl'); + $page->changeTpl('xnetgrp/asso.tpl'); if (S::logged()) { if (Env::has('read')) { - XDB::query('DELETE r.* - FROM groupex.announces_read AS r - INNER JOIN groupex.announces AS a ON a.id = r.announce_id - WHERE peremption < CURRENT_DATE()'); - XDB::query('INSERT INTO groupex.announces_read - VALUES ({?}, {?})', + XDB::query('DELETE r.* + FROM group_announces_read AS r + INNER JOIN group_announces AS a ON (a.id = r.announce_id) + WHERE expiration < CURRENT_DATE()'); + XDB::query('INSERT INTO group_announces_read + VALUES ({?}, {?})', Env::i('read'), S::i('uid')); pl_redirect(""); } if (Env::has('unread')) { - XDB::query('DELETE FROM groupex.announces_read - WHERE announce_id={?} AND user_id={?}', + XDB::query('DELETE FROM group_announces_read + WHERE announce_id = {?} AND uid = {?}', Env::i('unread'), S::i('uid')); pl_redirect("#art" . Env::i('unread')); } - $arts = XDB::iterator("SELECT a.*, u.nom, u.prenom, u.promo, l.alias AS forlife - FROM groupex.announces AS a - INNER JOIN auth_user_md5 AS u USING(user_id) - INNER JOIN aliases AS l ON (u.user_id = l.id AND l.type = 'a_vie') - LEFT JOIN groupex.announces_read AS r ON (r.user_id = {?} AND r.announce_id = a.id) - WHERE asso_id = {?} AND peremption >= CURRENT_DATE() - AND (promo_min = 0 OR promo_min <= {?}) - AND (promo_max = 0 OR promo_max >= {?}) - AND r.announce_id IS NULL - ORDER BY a.peremption", - S::i('uid'), $globals->asso('id'), S::i('promo'), S::i('promo')); - $index = XDB::iterator("SELECT a.id, a.titre, r.user_id IS NULL AS nonlu - FROM groupex.announces AS a - LEFT JOIN groupex.announces_read AS r ON (a.id = r.announce_id AND r.user_id = {?}) - WHERE asso_id = {?} AND peremption >= CURRENT_DATE() + // XXX: Fix promo_min; promo_max + $arts = XDB::iterator("SELECT a.*, FIND_IN_SET('photo', a.flags) AS photo + FROM group_announces AS a + LEFT JOIN group_announces_read AS r ON (r.uid = {?} AND r.announce_id = a.id) + WHERE asso_id = {?} AND expiration >= CURRENT_DATE() AND (promo_min = 0 OR promo_min <= {?}) AND (promo_max = 0 OR promo_max >= {?}) - ORDER BY a.peremption", + AND r.announce_id IS NULL + ORDER BY a.expiration", + S::i('uid'), $globals->asso('id'), S::i('promo'), S::i('promo')); + $index = XDB::iterator("SELECT a.id, a.titre, r.uid IS NULL AS nonlu + FROM group_announces AS a + LEFT JOIN group_announces_read AS r ON (a.id = r.announce_id AND r.uid = {?}) + WHERE asso_id = {?} AND expiration >= CURRENT_DATE() + AND (promo_min = 0 OR promo_min <= {?}) + AND (promo_max = 0 OR promo_max >= {?}) + ORDER BY a.expiration", S::i('uid'), $globals->asso('id'), S::i('promo'), S::i('promo')); $page->assign('article_index', $index); } else { - $arts = XDB::iterator("SELECT a.*, u.nom, u.prenom, u.promo - FROM groupex.announces AS a - INNER JOIN auth_user_md5 AS u USING(user_id) - WHERE asso_id = {?} AND peremption >= CURRENT_DATE() - AND FIND_IN_SET(a.flags, 'public')", + $arts = XDB::iterator("SELECT *, FIND_IN_SET('photo', flags) AS photo + FROM group_announces + WHERE asso_id = {?} AND expiration >= CURRENT_DATE() + AND FIND_IN_SET('public', flags)", $globals->asso('id')); } + if (may_update()) { + $subs_valid = XDB::query("SELECT uid + FROM group_member_sub_requests + WHERE asso_id = {?}", + $globals->asso('id')); + $page->assign('requests', $subs_valid->numRows()); + } - if (!S::has('core_rss_hash')) { + if (!S::hasAuthToken()) { $page->setRssLink("Polytechnique.net :: {$globals->asso("nom")} :: News publiques", - "rss/rss.xml"); + $platal->ns . "rss/rss.xml"); } else { $page->setRssLink("Polytechnique.net :: {$globals->asso("nom")} :: News", - 'rss/'.S::v('forlife') .'/'.S::v('core_rss_hash').'/rss.xml'); + $platal->ns . 'rss/'.S::v('hruid') .'/'.S::v('token').'/rss.xml'); } - require_once('url_catcher.inc.php'); - $page->register_modifier('url_catcher', 'url_catcher'); $page->assign('articles', $arts); - - $page->assign('asso', $globals->asso()); } function handler_logo(&$page) { global $globals; + $globals->asso()->getLogo()->send(); + } - $res = XDB::query("SELECT logo, logo_mime - FROM groupex.asso WHERE id = {?}", - $globals->asso('id')); - list($logo, $logo_mime) = $res->fetchOneRow(); - - if (!empty($logo)) { - header("Content-type: $mime"); - header('Expires: Mon, 26 Jul 1997 05:00:00 GMT'); - header('Last-Modified:' . gmdate('D, d M Y H:i:s') . ' GMT'); - header('Cache-Control: no-cache, must-revalidate'); - header('Pragma: no-cache'); - echo $logo; - } else { - header('Content-type: image/jpeg'); - header('Expires: Mon, 26 Jul 1997 05:00:00 GMT'); - header('Last-Modified:' . gmdate('D, d M Y H:i:s') . ' GMT'); - header('Cache-Control: no-cache, must-revalidate'); - header('Pragma: no-cache'); - readfile(dirname(__FILE__).'/../htdocs/images/dflt_carre.jpg'); + function handler_site(&$page) + { + global $globals; + $site = $globals->asso('site'); + if (!$site) { + $page->trigError('Le groupe n\'a pas de site web.'); + return $this->handler_index($page); } - + http_redirect($site); exit; } function handler_edit(&$page) { global $globals; - - new_groupadmin_page('xnet/groupe/edit.tpl'); + $page->changeTpl('xnetgrp/edit.tpl'); if (Post::has('submit')) { + S::assert_xsrf_token(); + + $flags = new PlFlagSet('wiki_desc'); + $flags->addFlag('notif_unsub', Post::i('notif_unsub') == 1); + $site = Post::t('site'); + if ($site && ($site != "http://")) { + $scheme = parse_url($site, PHP_URL_SCHEME); + if (!$scheme) { + $site = "http://" . $site; + } + } else { + $site = ""; + } if (S::has_perms()) { if (Post::v('mail_domain') && (strstr(Post::v('mail_domain'), '.') === false)) { - $page->trig("le domaine doit être un FQDN (aucune modif effectuée) !!!"); + $page->trigError('Le domaine doit être un FQDN (aucune modification effectuée) !!!'); return; } XDB::execute( - "UPDATE groupex.asso + "UPDATE groups SET nom={?}, diminutif={?}, cat={?}, dom={?}, descr={?}, site={?}, mail={?}, resp={?}, forum={?}, mail_domain={?}, ax={?}, pub={?}, - sub_url={?}, inscriptible={?} + sub_url={?}, inscriptible={?}, unsub_url={?}, + flags={?} WHERE id={?}", Post::v('nom'), Post::v('diminutif'), Post::v('cat'), Post::i('dom'), - Post::v('descr'), Post::v('site'), + Post::v('descr'), $site, Post::v('mail'), Post::v('resp'), Post::v('forum'), Post::v('mail_domain'), - Post::has('ax'), Post::has('pub')?'private':'public', + Post::has('ax'), Post::v('pub'), Post::v('sub_url'), Post::v('inscriptible'), - $globals->asso('id')); + Post::v('unsub_url'), $flags, $globals->asso('id')); if (Post::v('mail_domain')) { - XDB::execute('INSERT INTO virtual_domains (domain) VALUES({?})', + XDB::execute('INSERT IGNORE INTO virtual_domains (domain) VALUES({?})', Post::v('mail_domain')); } } else { XDB::execute( - "UPDATE groupex.asso + "UPDATE groups SET descr={?}, site={?}, mail={?}, resp={?}, - forum={?}, ax={?}, pub= {?}, sub_url={?} + forum={?}, pub= {?}, sub_url={?}, + unsub_url={?},flags={?} WHERE id={?