Project

General

Profile

1
<?php
2
/**
3
 *
4
 * @category        modules
5
 * @package         news
6
 * @author          WebsiteBaker Project
7
 * @copyright       2004-2009, Ryan Djurovich
8
 * @copyright       2009-2011, Website Baker Org. e.V.
9
 * @link			http://www.websitebaker2.org/
10
 * @license         http://www.gnu.org/licenses/gpl.html
11
 * @platform        WebsiteBaker 2.8.x
12
 * @requirements    PHP 5.2.2 and higher
13
 * @version         $Id: save_group.php 1425 2011-02-03 23:16:12Z Luisehahne $
14
 * @filesource		$HeadURL: svn://isteam.dynxs.de/wb-archiv/branches/2.8.x/wb/modules/news/save_group.php $
15
 * @lastmodified    $Date: 2011-02-04 00:16:12 +0100 (Fri, 04 Feb 2011) $
16
 *
17
 */
18

    
19
require('../../config.php');
20

    
21
// Get id
22
if(!isset($_POST['group_id']) OR !is_numeric($_POST['group_id']))
23
{
24
	header("Location: ".ADMIN_URL."/pages/index.php");
25
	exit( 0 );
26
}
27
else
28
{
29
	$group_id = $_POST['group_id'];
30
}
31

    
32
// Include WB admin wrapper script
33
$update_when_modified = true; // Tells script to update when this page was last updated
34
require(WB_PATH.'/modules/admin.php');
35

    
36
if (!$admin->checkFTAN())
37
{
38
	$admin->print_error($MESSAGE['GENERIC_SECURITY_ACCESS'],ADMIN_URL.'/pages/modify.php?page_id='.$page_id);
39
	exit();
40
}
41

    
42
// Include WB functions file
43
require(WB_PATH.'/framework/functions.php');
44

    
45
// Vagroup_idate all fields
46
if($admin->get_post('title') == '')
47
{
48
	$admin->print_error($MESSAGE['GENERIC']['FILL_IN_ALL'], WB_URL.'/modules/news/modify_group.php?page_id='.$page_id.'&section_id='.$section_id.'&group_id='.$admin->getIDKEY($group_id));
49
}
50
else
51
{
52
	$title = $admin->get_post_escaped('title');
53
	$active = $admin->get_post_escaped('active');
54
}
55

    
56
// Update row
57
$database->query("UPDATE ".TABLE_PREFIX."mod_news_groups SET title = '$title', active = '$active' WHERE group_id = '$group_id'");
58

    
59
// Check if the user uploaded an image or wants to delete one
60
if(isset($_FILES['image']['tmp_name']) AND $_FILES['image']['tmp_name'] != '')
61
{
62
	// Get real filename and set new filename
63
	$filename = $_FILES['image']['name'];
64
	$new_filename = WB_PATH.MEDIA_DIRECTORY.'/.news/image'.$group_id.'.jpg';
65
	// Make sure the image is a jpg file
66
	$file4=substr($filename, -4, 4);
67
	if(($file4 != '.jpg')and($file4 != '.JPG')and($file4 != '.png')and($file4 != '.PNG') and ($file4 !='jpeg') and ($file4 != 'JPEG'))
68
    {
69
		$admin->print_error($MESSAGE['GENERIC']['FILE_TYPE'].' JPG (JPEG) or PNG a');
70
	} elseif(
71
	(($_FILES['image']['type']) != 'image/jpeg' AND mime_content_type($_FILES['image']['tmp_name']) != 'image/jpg')
72
	and
73
	(($_FILES['image']['type']) != 'image/png' AND mime_content_type($_FILES['image']['tmp_name']) != 'image/png')
74
	){
75
		$admin->print_error($MESSAGE['GENERIC']['FILE_TYPE'].' JPG (JPEG) or PNG b');
76
	}
77
	// Make sure the target directory exists
78
	make_dir(WB_PATH.MEDIA_DIRECTORY.'/.news');
79
	// Upload image
80
	move_uploaded_file($_FILES['image']['tmp_name'], $new_filename);
81
	// Check if we need to create a thumb
82
	$query_settings = $database->query("SELECT resize FROM ".TABLE_PREFIX."mod_news_settings WHERE section_id = '$section_id'");
83
	$fetch_settings = $query_settings->fetchRow();
84
	$resize = $fetch_settings['resize'];
85
	if($resize != 0)
86
    {
87
		// Resize the image
88
		$thumb_location = WB_PATH.MEDIA_DIRECTORY.'/.news/thumb'.$group_id.'.jpg';
89
		if(make_thumb($new_filename, $thumb_location, $resize))
90
        {
91
			// Delete the actual image and replace with the resized version
92
			unlink($new_filename);
93
			rename($thumb_location, $new_filename);
94
		}
95
	}
96
}
97
if(isset($_POST['delete_image']) AND $_POST['delete_image'] != '')
98
{
99
	// Try unlinking image
100
	if(file_exists(WB_PATH.MEDIA_DIRECTORY.'/.news/image'.$group_id.'.jpg'))
101
    {
102
		unlink(WB_PATH.MEDIA_DIRECTORY.'/.news/image'.$group_id.'.jpg');
103
	}
104
}
105

    
106
// Check if there is a db error, otherwise say successful
107
if($database->is_error()) {
108
	$admin->print_error($database->get_error(), WB_URL.'/modules/news/modify_group.php?page_id='.$page_id.'&section_id='.$section_id.'&group_id='.$admin->getIDKEY($group_id));
109
} else {
110
	$admin->print_success($TEXT['SUCCESS'], ADMIN_URL.'/pages/modify.php?page_id='.$page_id);
111
}
112

    
113
// Print admin footer
114
$admin->print_footer();
115

    
116
?>
(24-24/31)