OSDN Git Service

fixed url
[nucleus-jp/nucleus-jp-ancient.git] / nucleus / libs / ACTION.php
1 <?php\r
2 \r
3 /*\r
4  * Nucleus: PHP/MySQL Weblog CMS (http://nucleuscms.org/)\r
5  * Copyright (C) 2002-2005 The Nucleus Group\r
6  *\r
7  * This program is free software; you can redistribute it and/or\r
8  * modify it under the terms of the GNU General Public License\r
9  * as published by the Free Software Foundation; either version 2\r
10  * of the License, or (at your option) any later version.\r
11  * (see nucleus/documentation/index.html#license for more info)\r
12  */\r
13 /**\r
14  * Actions that can be called via action.php\r
15  *\r
16  * @license http://nucleuscms.org/license.txt GNU General Public License\r
17  * @copyright Copyright (C) 2002-2005 The Nucleus Group\r
18  * @version $Id: ACTION.php,v 1.3 2005-08-13 07:30:01 kimitake Exp $\r
19  * $NucleusJP: ACTION.php,v 1.2 2005/03/12 06:19:04 kimitake Exp $\r
20  */\r
21 class ACTION\r
22 {\r
23         function ACTION()\r
24         {\r
25         \r
26         }\r
27         \r
28         function doAction($action) \r
29         {\r
30                 switch($action) {\r
31                         case 'addcomment':\r
32                                 return $this->addComment();\r
33                                 break;\r
34                         case 'sendmessage':\r
35                                 return $this->sendMessage();\r
36                                 break;\r
37                         case 'createaccount':\r
38                                 return $this->createAccount();\r
39                                 break;          \r
40                         case 'forgotpassword':\r
41                                 return $this->forgotPassword();\r
42                                 break;\r
43                         case 'votepositive':\r
44                                 return $this->doKarma('pos');\r
45                                 break;\r
46                         case 'votenegative':\r
47                                 return $this->doKarma('neg');\r
48                                 break;\r
49                         case 'plugin':\r
50                                 return $this->callPlugin();\r
51                                 break;\r
52                         default:\r
53                                 doError(_ERROR_BADACTION);\r
54                 }\r
55         }\r
56         \r
57         function addComment() {\r
58                 global $CONF, $errormessage, $manager;\r
59 \r
60                 $post['itemid'] =       intPostVar('itemid');\r
61                 $post['user'] =         postVar('user');\r
62                 $post['userid'] =       postVar('userid');\r
63                 $post['body'] =         postVar('body');\r
64 \r
65                 // set cookies when required\r
66                 $remember = intPostVar('remember');\r
67                 if ($remember == 1) {\r
68                         $lifetime = time()+2592000;\r
69                         setcookie($CONF['CookiePrefix'] . 'comment_user',$post['user'],$lifetime,'/','',0);\r
70                         setcookie($CONF['CookiePrefix'] . 'comment_userid', $post['userid'],$lifetime,'/','',0);\r
71                 }\r
72 \r
73                 $comments = new COMMENTS($post['itemid']);\r
74 \r
75                 $blogid = getBlogIDFromItemID($post['itemid']);\r
76                 $this->checkban($blogid);\r
77                 $blog =& $manager->getBlog($blogid);\r
78 \r
79                 // note: PreAddComment and PostAddComment gets called somewhere inside addComment\r
80                 $errormessage = $comments->addComment($blog->getCorrectTime(),$post);\r
81 \r
82                 if ($errormessage == '1') {             \r
83                         // redirect when adding comments succeeded\r
84                         if (postVar('url')) {\r
85                                 redirect(postVar('url'));\r
86                         } else {\r
87                                 $url = createItemLink($post['itemid']);\r
88                                 redirect($url);\r
89                         }\r
90                 } else {\r
91                         // else, show error message using default skin for blog\r
92                         return array(\r
93                                 'message' => $errormessage,\r
94                                 'skinid' => $blog->getDefaultSkin()\r
95                         );\r
96                 }\r
97                 \r
98                 exit;\r
99         }\r
100 \r
101         // Sends a message from the current member to the member given as argument\r
102         function sendMessage() {\r
103                 global $CONF, $member;\r
104 \r
105                 $error = $this->validateMessage();\r
106                 if ($error != '')\r
107                         return array('message' => $error);\r
108 \r
109                 if (!$member->isLoggedIn()) {\r
110                         $fromMail = postVar('frommail');\r