}", - Post::v('descr'), Post::v('site'), + Post::v('descr'), $site, Post::v('mail'), Post::v('resp'), - Post::v('forum'), Post::has('ax'), - Post::has('pub')?'private':'public', - Post::v('sub_url'), $globals->asso('id')); + Post::v('forum'), Post::v('pub'), + Post::v('sub_url'), Post::v('unsub_url'), + $flags, $globals->asso('id')); } + if ($_FILES['logo']['name']) { - $logo = file_get_contents($_FILES['logo']['tmp_name']); - $mime = $_FILES['logo']['type']; - XDB::execute('UPDATE groupex.asso - SET logo={?}, logo_mime={?} - WHERE id={?}', $logo, $mime, - $globals->asso('id')); + $upload = PlUpload::get($_FILES['logo'], $globals->asso('id'), 'asso.logo', true); + if (!$upload) { + $page->trigError("Impossible de télécharger le logo."); + } else { + XDB::execute('UPDATE groups + SET logo = {?}, logo_mime = {?} + WHERE id = {?}', $upload->getContents(), $upload->contentType(), + $globals->asso('id')); + $upload->rm(); + } } pl_redirect('../'.Post::v('diminutif', $globals->asso('diminutif')).'/edit'); } - if (S::has_perms()) { - $dom = XDB::iterator('SELECT * FROM groupex.dom ORDER BY nom'); + if (S::admin()) { + $dom = XDB::iterator('SELECT * FROM group_dom ORDER BY nom'); $page->assign('dom', $dom); $page->assign('super', true); } @@ -269,380 +230,349 @@ class XnetGrpModule extends PLModule { global $globals; - new_groupadmin_page('xnet/groupe/mail.tpl'); + $page->changeTpl('xnetgrp/mail.tpl'); $mmlist = new MMList(S::v('uid'), S::v('password'), $globals->asso('mail_domain')); $page->assign('listes', $mmlist->get_lists()); + $page->assign('user', S::user()); + $page->addJsLink('ajax.js'); if (Post::has('send')) { + S::assert_xsrf_token(); $from = Post::v('from'); $sujet = Post::v('sujet'); $body = Post::v('body'); $mls = array_keys(Env::v('ml', array())); + $mbr = array_keys(Env::v('membres', array())); + + $this->load('mail.inc.php'); + set_time_limit(120); + $tos = get_all_redirects($mbr, $mls, $mmlist); - require_once 'xnet/mail.inc.php'; - $tos = get_all_redirects(Post::has('membres'), $mls, $mmlist); - send_xnet_mails($from, $sujet, $body, $tos, Post::v('replyto')); - $page->kill("Mail envoyé !"); + $upload = PlUpload::get($_FILES['uploaded'], S::user()->login(), 'xnet.emails', true); + if (!$upload && @$_FILES['uploaded']['name'] && PlUpload::$lastError != null) { + $page->trigError(PlUpload::$lastError); + return; + } + + send_xnet_mails($from, $sujet, $body, Env::v('wiki'), $tos, Post::v('replyto'), $upload, @$_FILES['uploaded']['name']); + if ($upload) { + $upload->rm(); + } + $page->killSuccess("Email envoyé !"); $page->assign('sent', true); } } - function handler_annuaire(&$page) + function handler_forum(&$page, $group = null, $artid = null) { global $globals; - new_annu_page('xnet/groupe/annuaire.tpl'); - - $sort = Env::v('order'); - switch (Env::v('order')) { - case 'promo' : $group = 'promo'; $tri = 'promo_o DESC, nom, prenom'; break; - case 'promo_inv': $group = 'promo'; $tri = 'promo_o, nom, prenom'; break; - case 'alpha_inv': $group = 'initiale'; $tri = 'nom DESC, prenom DESC, promo'; break; - default : $group = 'initiale'; $tri = 'nom, prenom, promo'; $sort = 'alpha'; + $page->changeTpl('xnetgrp/forum.tpl'); + if (!$globals->asso('forum')) { + return PL_NOT_FOUND; } - $page->assign('sort', $sort); - - if ($group == 'initiale') - $res = XDB::iterRow( - 'SELECT UPPER(SUBSTRING( - IF(m.origine="X", IF(u.nom_usage<>"", u.nom_usage, u.nom),m.nom), - 1, 1)) as letter, COUNT(*) - FROM groupex.membres AS m - LEFT JOIN auth_user_md5 AS u ON ( u.user_id = m.uid ) - WHERE asso_id = {?} - GROUP BY letter - ORDER BY letter', $globals->asso('id')); - else - $res = XDB::iterRow( - 'SELECT IF(m.origine="X",u.promo,"extérieur") AS promo, - COUNT(*), IF(m.origine="X",u.promo,"") AS promo_o - FROM groupex.membres AS m - LEFT JOIN auth_user_md5 AS u ON ( u.user_id = m.uid ) - WHERE asso_id = {?} - GROUP BY promo - ORDER BY promo_o DESC', $globals->asso('id')); - - $alphabet = array(); - $nb_tot = 0; - while (list($char, $nb) = $res->next()) { - $alphabet[] = $char; - $nb_tot += $nb; - if (Env::has($group) && $char == strtoupper(Env::v($group))) { - $tot = $nb; + require_once 'banana/forum.inc.php'; + $get = array(); + get_banana_params($get, $globals->asso('forum'), $group, $artid); + run_banana($page, 'ForumsBanana', $get); + } + + function handler_annuaire(&$page, $action = null, $subaction = null) + { + global $globals; + + if ($action == 'trombi') { + __autoload('userset'); + if ($action == 'trombi') { + $view = new ProfileSet(new UFC_Group($globals->asso('id'))); + } else { + $view = new UserSet(new UFC_Group($globals->asso('id'))); } + $view->addMod('trombi', 'Trombinoscope'); + $view->apply('annuaire', $page, $action, $subaction); + $page->changeTpl('xnetgrp/annuaire.tpl'); + return; } - $page->assign('group', $group); - $page->assign('request_group', Env::v($group)); - $page->assign('only_admin', Env::has('admin')); - $page->assign('alphabet', $alphabet); - $page->assign('nb_tot', $nb_tot); - - $ofs = Env::i('offset'); - $tot = Env::v($group) ? $tot : $nb_tot; - $nbp = intval(($tot-1)/NB_PER_PAGE); - $links = array(); - if ($ofs) { - $links['précédent'] = $ofs-1; - } - for ($i = 0; $i <= $nbp; $i++) { - $links[(string)($i+1)] = $i; - } - if ($ofs < $nbp) { - $links['suivant'] = $ofs+1; + + $page->changeTpl('xnetgrp/annuaire.tpl'); + $sort = Env::s('order', 'directory_name'); + $ofs = Env::i('offset'); + if ($ofs < 0) { + $ofs = 0; } - if (count($links)>1) { - $page->assign('links', $links); + + $sdesc = $sort{0} == '-'; + $sf = $sdesc ? substr($sort, 1) : $sort; + if ($sf == 'promo') { + $se = new UFO_Promo(null, $sdesc); + } else { + $se = new UFO_Name($sf, null, null, $sdesc); } - $ini = ''; - if (Env::has('initiale')) { - $ini = 'AND IF(m.origine="X", - IF(u.nom_usage<>"", u.nom_usage, u.nom), - m.nom) LIKE "'.addslashes(Env::v('initiale')).'%"'; - } elseif (Env::has('promo')) { - $ini = 'AND IF(m.origine="X", u.promo, "extérieur") = "' - .addslashes(Env::v('promo')).'"'; - } elseif (Env::has('admin')) { - $ini = 'AND m.perms = "admin"'; + if (Env::b('admin')) { + $uf = $globals->asso()->getAdminsFilter(null, $se); + } else { + $uf = $globals->asso()->getMembersFilter(null, $se); } + $users = $uf->getUsers(new PlLimit(NB_PER_PAGE, $ofs * NB_PER_PAGE)); + $count = $uf->getTotalCount(); + + $page->assign('pages', floor(($count + NB_PER_PAGE - 1) / NB_PER_PAGE)); + $page->assign('current', $ofs); + $page->assign('order', $sort); + $page->assign('users', $users); + $page->assign('only_admin', Env::b('admin')); + } - $ann = XDB::iterator( - "SELECT IF(m.origine='X',IF(u.nom_usage<>'', u.nom_usage, u.nom) ,m.nom) AS nom, - IF(m.origine='X',u.prenom,m.prenom) AS prenom, - IF(m.origine='X',u.promo,'extérieur') AS promo, - IF(m.origine='X',u.promo,'') AS promo_o, - IF(m.origine='X' AND u.perms != 'pending',a.alias,m.email) AS email, - IF(m.origine='X',FIND_IN_SET('femme', u.flags), m.sexe) AS femme, - m.perms='admin' AS admin, - m.origine='X' AS x, - u.perms!='pending' AS inscrit, - m.uid - FROM groupex.membres AS m - LEFT JOIN auth_user_md5 AS u ON ( u.user_id = m.uid ) - LEFT JOIN aliases AS a ON ( a.id = m.uid AND a.type='a_vie' ) - WHERE m.asso_id = {?} $ini - AND (m.origine = 'ext' OR u.perms != 'pending' OR m.email IS NOT NULL) - ORDER BY $tri - LIMIT {?},{?}", $globals->asso('id'), $ofs*NB_PER_PAGE, NB_PER_PAGE); - $page->assign('ann', $ann); + function handler_trombi(&$page) + { + pl_redirect('annuaire/trombi'); } - function handler_trombi(&$page, $num = 1) + function handler_geoloc(&$page) + { + pl_redirect('annuaire/geoloc'); + } + + function handler_vcard(&$page, $photos = null) { global $globals; - new_annu_page('xnet/groupe/trombi.tpl'); - - $page->assign('urlmainsite', "https://www.polytechnique.org/"); - $trombi = new Trombi(array($this, '_trombi_getlist')); - $trombi->hidePromo(); - $trombi->setAdmin(); - $page->assign_by_ref('trombi', $trombi); + $vcard = new VCard($photos == 'photos', 'Membre du groupe ' . $globals->asso('nom')); + $vcard->addProfiles($globals->asso()->getMembersFilter()->getProfiles()); + $vcard->show(); } - function _trombi_getlist($offset, $limit) + function handler_csv(&$page, $filename = null) { global $globals; - $where = "WHERE m.asso_id= '".addslashes($globals->asso('id'))."'"; - - $res = XDB::query( - "SELECT COUNT(*) - FROM auth_user_md5 AS u - RIGHT JOIN photo AS p ON u.user_id=p.uid - INNER JOIN groupex.membres AS m ON (m.uid = u.user_id) - $where"); - $pnb = $res->fetchOneCell(); - - $res = XDB::query("SELECT promo, user_id, a.alias AS forlife, - IF (nom_usage='', u.nom, nom_usage) AS nom, u.prenom - FROM photo AS p - INNER JOIN auth_user_md5 AS u ON u.user_id=p.uid - INNER JOIN aliases AS a ON ( u.user_id=a.id AND a.type='a_vie' ) - INNER JOIN groupex.membres AS m ON (m.uid = u.user_id) - $where - ORDER BY promo, u.nom, u.prenom LIMIT {?}, {?}", $offset*$limit, $limit); - - return array($pnb, $res->fetchAllAssoc()); + if (is_null($filename)) { + $filename = $globals->asso('diminutif') . '.csv'; + } + $users = $globals->asso()->getMembersFilter(null, new UFO_Name('directory_name'))->getUsers(); + header('Content-Type: text/x-csv; charset=utf-8;'); + header('Pragma: '); + header('Cache-Control: '); + pl_content_headers("text/x-csv"); + $page->changeTpl('xnetgrp/annuaire-csv.tpl', NO_SKIN); + $page->assign('users', $users); } - - function handler_vcard(&$page, $photos = null) + + private function removeSubscriptionRequest($uid) { global $globals; + XDB::execute("DELETE FROM group_member_sub_requests + WHERE asso_id = {?} AND uid = {?}", + $globals->asso('id'), $uid); + } - if (($globals->asso('pub') == 'public' && is_member()) || may_update()) { - $res = XDB::query('SELECT uid - FROM groupex.membres - WHERE asso_id = {?}', $globals->asso('id')); - require_once('vcard.inc.php'); - $vcard = new VCard($res->fetchColumn(), $photos == 'photos', 'Membre du groupe ' . $globals->asso('nom')); - $vcard->do_page($page); - } else { - return PL_NOTALLOWED; + private function validSubscription(User &$user) + { + global $globals; + $this->removeSubscriptionRequest($user->id()); + XDB::execute("INSERT IGNORE INTO group_members (asso_id, uid) + VALUES ({?}, {?})", + $globals->asso('id'), $user->id()); + if (XDB::affectedRows() == 1) { + $mailer = new PlMailer(); + $mailer->addTo($user->forlifeEmail()); + $mailer->setFrom('"' . S::user()->fullName() . '" <' . S::user()->forlifeEmail() . '>'); + $mailer->setSubject('[' . $globals->asso('nom') . '] Demande d\'inscription'); + $message = ($user->isFemale() ? 'Chère' : 'Cher') . " Camarade,\n" + . "\n" + . " Suite à ta demande d'adhésion à " . $globals->asso('nom') . ",\n" + . "j'ai le plaisir de t'annoncer que ton inscription a été validée !\n" + . "\n" + . "Bien cordialement,\n" + . "-- \n" + . S::user()->fullName() . '.'; + $mailer->setTxtBody($message); + $mailer->send(); } } function handler_subscribe(&$page, $u = null) { global $globals; - - new_group_open_page('xnet/groupe/inscrire.tpl'); + $page->changeTpl('xnetgrp/inscrire.tpl'); if (!$globals->asso('inscriptible')) - $page->kill("Il n'est pas possible de s'inscire en ligne à ce " - ."groupe. Essaie de joindre le contact indiqué " - ."sur la page de présentation."); + $page->kill("Il n'est pas possible de s'inscire en ligne à ce " + ."groupe. Essaie de joindre le contact indiqué " + ."sur la page de présentation."); if (!is_null($u) && may_update()) { - $page->assign('u', $u); - $res = XDB::query("SELECT nom, prenom, promo, user_id - FROM auth_user_md5 AS u - INNER JOIN aliases AS al ON (al.id = u.user_id - AND al.type != 'liste') - WHERE al.alias = {?}", $u); - - if (list($nom, $prenom, $promo, $uid) = $res->fetchOneRow()) { - $res = XDB::query("SELECT COUNT(*) - FROM groupex.membres AS m - INNER JOIN aliases AS a ON (m.uid = a.id - AND a.type != 'homonyme') - WHERE a.alias = {?} AND m.asso_id = {?}", - $u, $globals->asso('id')); - $n = $res->fetchOneCell(); - if ($n) { - $page->kill("$prenom $nom est déjà membre du groupe !"); - return; - } - elseif (Env::has('accept')) - { - XDB::execute("INSERT INTO groupex.membres - VALUES ({?}, {?}, 'membre', 'X', NULL, NULL, NULL, NULL, NULL)", - $globals->asso('id'), $uid); - require_once 'diogenes/diogenes.hermes.inc.php'; - $mailer = new HermesMailer(); - $mailer->addTo("$u@polytechnique.org"); - $mailer->setFrom('"'.S::v('prenom').' '.S::v('nom') - .'" <'.S::v('forlife').'@polytechnique.org>'); - $mailer->setSubject('['.$globals->asso('nom').'] Demande d\'inscription'); - $message = "Cher Camarade,\n" - . "\n" - . " Suite à ta demande d'adhésion à ".$globals->asso('nom').",\n" - . "j'ai le plaisir de t'annoncer que ton inscription a été validée !\n" - . "\n" - . "Bien cordialement,\n" - . "{$_SESSION["prenom"]} {$_SESSION["nom"]}."; - $mailer->setTxtBody($message); - $mailer->send(); - $page->kill("$prenom $nom a bien été inscrit"); - } - elseif (Env::has('refuse')) - { - require_once 'diogenes/diogenes.hermes.inc.php'; - $mailer = new HermesMailer(); - $mailer->addTo("$u@polytechnique.org"); - $mailer->setFrom('"'.S::v('prenom').' '.S::v('nom') - .'" <'.S::v('forlife').'@polytechnique.org>'); - $mailer->setSubject('['.$globals->asso('nom').'] Demande d\'inscription annulée'); - $mailer->setTxtBody(Env::v('motif')); - $mailer->send(); - $page->kill("la demande $prenom $nom a bien été refusée"); - } else { - $page->assign('show_form', true); - $page->assign('prenom', $prenom); - $page->assign('nom', $nom); - $page->assign('promo', $promo); - $page->assign('uid', $uid); - } - return; + $user = User::get($u); + if (!$user) { + return PL_NOT_FOUND; + } else { + $page->assign('user', $user); } - return PL_NOT_FOUND; + + // Retrieves the subscription status, and the reason. + $res = XDB::query("SELECT reason + FROM group_member_sub_requests + WHERE asso_id = {?} AND uid = {?}", + $globals->asso('id'), $user->id()); + $reason = ($res->numRows() ? $res->fetchOneCell() : null); + + $res = XDB::query("SELECT COUNT(*) + FROM group_members + WHERE asso_id = {?} AND uid = {?