111                         $fromName = _MMAIL_FROMANON;\r
112                 } else {\r
113                         $fromMail = $member->getEmail();\r
114                         $fromName = $member->getDisplayName();\r
115                 }\r
116 \r
117                 $tomem = new MEMBER();\r
118                 $tomem->readFromId(postVar('memberid'));\r
119 \r
120                 $message  = _MMAIL_MSG . ' ' . $fromName . "\n"\r
121                           . '(' . _MMAIL_FROMNUC. ' ' . $CONF['IndexURL'] .") \n\n"\r
122                           . _MMAIL_MAIL . " \n\n"\r
123                           . postVar('message');\r
124                 $message .= getMailFooter();\r
125 \r
126                 $title = _MMAIL_TITLE . ' ' . $fromName;\r
127                 mb_language('ja');\r
128                 mb_internal_encoding(_CHARSET);\r
129                 @mb_send_mail($tomem->getEmail(), $title, $message, "From: ". $fromMail);\r
130 \r
131                 if (postVar('url')) {\r
132                         redirect(postVar('url'));\r
133                 } else {\r
134                         $CONF['MemberURL'] = $CONF['IndexURL'];\r
135                         if ($CONF['URLMode'] == 'pathinfo')\r
136                                 $url = createMemberLink($tomem->getID());\r
137                         else\r
138                                 $url = $CONF['IndexURL'] . createMemberLink($tomem->getID());\r
139                         redirect($url);\r
140                 }\r
141                 \r
142                 exit;\r
143 \r
144         }\r
145         \r
146         function validateMessage() {\r
147                 global $CONF, $member, $manager;\r
148 \r
149                 if (!$CONF['AllowMemberMail']) \r
150                         return _ERROR_MEMBERMAILDISABLED;\r
151 \r
152                 if (!$member->isLoggedIn() && !$CONF['NonmemberMail'])\r
153                         return _ERROR_DISALLOWED;\r
154 \r
155                 if (!$member->isLoggedIn() && (!isValidMailAddress(postVar('frommail'))))\r
156                         return _ERROR_BADMAILADDRESS;\r
157                         \r
158                 // let plugins do verification (any plugin which thinks the comment is invalid\r
159                 // can change 'error' to something other than '')\r
160                 $result = '';\r
161                 $manager->notify('ValidateForm', array('type' => 'membermail', 'error' => &$result));\r
162                 \r
163                 return $result;\r
164                 \r
165         }\r
166 \r
167         // creates a new user account\r
168         function createAccount() {\r
169                 global $CONF, $manager;\r
170 \r
171                 if (!$CONF['AllowMemberCreate']) \r
172                         doError(_ERROR_MEMBERCREATEDISABLED);\r
173 \r
174                 // even though the member can not log in, set some random initial password. One never knows.\r
175                 srand((double)microtime()*1000000);\r
176                 $initialPwd = md5(uniqid(rand(), true));\r
177 \r
178                 // create member (non admin/can not login/no notes/random string as password)\r
179                 $r = MEMBER::create(postVar('name'), postVar('realname'), $initialPwd, postVar('email'), postVar('url'), 0, 0, '');\r
180                 \r
181                 if ($r != 1)\r
182                         doError($r);\r
183                         \r
184                 // send message containing password.\r
185                 $newmem = new MEMBER();\r
186                 $newmem->readFromName(postVar('name'));\r
187                 $newmem->sendActivationLink('register');\r
188 \r
189                 $manager->notify('PostRegister',array('member' => &$newmem));           \r
190 \r
191                 if (postVar('desturl')) {\r
192                         redirect(postVar('desturl'));\r
193                 } else {\r
194                         header ("Content-Type: text/html; charset="._CHARSET);\r
195                         echo _MSG_ACTIVATION_SENT;\r
196                 }\r
197                 \r
198                 exit;\r
199         }\r
200 \r
201         // sends a new password \r
202         function forgotPassword() {\r
203                 $membername = trim(postVar('name'));\r
204 \r
205                 if (!MEMBER::exists($membername))\r
206                         doError(_ERROR_NOSUCHMEMBER);\r
207                 $mem = MEMBER::createFromName($membername);\r
208 \r
209                 if (!$mem->canLogin())\r
210                         doError(_ERROR_NOLOGON_NOACTIVATE);\r
211 \r
212                 // check if e-mail address is correct\r
213                 if (!($mem->getEmail() == postVar('email')))\r
214                         doError(_ERROR_INCORRECTEMAIL);\r
215 \r
216                 // send activation link\r
217                 $mem->sendActivationLink('forgot');\r
218 \r
219                 if (postVar('url')) {\r
220                         redirect(postVar('url'));\r