}", + $globals->asso('id'), $user->id()); + $already_member = ($res->fetchOneCell() > 0); + + // Handles the membership request. + if ($already_member) { + $this->removeSubscriptionRequest($user->id()); + $page->kill($user->fullName() . ' est déjà membre du groupe !'); + } elseif (Env::has('accept')) { + S::assert_xsrf_token(); + + $this->validSubscription($user); + pl_redirect("member/" . $user->login()); + } elseif (Env::has('refuse')) { + S::assert_xsrf_token(); + + $this->removeSubscriptionRequest($user->id()); + $mailer = new PlMailer(); + $mailer->addTo($user->forlifeEmail()); + $mailer->setFrom('"' . S::user()->fullName() . '" <' . S::user()->forlifeEmail() . '>'); + $mailer->setSubject('['.$globals->asso('nom').'] Demande d\'inscription annulée'); + $mailer->setTxtBody(Env::v('motif')); + $mailer->send(); + $page->killSuccess("La demande de {$user->fullName()} a bien été refusée."); + } else { + $page->assign('show_form', true); + $page->assign('reason', $reason); + } + return; } if (is_member()) { - $page->kill("tu es déjà membre !"); + $page->kill("Tu es déjà membre !"); + return; + } + + $res = XDB::query("SELECT uid + FROM group_member_sub_requests + WHERE uid = {?} AND asso_id = {?}", + S::i('uid'), $globals->asso('id')); + if ($res->numRows() != 0) { + $page->kill("Tu as déjà demandé ton inscription à ce groupe. Cette demande est actuellement en attente de validation."); return; } if (Post::has('inscrire')) { + S::assert_xsrf_token(); + + XDB::execute("INSERT INTO group_member_sub_requests (asso_id, uid, ts, reason) + VALUES ({?}, {?}, NOW(), {?})", + $globals->asso('id'), S::i('uid'), Post::v('message')); $res = XDB::query('SELECT IF(m.email IS NULL, - CONCAT(al.alias,"@polytechnique.org"), - m.email) - FROM groupex.membres AS m - INNER JOIN aliases AS al ON (al.type = "a_vie" - AND al.id = m.uid) - WHERE perms="admin" AND m.asso_id = {?}', - $globals->asso('id')); + CONCAT(al.alias,"@polytechnique.org"), + m.email) + FROM group_members AS m + INNER JOIN aliases AS al ON (al.type = "a_vie" + AND al.uid = m.uid) + WHERE perms="admin" AND m.asso_id = {?}', + $globals->asso('id')); $emails = $res->fetchColumn(); $to = implode(',', $emails); $append = "\n" . "-- \n" - . "Ce message a été envoyé suite à la demande d'inscription de\n" - . S::v('prenom').' '.S::v('nom').' (X'.S::v('promo').")\n" + . "Ce message a été envoyé suite à la demande d'inscription de\n" + . S::user()->fullName() . ' (X' . S::v('promo') . ")\n" . "Via le site www.polytechnique.net. Tu peux choisir de valider ou\n" . "de refuser sa demande d'inscription depuis la page :\n" - . - "http://www.polytechnique.net/".$globals->asso("diminutif")."/subscribe/" - .S::v('forlife')."\n" + . "http://www.polytechnique.net/" . $globals->asso("diminutif") . "/subscribe/" . S::user()->login() . "\n" . "\n" - . "En cas de problème, contacter l'équipe de Polytechnique.org\n" - . "à l'adresse : support@polytechnique.org\n"; + . "En cas de problème, contacter l'équipe de Polytechnique.org\n" + . "à l'adresse : support@polytechnique.org\n"; if (!$to) { - $to = $globals->asso("mail").", support@polytechnique.org"; + $to = ($globals->asso('mail') != '') ? $globals->asso('mail') . ', ' : ''; + $to .= 'support@polytechnique.org'; $append = "\n-- \nLe groupe ".$globals->asso("nom") - ." n'a pas d'administrateur, l'équipe de" - ." Polytechnique.org a été prévenue et va rapidement" - ." résoudre ce problème.\n"; + ." n'a pas d'administrateur, l'équipe de" + ." Polytechnique.org a été prévenue et va rapidement" + ." résoudre ce problème.\n"; } - require_once 'diogenes/diogenes.hermes.inc.php'; - $mailer = new HermesMailer(); + $mailer = new PlMailer(); $mailer->addTo($to); - $mailer->setFrom('"'.S::v('prenom').' '.S::v('nom') - .'" <'.S::v('forlife').'@polytechnique.org>'); + $mailer->setFrom('"' . S::user()->fullName() . '" <' . S::user()->forlifeEmail() . '>'); $mailer->setSubject('['.$globals->asso('nom').'] Demande d\'inscription'); $mailer->setTxtBody(Post::v('message').$append); $mailer->send(); } } - function handler_paiement(&$page) + function handler_subscribe_valid(&$page) { global $globals; - new_group_page('xnet/groupe/telepaiement.tpl'); - - $res = XDB::query( - "SELECT id, text - FROM {$globals->money->mpay_tprefix}paiements - WHERE asso_id = {?} AND NOT FIND_IN_SET(flags, 'old') - ORDER BY id DESC", $globals->asso('id')); - $tit = $res->fetchAllAssoc(); - $page->assign('titres', $tit); - - $order = Env::v('order', 'timestamp'); - $orders = array('timestamp', 'nom', 'promo', 'montant'); - if (!in_array($order, $orders)) { - $order = 'timestamp'; - } - $inv_order = Env::v('order_inv', 0); - $page->assign('order', $order); - $page->assign('order_inv', !$inv_order); - - if ($order == 'timestamp') { - $inv_order = !$inv_order; - } - - if ($inv_order) { - $inv_order = ' DESC'; - } else { - $inv_order = ''; - } - if ($order == 'montant') { - $order = 'LENGTH(montant) '.$inv_order.', montant'; + if (Post::has('valid')) { + S::assert_xsrf_token(); + $subs = Post::v('subs'); + if (is_array($subs)) { + $users = array(); + foreach ($subs as $hruid => $val) { + if ($val == '1') { + $user = User::get($hruid); + if ($user) { + $this->validSubscription($user); + } + } + } + } } - $orderby = 'ORDER BY '.$order.$inv_order; - if ($order != 'nom') { - $orderby .= ', nom'; $inv_order = ''; - } - $orderby .= ', prenom'.$inv_order; - if ($order != 'timestamp') { - $orderby .= ', timestamp DESC'; - } + $it = XDB::iterator('SELECT s.uid, a.hruid, s.ts AS date + FROM group_member_sub_requests AS s + INNER JOIN accounts AS a ON(s.uid = a.uid) + WHERE s.asso_id = {?} + ORDER BY s.ts', $globals->asso('id')); + $page->changeTpl('xnetgrp/subscribe-valid.tpl'); + $page->assign('valid', $it); + } - if (may_update()) { - $trans = array(); - foreach($tit as $foo) { - $pid = $foo['id']; - $res = XDB::query( - "SELECT IF(u.nom_usage<>'', u.nom_usage, u.nom) AS nom, - u.prenom, u.promo, a.alias, timestamp AS `date`, montant - FROM {$globals->money->mpay_tprefix}transactions AS t - INNER JOIN auth_user_md5 AS u ON ( t.uid = u.user_id ) - INNER JOIN aliases AS a ON ( t.uid = a.id AND a.type='a_vie' ) - WHERE ref = {?} ".$orderby, $pid); - $trans[$pid] = $res->fetchAllAssoc(); - $sum = 0; - foreach ($trans[$pid] as $i => $t) { - $sum += strtr(substr($t['montant'], 0, strpos($t['montant'], 'EUR')), ',', '.'); - } - $trans[$pid][] = array('nom' => 'somme totale', - 'montant' => strtr($sum, '.', ',').' EUR'); + function handler_change_rights(&$page) + { + if (Env::has('right') && (may_update() || S::suid())) { + switch (Env::v('right')) { + case 'admin': + Platal::session()->stopSUID(); + break; + case 'anim': + Platal::session()->doSelfSuid(); + may_update(true); + is_member(true); + break; + case 'member': + Platal::session()->doSelfSuid(); + may_update(false, true); + is_member(true); + break; + case 'logged': + Platal::session()->doSelfSuid(); + may_update(false, true); + is_member(false, true); + break; } - $page->assign('trans', $trans); } + http_redirect($_SERVER['HTTP_REFERER']); } function handler_admin_annuaire(&$page) { global $globals; - require_once 'xnet/mail.inc.php'; - - new_groupadmin_page('xnet/groupe/annuaire-admin.tpl'); - $mmlist = new MMList(S::v('uid'), S::v('password'), - $globals->asso('mail_domain')); + $this->load('mail.inc.php'); + $page->changeTpl('xnetgrp/annuaire-admin.tpl'); + $user = S::user(); + $mmlist = new MMList($user, $globals->asso('mail_domain')); $lists = $mmlist->get_lists(); if (!$lists) $lists = array(); $listes = array_map(create_function('$arr', 'return $arr["list"];'), $lists); @@ -659,16 +589,10 @@ class XnetGrpModule extends PLModule $not_in_group_ext = array(); foreach ($subscribers as $mail) { - $res = XDB::query( - 'SELECT COUNT(*) - FROM groupex.membres AS m - LEFT JOIN auth_user_md5 AS u ON (m.uid=u.user_id AND m.uid<50000) - LEFT JOIN aliases AS a ON (a.id=u.user_id and a.type="a_vie") - WHERE asso_id = {?} AND - (m.email = {?} OR CONCAT(a.alias, "@polytechnique.org") = {?})', - $globals->asso('id'), $mail, $mail); - if ($res->fetchOneCell() == 0) { - if (strstr($mail, '@polytechnique.org') === false) { + $uf = new UserFilter(new PFC_And(new UFC_Group($globals->asso('id')), + new UFC_Email($mail))); + if ($uf->getTotalCount() == 0) { + if (User::isForeignEmailAddress($mail)) { $not_in_group_ext[] = $mail; } else { $not_in_group_x[] = $mail; @@ -685,216 +609,347 @@ class XnetGrpModule extends PLModule { global $globals; - new_groupadmin_page('xnet/groupe/membres-add.tpl'); + $page->changeTpl('xnetgrp/membres-add.tpl'); $page->addJsLink('ajax.js'); if (is_null($email)) { return; + } else { + S::assert_xsrf_token(); } - list(,$fqdn) = explode('@', $email); - $fqdn = strtolower($fqdn); - $x = ($fqdn == 'polytechnique.org' || $fqdn == 'melix.org' || - $fqdn == 'm4x.org' || $fqdn == 'melix.net'); - - if ($x) { - require_once 'user.func.inc.php'; - if ($forlife = get_user_forlife($email)) { - XDB::execute( - 'INSERT INTO groupex.membres (uid,asso_id,origine) - SELECT user_id,{?},"X" - FROM auth_user_md5 AS u - INNER JOIN aliases AS a ON (u.user_id = a.id) - WHERE a.alias={?}', $globals->asso('id'), $forlife); - pl_redirect("member/$email"); - } else { - $page->trig($email." n'est pas un alias polytechnique.org valide"); + if (!User::isForeignEmailAddress($email)) { + $user = User::get($email); + if ($user) { + XDB::execute("REPLACE INTO group_members (uid, asso_id, origine) + VALUES ({?}, {?}, 'X')", + $user->id(), $globals->asso('id')); + pl_redirect("member/" . $user->login()); } } else { if (isvalid_email($email)) { - if (Env::v('x') && Env::has('userid') && Env::i('userid')) { + if (Env::v('x') && Env::i('userid')) { $uid = Env::i('userid'); - $res = XDB::query("SELECT * - FROM auth_user_md5 - WHERE user_id = {?} AND perms = 'pending'", $uid); - if ($res->numRows() == 1) { - XDB::execute('INSERT INTO groupex.membres (uid, asso_id, origine, email) - VALUES ({?}, {?}, "X", {?})', - $uid, $globals->asso('id'), $email); + $user = User::getWithUID($uid); + if ($user && $user->state == 'pending') { if (Env::v('market')) { - $res = XDB::query('SELECT COUNT(*) - FROM register_marketing - WHERE uid={?} AND email={?}', $uid, $email); - if (!$res->fetchOneCell()) { - XDB::execute("INSERT INTO register_marketing (uid,sender,email,date,last,nb,type,hash) - VALUES ({?}, {?}, {?}, NOW(), 0, 0, {?}, '')", - $uid, S::v('uid'), $email, Env::v('market_from')); - require_once('validations.inc.php'); - $req = new MarkReq(S::v('uid'), $uid, $email, Env::v('market_from') == 'user'); - $req->submit(); - } + $market = Marketing::get($uid, $email); + if (!$market) { + $market = new Marketing($uid, $email, 'group', $globals->asso('nom'), + Env::v('market_from'), S::v('uid')); + $market->add(); + } } + XDB::execute('REPLACE INTO group_members (uid, asso_id, origine, email) + VALUES ({?}, {?}, "X", {?})', + $uid, $globals->asso('id'), $email); + $this->removeSubscriptionRequest($uid); pl_redirect("member/$email"); } - $page->trig("Utilisateur invalide"); + $page->trigError("Utilisateur invalide"); } else { - $res = XDB::query('SELECT MAX(uid)+1 FROM groupex.membres'); + $res = XDB::query('SELECT MAX(uid) + 1 FROM group_members'); $uid = max(intval($res->fetchOneCell()), 50001); - XDB::execute('INSERT INTO groupex.membres (uid,asso_id,origine,email) - VALUES({?},{?},"ext",{?})', $uid, - $globals->asso('id'), $email); + XDB::execute('REPLACE INTO group_members (uid, asso_id, origine, email) + VALUES ({?}, {?}, "ext", {?})', + $uid, $globals->asso('id'), $email); pl_redirect("member/$email"); } } else { - $page->trig("« $email » n'est pas une adresse mail valide"); + $page->trigError("« $email Â» n'est pas une adresse email valide."); } } } function handler_admin_member_new_ajax(&$page) { - header('Content-Type: text/html; charset="iso-8859-15"'); - $page->changeTpl('xnet/groupe/membres-new-search.tpl', NO_SKIN); - list($nom, $prenom) = str_replace(array('-', ' ', "'"), '%', array(Env::v('nom'), Env::v('prenom'))); - $where = "perms = 'pending'"; - if (!empty($nom)) { - $where .= " AND nom LIKE '%$nom%'"; - } - if (!empty($prenom)) { - $where .= " AND prenom LIKE '%$prenom%'"; - } - if (preg_match('/^[0-9]{4}$/', Env::v('promo'))) { - $where .= " AND promo = " . Env::i('promo'); - } elseif (Env::has('promo')) { - return; + pl_content_headers("text/html"); + $page->changeTpl('xnetgrp/membres-new-search.tpl', NO_SKIN); + $users = array(); + if (Env::has('login')) { + $user = User::getSilent(Env::t('login')); + if ($user && $user->state != 'pending') { + $users = array($user); + } } - $res = XDB::iterator("SELECT user_id, nom, prenom, promo - FROM auth_user_md5 - WHERE $where"); - if ($res->total() < 30) { - $page->assign("choix", $res); + if (empty($users)) { + list($nom, $prenom) = str_replace(array('-', ' ', "'"), '%', array(Env::t('nom'), Env::t('prenom'))); + $cond = new PFC_And(new PFC_Not(new UFC_Registered())); + if (!empty($nom)) { + $cond->addChild(new UFC_Name(Profile::LASTNAME, $nom, UFC_Name::CONTAINS)); + } + if (!empty($prenom)) { + $cond->addChild(new UFC_Name(Profile::FIRSTNAME, $prenom, UFC_Name::CONTAINS)); + } + if (Env::i('promo')) { + $cond->addChild(new UFC_Promo('=', UserFilter::GRADE_ING, Env::i('promo'))); + } + $uf = new UserFilter($cond); + $users = $uf->getUsers(new PlLimit(30)); + if ($uf->getTotalCount() > 30) { + $page->assign('too_many', true); + $users = array(); + } } + $page->assign('users', $users); } - function handler_admin_member_del(&$page, $user = null) + function unsubscribe(PlUser &$user) { global $globals; + XDB::execute("DELETE FROM group_members + WHERE uid = {?} AND asso_id = {?}", + $user->id(), $globals->asso('id')); + + if ($globals->asso('notif_unsub')) { + $mailer = new PlMailer('xnetgrp/unsubscription-notif.mail.tpl'); + $admins = $globals->asso()->iterAdmins(); + while ($admin = $admins->next()) { + $mailer->addTo($admin); + } + $mailer->assign('group', $globals->asso('nom')); + $mailer->assign('user', $user); + $mailer->assign('selfdone', $user->id() == S::i('uid')); + $mailer->send(); + } + + $domain = $globals->asso('mail_domain'); + if (!