221                 } else {\r
222                         header ("Content-Type: text/html; charset="._CHARSET);\r
223                         echo _MSG_ACTIVATION_SENT;\r
224                 }\r
225                 \r
226                 exit;\r
227         }\r
228 \r
229         // handle karma votes\r
230         function doKarma($type) {\r
231                 global $itemid, $member, $CONF, $manager;\r
232 \r
233                 // check if itemid exists\r
234                 if (!$manager->existsItem($itemid,0,0)) \r
235                         doError(_ERROR_NOSUCHITEM);\r
236 \r
237                 $blogid = getBlogIDFromItemID($itemid);\r
238                 $this->checkban($blogid);       \r
239 \r
240                 $karma =& $manager->getKarma($itemid);\r
241 \r
242                 // check if not already voted\r
243                 if (!$karma->isVoteAllowed(serverVar('REMOTE_ADDR'))) \r
244                         doError(_ERROR_VOTEDBEFORE);            \r
245 \r
246                 // check if item does allow voting\r
247                 $item =& $manager->getItem($itemid,0,0);\r
248                 if ($item['closed'])\r
249                         doError(_ERROR_ITEMCLOSED);\r
250 \r
251                 switch($type) {\r
252                         case 'pos': \r
253                                 $karma->votePositive();\r
254                                 break;\r
255                         case 'neg':\r
256                                 $karma->voteNegative();\r
257                                 break;\r
258                 }\r
259 \r
260                 $blogid = getBlogIDFromItemID($itemid);\r
261                 $blog =& $manager->getBlog($blogid);\r
262 \r
263                 // send email to notification address, if any\r
264                 if ($blog->getNotifyAddress() && $blog->notifyOnVote()) {\r
265 \r
266                         $mailto_msg = _NOTIFY_KV_MSG . ' ' . $itemid . "\n";\r
267                         $mailto_msg .= $CONF['IndexURL'] . 'index.php?itemid=' . $itemid . "\n\n";\r
268                         if ($member->isLoggedIn()) {\r
269                                 $mailto_msg .= _NOTIFY_MEMBER . ' ' . $member->getDisplayName() . ' (ID=' . $member->getID() . ")\n";\r
270                         }\r
271                         $mailto_msg .= _NOTIFY_IP . ' ' . serverVar('REMOTE_ADDR') . "\n";\r
272                         $mailto_msg .= _NOTIFY_HOST . ' ' .  gethostbyaddr(serverVar('REMOTE_ADDR'))  . "\n";\r
273                         $mailto_msg .= _NOTIFY_VOTE . "\n " . $type . "\n";\r
274                         $mailto_msg .= getMailFooter();\r
275 \r
276                         $mailto_title = _NOTIFY_KV_TITLE . ' ' . strip_tags($item['title']) . ' (' . $itemid . ')';\r
277 \r
278                         $frommail = $member->getNotifyFromMailAddress();\r
279 \r
280                         $notify = new NOTIFICATION($blog->getNotifyAddress());\r
281                         $notify->notify($mailto_title, $mailto_msg , $frommail);\r
282                 }\r
283 \r
284 \r
285                 $refererUrl = serverVar('HTTP_REFERER');\r
286                 if ($refererUrl)\r
287                         $url = $refererUrl;\r
288                 else\r
289                         $url = $CONF['IndexURL'] . 'index.php?itemid=' . $itemid;\r
290 \r
291                 redirect($url); \r
292                 exit;\r
293         }\r
294 \r
295         /**\r
296           * Calls a plugin action\r
297           */\r
298         function callPlugin() {\r
299                 global $manager;\r
300 \r
301                 $pluginName = 'NP_' . requestVar('name');\r
302                 $actionType = requestVar('type');\r
303 \r
304                 // 1: check if plugin is installed\r
305                 if (!$manager->pluginInstalled($pluginName))\r
306                         doError(_ERROR_NOSUCHPLUGIN);\r
307 \r
308                 // 2: call plugin\r
309                 $pluginObject =& $manager->getPlugin($pluginName);\r
310                 if ($pluginObject)\r
311                         $error = $pluginObject->doAction($actionType);\r
312                 else\r
313                         $error = 'Could not load plugin (see actionlog)';\r
314 \r
315                 // doAction returns error when:\r
316                 // - an error occurred (duh)\r
317                 // - no actions are allowed (doAction is not implemented)\r
318                 if ($error)\r
319                         doError($error);\r
320                         \r
321                 exit;\r
322 \r
323         }\r
324 \r
325         function checkban($blogid) {\r
326                 // check if banned\r
327                 $ban = BAN::isBanned($blogid, serverVar('REMOTE_ADDR'));\r
328                 if ($ban != 0) {\r
329                         doError(_ERROR_BANNED1 . $ban->iprange . _ERROR_BANNED2 . $ban->message . _ERROR_BANNED3);\r
330                 }\r
331 \r
332         }\r
333 \r
334 \r
335 }\r
336 \r
337 ?>\r