$domain) { + return true; + } + + $mmlist = new MMList($user, $domain); + $listes = $mmlist->get_lists($user->forlifeEmail()); - new_groupadmin_page('xnet/groupe/membres-del.tpl'); - $user = get_infos($user); + $may_update = may_update(); + $warning = false; + foreach ($listes as $liste) { + if ($liste['sub'] == 2) { + if ($may_update) { + $mmlist->mass_unsubscribe($liste['list'], Array($user->forlifeEmail())); + } else { + $mmlist->unsubscribe($liste['list']); + } + } elseif ($liste['sub']) { + Platal::page()->trigWarning($user->fullName() . " a une" + ." demande d'inscription en cours sur la" + ." liste {$liste['list']}@ !"); + $warning = true; + } + } + + XDB::execute("DELETE FROM virtual_redirect + USING virtual_redirect + INNER JOIN virtual USING(vid) + WHERE redirect={?} AND alias LIKE {?}", + $user->forlifeEmail(), '%@'.$domain); + return !$warning; + } + + function handler_unsubscribe(&$page) + { + $page->changeTpl('xnetgrp/membres-del.tpl'); + $user = S::user()->id(); if (empty($user)) { return PL_NOT_FOUND; } + $page->assign('self', true); $page->assign('user', $user); if (!Post::has('confirm')) { return; + } else { + S::assert_xsrf_token(); } - XDB::execute( - "DELETE FROM groupex.membres WHERE uid={?} AND asso_id={?}", - $user['uid'], $globals->asso('id')); + if ($this->unsubscribe($user)) { + $page->trigSuccess('Vous avez été désinscrit du groupe avec succès.'); + } else { + $page->trigWarning('Vous avez été désinscrit du groupe, mais des erreurs se sont produites lors des désinscriptions des alias et des listes de diffusion.'); + } + $page->assign('is_member', is_member(true)); + } - // don't unsubscribe email from list if other user use same email - $user_same_email = get_infos($user['email']); + function handler_admin_member_del(&$page, $user = null) + { + $page->changeTpl('xnetgrp/membres-del.tpl'); + $user = User::getSilent($user); + if (empty($user)) { + return PL_NOT_FOUND; + } + $page->assign('user', $user); - if (($domain = $globals->asso('mail_domain')) && empty($user_same_email)) { + if (!Post::has('confirm')) { + return; + } else { + S::assert_xsrf_token(); + } - $mmlist = new MMList(S::v('uid'), S::v('password'), $domain); - $listes = $mmlist->get_lists($user['email2']); + if ($this->unsubscribe($user)) { + $page->trigSuccess("{$user->fullName()} a été désinscrit du groupe !"); + } else { + $page->trigWarning("{$user->fullName()} a été désinscrit du groupe, mais des erreurs subsistent !"); + } + } - foreach ($listes as $liste) { - if ($liste['sub'] == 2) { - $mmlist->mass_unsubscribe($liste['list'], Array($user['email2'])); - $page->trig("{$user['prenom']} {$user['nom']} a été" - ." désinscrit de {$liste['list']}"); - } elseif ($liste['sub']) { - $page->trig("{$user['prenom']} {$user['nom']} a une" - ." demande d'inscription en cours sur la" - ." liste {$liste['list']}@ !"); - } + private function changeLogin(PlPage &$page, PlUser &$user, MMList &$mmlist, $login) + { + // Search the uid of the user... + $res = XDB::query("SELECT f.uid, f.alias + FROM aliases AS a + INNER JOIN aliases AS f ON (f.uid = a.uid AND f.type = 'a_vie') + WHERE a.alias = {?}", + $login); + if ($res->numRows() == 0) { + $accounts = User::getPendingAccounts($login); + if (!$accounts) { + $page->trigError("L'identifiant $login ne correspond à aucun X."); + return false; + } else if (count($accounts) > 1) { + $page->trigError("L'identifiant $login correspond à plusieurs camarades."); + return false; } + $uid = $accounts[0]['uid']; + $sub = false; + } else { + list($uid, $login) = $res->fetchOneRow(); + $sub = true; + } - XDB::execute( - "DELETE FROM virtual_redirect - USING virtual_redirect - INNER JOIN virtual USING(vid) - WHERE redirect={?} AND alias LIKE {?}", $user['email'], '%@'.$domain); - if (mysql_affected_rows()) { - $page->trig("{$user['prenom']} {$user['nom']} a été désabonné des alias du groupe !"); - } + // Check if the user is already in the group + global $globals; + $res = XDB::query("SELECT uid, email + FROM group_members + WHERE uid = {?} AND asso_id = {?}", + $uid, $globals->asso('id')); + if ($res->numRows()) { + list($uid, $email) = $res->fetchOneRow(); + XDB::execute("DELETE FROM group_members + WHERE uid = {?}", + $user['uid']); + } else { + $email = $user['email']; + XDB::execute("UPDATE group_members + SET uid = {?}, origine = 'X' + WHERE uid = {?} AND asso_id = {?}", + $uid, $user['uid'], $globals->asso('id')); + } + if ($sub) { + $email = $login . '@' . $globals->mail->domain; } - $page->trig("{$user['prenom']} {$user['nom']} a été retiré du groupe !"); + // Update subscription to aliases + if ($email != $user['email']) { + XDB::execute("UPDATE IGNORE virtual_redirect AS vr + INNER JOIN virtual AS v ON(vr.vid = v.vid AND SUBSTRING_INDEX(alias, '@', -1) = {?}) + SET vr.redirect = {?} + WHERE vr.redirect = {?}", + $globals->asso('mail_domain'), $email, $user['email']); + XDB::execute("DELETE vr.* + FROM virtual_redirect AS vr + INNER JOIN virtual AS v ON(vr.vid = v.vid AND SUBSTRING_INDEX(alias, '@', -1) = {?}) + WHERE vr.redirect = {?}", + $globals->asso('mail_domain'), $user['email']); + foreach (Env::v('ml1', array()) as $ml => $state) { + $mmlist->replace_email($ml, $user['email'], $email); + } + } + if ($sub) { + return $login; + } + return $user['email']; } function handler_admin_member(&$page, $user) { global $globals; - new_groupadmin_page('xnet/groupe/membres-edit.tpl'); + $page->changeTpl('xnetgrp/membres-edit.tpl'); - $user = get_infos($user); + $user = User::getSilent($user); if (empty($user)) { return PL_NOT_FOUND; } - $mmlist = new MMList(S::v('uid'), S::v('password'), - $globals->asso('mail_domain')); + $mmlist = new MMList($user, $globals->asso('mail_domain')); if (Post::has('change')) { + S::assert_xsrf_token(); + + // Convert user status to X + if (Post::blank('login_X')) { + // TODO: Rewrite changeLogin!!! + $forlife = $this->changeLogin($page, $user, $mmlist, Post::t('login_X')); + if ($forlife) { + pl_redirect('member/' . $forlife); + } + } + + // Update user info $email_changed = ($user['origine'] != 'X' && strtolower($user['email']) != strtolower(Post::v('email'))); $from_email = $user['email']; if ($user['origine'] != 'X') { - XDB::query('UPDATE groupex.membres - SET prenom={?}, nom={?}, email={?}, sexe={?} - WHERE uid={?} AND asso_id={?}', - Post::v('prenom'), Post::v('nom'), - Post::v('email'), Post::v('sexe'), + $user['nom'] = Post::v('nom'); + $user['prenom'] = (Post::v('origine') == 'ext') ? Post::v('prenom') : ''; + $user['sexe'] = (Post::v('origine') == 'ext') ? Post::v('sexe') : 0; + $user['origine'] = Post::v('origine'); + XDB::query('UPDATE group_members + SET prenom = {?}, nom = {?}, email = {?}, sexe = {?}, origine = {?} + WHERE uid = {?} AND asso_id = {?}', + $user['prenom'], $user['nom'], Post::v('email'), + $user['sexe'], $user['origine'], $user['uid'], $globals->asso('id')); - $user['nom'] = Post::v('nom'); - $user['prenom'] = Post::v('prenom'); - $user['sexe'] = Post::v('sexe'); - $user['email'] = Post::v('email'); - $user['email2'] = Post::v('email'); + $user['email'] = Post::v('email'); + $user['email2'] = Post::v('email'); + $page->trigSuccess('Données de l\'utilisateur mise à jour.'); } $perms = Post::i('is_admin'); - if ($user['perms'] != $perms) { - XDB::query('UPDATE groupex.membres SET perms={?} - WHERE uid={?} AND asso_id={?}', - $perms ? 'admin' : 'membre', + $comm = Post::t('comm'); + if ($user['perms'] != $perms || $user['comm'] != $comm) { + XDB::query('UPDATE group_members + SET perms = {?}, comm = {?} + WHERE uid = {?} AND asso_id = {?}', + $perms ? 'admin' : 'membre', $comm, $user['uid'], $globals->asso('id')); + if ($perms != $user['perms']) { + $page->trigSuccess('Permissions modifiées !'); + } + if ($comm != $user['comm']) { + $page->trigSuccess('Commentaire mis à jour.'); + } $user['perms'] = $perms; - $page->trig('permissions modifiées'); + $user['comm'] = $comm; } + // Update ML subscriptions foreach (Env::v('ml1', array()) as $ml => $state) { $ask = empty($_REQUEST['ml2'][$ml]) ? 0 : 2; if ($ask == $state) { - if ($state) { + if ($state && $email_changed) { $mmlist->replace_email($ml, $from_email, $user['email2']); - $page->trig("L'abonnement de {$user['prenom']} {$user['nom']} à $ml@ a été mis à jour"); + $page->trigSuccess("L'abonnement de {$user['prenom']} {$user['nom']} à $ml@ a été mis à jour."); } continue; } if ($state == '1') { - $page->trig("{$user['prenom']} {$user['nom']} a " + $page->trigWarning("{$user['prenom']} {$user['nom']} a " ."actuellement une demande d'inscription en " ."cours sur $ml@ !!!"); } elseif ($ask) { $mmlist->mass_subscribe($ml, Array($user['email2'])); - $page->trig("{$user['prenom']} {$user['nom']} a été abonné à $ml@"); + $page->trigSuccess("{$user['prenom']} {$user['nom']} a été abonné à $ml@."); } else { if ($email_changed) { $mmlist->mass_unsubscribe($ml, Array($from_email)); } else { $mmlist->mass_unsubscribe($ml, Array($user['email2'])); } - $page->trig("{$user['prenom']} {$user['nom']} a été désabonné de $ml@"); + $page->trigSuccess("{$user['prenom']} {$user['nom']} a été désabonné de $ml@."); } } + // Change subscriptioin to aliases foreach (Env::v('ml3', array()) as $ml => $state) { $ask = !empty($_REQUEST['ml4'][$ml]); if($state == $ask) continue; @@ -902,66 +957,88 @@ class XnetGrpModule extends PLModule XDB::query("INSERT INTO virtual_redirect (vid,redirect) SELECT vid,{?} FROM virtual WHERE alias={?}", $user['email'], $ml); - $page->trig("{$user['prenom']} {$user['nom']} a été abonné à $ml"); + $page->trigSuccess("{$user['prenom']} {$user['nom']} a été abonné à $ml."); } else { XDB::query("DELETE FROM virtual_redirect USING virtual_redirect INNER JOIN virtual USING(vid) WHERE redirect={?} AND alias={?}", $user['email'], $ml); - $page->trig("{$user['prenom']} {$user['nom']} a été désabonné de $ml"); + $page->trigSuccess("{$user['prenom']} {$user['nom']} a été désabonné de $ml."); } } } $page->assign('user', $user); - $listes = $mmlist->get_lists($user['email2']); - $page->assign('listes', $listes); - - $res = XDB::query( - 'SELECT alias, redirect IS NOT NULL as sub - FROM virtual AS v - LEFT JOIN virtual_redirect AS vr ON(v.vid=vr.vid AND redirect={?}) - WHERE alias LIKE {?} AND type="user"', - $user['email'], '%@'.$globals->asso('mail_domain')); - $page->assign('alias', $res->fetchAllAssoc()); + $page->assign('listes', $mmlist->get_lists($user->forlifeEmail())); + $page->assign('alias', $user->emailAliases($globals->asso('mail_domain'), 'user', true)); } function handler_rss(&$page, $user = null, $hash = null) { global $globals; - require_once('rss.inc.php'); - require_once('url_catcher.inc.php'); - $uid = init_rss('xnet/groupe/announce-rss.tpl', $user, $hash, false); - $page->register_modifier('url_catcher', 'url_catcher'); - - if ($uid) { - $rss = XDB::iterator("SELECT a.id, a.titre, a.texte, a.contacts, a.create_date, - IF(u2.nom_usage != '', u2.nom_usage, u2.nom) AS nom, u2.prenom, u2.promo - FROM auth_user_md5 AS u - INNER JOIN groupex.announces AS a ON ( (a.promo_min = 0 OR a.promo_min <= u.promo) - AND (a.promo_max = 0 OR a.promo_max <= u.promo)) - INNER JOIN auth_user_md5 AS u2 ON (u2.user_id = a.user_id) - WHERE u.user_id = {?} AND peremption >= NOW()", $uid); + $page->assign('asso', $globals->asso()); + + $this->load('feed.inc.php'); + $feed = new XnetGrpEventFeed(); + return $feed->run($page, $user, $hash, false); + } + + private function upload_image(PlPage &$page, PlUpload &$upload) + { + if (@!$_FILES['image']['tmp_name'] && !Env::v('image_url')) { + return true; + } + if (!$upload->upload($_FILES['image']) && !$upload->download(Env::v('image_url'))) { + $page->trigError('Impossible de télécharger l\'image'); + return false; + } elseif (!$upload->isType('image')) { + $page->trigError('Le fichier n\'est pas une image valide au format JPEG, GIF ou PNG.'); + $upload->rm(); + return false; + } elseif (!$upload->resizeImage(200, 300, 100, 100, 32284)) { + $page->trigError('Impossible de retraiter l\'image'); + return false; + } + return true; + } + + function handler_photo_announce(&$page, $eid = null) { + if ($eid) { + $res = XDB::query('SELECT * + FROM group_announces_photo + WHERE eid = {?}', $eid); + if ($res->numRows()) { + $photo = $res->fetchOneAssoc(); + pl_cached_dynamic_content_headers("image/" . $photo['attachmime']); + echo $photo['attach']; + exit; + } } else { - $rss = XDB::iterator("SELECT a.id, a.titre, a.texte, a.create_date, - IF(u.nom_usage != '', u.nom_usage, u.nom) AS nom, u.prenom, u.promo - FROM groupex.announces AS a - INNER JOIN auth_user_md5 AS u USING(user_id) - WHERE FIND_IN_SET(a.flags, 'public') AND peremption >= NOW()"); + $upload = new PlUpload(S::user()->login(), 'xnetannounce'); + if ($upload->exists() && $upload->isType('image')) { + pl_cached_dynamic_content_headers($upload->contentType()); + echo $upload->getContents(); + exit; + } } - $page->assign('asso', $globals->asso()); - $page->assign('rss', $rss); + global $globals; + pl_cached_dynamic_content_headers("image/png"); + echo file_get_contents($globals->spoolroot . '/htdocs/images/logo.png'); + exit; } function handler_edit_announce(&$page, $aid = null) { global $globals, $platal; - new_groupadmin_page('xnet/groupe/announce-edit.tpl'); + $page->changeTpl('xnetgrp/announce-edit.tpl'); $page->assign('new', is_null($aid)); $art = array(); - if (Post::v('valid') == 'Visualiser' || Post::v('valid') == 'Enregistrer') { + if (Post::v('valid') == 'Visualiser' || Post::v('valid') == 'Enregistrer' + || Post::v('valid') == 'Supprimer l\'image' || Post::v('valid') == 'Pas d\'image') { + S::assert_xsrf_token(); + if (!is_null($aid)) { $art['id'] = $aid; } @@ -973,12 +1050,14 @@ class XnetGrpModule extends PLModule $art['nom'] = S::v('nom'); $art['prenom'] = S::v('prenom'); $art['promo'] = S::v('promo'); - $art['forlife'] = S::v('forlife'); - $art['peremption'] = Post::v('peremption'); + $art['hruid'] = S::user()->login(); + $art['expiration'] = Post::v('expiration'); $art['public'] = Post::has('public'); $art['xorg'] = Post::has('xorg'); $art['nl'] = Post::has('nl'); $art['event'] = Post::v('event'); + $upload = new PlUpload(S::user()->login(), 'xnetannounce'); + $this->upload_image($page, $upload); $art['contact_html'] = $art['contacts']; if ($art['event']) { @@ -986,120 +1065,153 @@ class XnetGrpModule extends PLModule } if (!$art['public'] && - ($art['promo_min'] > $art['promo_max'] || + (($art['promo_min'] > $art['promo_max'] && $art['promo_max'] != 0) || ($art['promo_min'] != 0 && ($art['promo_min'] <= 1900 || $art['promo_min'] >= 2020)) || ($art['promo_max'] != 0 && ($art['promo_max'] <= 1900 || $art['promo_max'] >= 2020)))) { - $page->trig("L'intervalle de promotions est invalide"); + $page->trigError("L'intervalle de promotions est invalide."); + Post::kill('valid'); + } + + if (!trim($art['titre']) || !trim($art['texte'])) { + $page->trigError("L'article doit avoir un titre et un contenu."); + Post::kill('valid'); + } + + if (Post::v('valid') == 'Supprimer l\'image') { + $upload->rm(); Post::kill('valid'); } + $art['photo'] = $upload->exists() || Post::i('photo'); + if (Post::v('valid') == 'Pas d\'image' && !is_null($aid)) { + XDB::query('DELETE FROM group_announces_photo + WHERE eid = {?}', $aid); + $upload->rm(); + Post::kill('valid'); + $art['photo'] = false; + } } if (Post::v('valid') == 'Enregistrer') { $promo_min = ($art['public'] ? 0 : $art['promo_min']); $promo_max = ($art['public'] ? 0 : $art['promo_max']); + $flags = new PlFlagSet(); + if ($art['public']) { + $flags->addFlag('public'); + } + if ($art['photo']) { + $flags->addFlag('photo'); + } if (is_null($aid)) { - XDB::query("INSERT INTO groupex.announces - (user_id, asso_id, create_date, titre, texte, contacts, - peremption, promo_min, promo_max, flags) - VALUES ({?}, {?}, NOW(), {?}, {?}, {?}, {?}, {?}, {?}, {?})", + $fulltext = $art['texte']; + if (!empty($art['contact_html'])) { + $fulltext .= "\n\n'''Contacts :'''\\\\\n" . $art['contact_html']; + } + $post = null;/* + if ($globals->asso('forum')) { + require_once 'banana/forum.inc.php'; + $banana = new ForumsBanana(S::user()); + $post = $banana->post($globals->asso('forum'), null, + $art['titre'], MiniWiki::wikiToText($fulltext, false, 0, 80)); + }*/ + XDB::query('INSERT INTO group_announces (uid, asso_id, create_date, titre, texte, contacts, + expiration, promo_min, promo_max, flags, post_id) + VALUES ({?}, {?}, NOW(), {?}, {?}, {?}, {?}, {?}, {?}, {?}, {?})', S::i('uid'), $globals->asso('id'), $art['titre'], $art['texte'], $art['contact_html'], - $art['peremption'], $promo_min, $promo_max, $art['public'] ? 'public' : ''); + $art['expiration'], $promo_min, $promo_max, $flags, $post); $aid = XDB::insertId(); + if ($art['photo']) { + list($imgx, $imgy, $imgtype) = $upload->imageInfo(); + XDB::execute('INSERT INTO group_announces_photo + SET eid = {?}, attachmime = {?}, x = {?}, y = {?}, attach = {?}', + $aid, $imgtype, $imgx, $imgy, $upload->getContents()); + } if ($art['xorg']) { require_once('validations.inc.php'); - require_once('url_catcher.inc.php'); - $article = new EvtReq("[{$globals->asso('nom')}] " . $art['titre'], - url_catcher($art['texte'] . (!empty($art['contact_html']) ? "\n\nContacts :\n" . $art['contact_html'] : "")), - $art['promo_min'], $art['promo_max'], $art['peremption'], "", S::v('uid')); + $article = new EvtReq("[{$globals->asso('nom')}] " . $art['titre'], $fulltext, + $art['promo_min'], $art['promo_max'], $art['expiration'], "", S::user(), + $upload); $article->submit(); - $page->trig("L'affichage sur la page d'accueil de Polytechnique.org est en attente de validation"); + $page->trigWarning("L'affichage sur la page d'accueil de Polytechnique.org est en attente de validation."); + } else if ($upload && $upload->exists()) { + $upload->rm(); } if ($art['nl']) { require_once('validations.inc.php'); - $article = new NLReq(S::v('uid'), $globals->asso('nom') . " : " .$art['titre'], + $article = new NLReq(S::user(), $globals->asso('nom') . " : " .$art['titre'], $art['texte'], $art['contact_html']); $article->submit(); - $page->trig("La parution dans la Lettre Mensuelle est en attente de validation"); + $page->trigWarning("La parution dans la Lettre Mensuelle est en attente de validation."); } } else { - XDB::query("UPDATE groupex.announces - SET titre={?}, texte={?}, contacts={?}, peremption={?}, - promo_min={?}, promo_max={?}, flags={?} - WHERE id={?} AND asso_id={?}", - $art['titre'], $art['texte'], $art['contacts'], $art['peremption'], - $promo_min, $promo_max, $art['public'] ? 'public' : '', + XDB::query('UPDATE group_announces + SET titre = {?}, texte = {?}, contacts = {?}, expiration = {?}, + promo_min = {?}, promo_max = {?}, flags = {?} + WHERE id = {?} AND asso_id = {?}', + $art['titre'], $art['texte'], $art['contacts'], $art['expiration'], + $promo_min, $promo_max, $flags, $art['id'], $globals->asso('id')); + if ($art['photo'] && $upload->exists()) { + list($imgx, $imgy, $imgtype) = $upload->imageInfo(); + XDB::execute("REPLACE INTO group_announces_photo + SET eid = {?}, attachmime = {?}, x = {?}, y = {?}, attach = {?}", + $aid, $imgtype, $imgx, $imgy, $upload->getContents()); + $upload->rm(); + } } } if (Post::v('valid') == 'Enregistrer' || Post::v('valid') == 'Annuler') { pl_redirect(""); - } + } if (empty($art) && !is_null($aid)) { - $res = XDB::query("SELECT a.*, u.nom, u.prenom, u.promo, l.alias AS forlife, - FIND_IN_SET(a.flags, 'public') AS public - FROM groupex.announces AS a - INNER JOIN auth_user_md5 AS u USING(user_id) - INNER JOIN aliases AS l ON (l.id = u.user_id AND l.type = 'a_vie') - WHERE asso_id = {?} AND a.id = {?}", + $res = XDB::query("SELECT *, FIND_IN_SET('public', flags) AS public, + FIND_IN_SET('photo', flags) AS photo + FROM group_announces + WHERE asso_id = {?} AND id = {?}", $globals->asso('id'), $aid); if ($res->numRows()) { $art = $res->fetchOneAssoc(); $art['contact_html'] = $art['contacts']; } else { - $page->kill("Aucun article correspond à l'identifiant indiqué"); - } - } - - $select = ''; - for ($i = 1 ; $i < 30 ; $i++) { - $time = time() + 3600 * 24 * $i; - $p_stamp = date('Ymd', $time); - $year = date('Y', $time); - $month = date('m', $time); - $day = date('d', $time); - - $select .= "\n"; } - $page->assign('select', $select); if (is_null($aid)) { $events = XDB::iterator("SELECT * - FROM groupex.evenements + FROM group_events WHERE asso_id = {?} AND archive = 0", $globals->asso('id')); if ($events->total()) { $page->assign('events', $events); } - } + } - require_once('url_catcher.inc.php'); - $art['contact_html'] = url_catcher($art['contact_html']); + $art['contact_html'] = @MiniWiki::WikiToHTML($art['contact_html']); $page->assign('art', $art); + $page->assign_by_ref('upload', $upload); } function handler_admin_announce(&$page) { global $globals; - new_groupadmin_page('xnet/groupe/announce-admin.tpl'); + $page->changeTpl('xnetgrp/announce-admin.tpl'); if (Env::has('del')) { - XDB::execute("DELETE FROM groupex.announces - WHERE id = {?} AND asso_id = {?}", + S::assert_xsrf_token(); + XDB::execute('DELETE FROM group_announces + WHERE id = {?} AND asso_id = {?}', Env::i('del'), $globals->asso('id')); } - $res = XDB::iterator("SELECT a.id, a.titre, a.peremption, a.peremption < CURRENT_DATE() AS perime - FROM groupex.announces AS a - WHERE a.asso_id = {?} - ORDER BY a.peremption DESC", + $res = XDB::iterator('SELECT id, titre, expiration, expiration < CURRENT_DATE() AS perime + FROM group_announces + WHERE asso_id = {?} + ORDER BY expiration DESC', $globals->asso('id')); $page->assign('articles', $res); } } +// vim:set et sw=4 sts=4 sws=4 foldmethod=marker enc=utf-8: ?>