Project

General

Profile

1
<?php
2
/**
3
 *
4
 * @category        module
5
 * @package         Form
6
 * @author          WebsiteBaker Project
7
 * @copyright       2009-2012, WebsiteBaker Org. e.V.
8
 * @link			http://www.websitebaker2.org/
9
 * @license         http://www.gnu.org/licenses/gpl.html
10
 * @platform        WebsiteBaker 2.8.x
11
 * @requirements    PHP 5.2.2 and higher
12
 * @version         $Id: save_settings.php 1757 2012-09-16 03:45:24Z Luisehahne $
13
 * @filesource		$HeadURL: svn://isteam.dynxs.de/wb-archiv/branches/2.8.x/wb/modules/form/save_settings.php $
14
 * @lastmodified    $Date: 2012-09-16 05:45:24 +0200 (Sun, 16 Sep 2012) $
15
 * @description
16
 */
17

    
18
require('../../config.php');
19

    
20
$admin_header = false;
21
// Tells script to update when this page was last updated
22
$update_when_modified = true;
23
// Include WB admin wrapper script
24
require(WB_PATH.'/modules/admin.php');
25

    
26
if (!$admin->checkFTAN())
27
{
28
	$admin->print_header();
29
	$admin->print_error($MESSAGE['GENERIC_SECURITY_ACCESS'], ADMIN_URL.'/pages/modify.php?page_id='.$page_id);
30
}
31
$admin->print_header();
32

    
33
$sec_anchor = (defined( 'SEC_ANCHOR' ) && ( SEC_ANCHOR != '' )  ? '#'.SEC_ANCHOR.$section['section_id'] : 'section_'.$section_id );
34

    
35
if (!function_exists('emailAdmin')) {
36
	function emailAdmin() {
37
		global $database,$admin;
38
        $retval = $admin->get_email();
39
        if($admin->get_user_id()!='1') {
40
			$sql  = 'SELECT `email` FROM `'.TABLE_PREFIX.'users` ';
41
			$sql .= 'WHERE `user_id`=\'1\' ';
42
	        $retval = $database->get_one($sql);
43
        }
44
		return $retval;
45
	}
46
}
47

    
48
// load module language file
49
$lang = (dirname(__FILE__)) . '/languages/' . LANGUAGE . '.php';
50
require_once(!file_exists($lang) ? (dirname(__FILE__)) . '/languages/EN.php' : $lang );
51
// later in upgrade.php
52
$table_name = TABLE_PREFIX.'mod_form_settings';
53
$field_name = 'perpage_submissions';
54
$description = "INT NOT NULL DEFAULT '10' AFTER `max_submissions`";
55
if(!$database->field_exists($table_name,$field_name)) {
56
	$database->field_add($table_name, $field_name, $description);
57
}
58

    
59

    
60
// This code removes any <?php tags and adds slashes
61
$friendly = array('&lt;', '&gt;', '?php');
62
$raw = array('<', '>', '');
63
$header     = $admin->add_slashes($_POST['header']);
64
$field_loop = $admin->add_slashes($_POST['field_loop']);
65
$footer     = $admin->add_slashes($_POST['footer']);
66
$email_to   = $admin->add_slashes($_POST['email_to']);
67
$email_to   = ($email_to != '' ? $email_to : emailAdmin());
68
$email_from = $admin->add_slashes(SERVER_EMAIL);
69
$use_captcha = $admin->add_slashes($_POST['use_captcha']);
70
/*
71
if( isset($_POST['email_from_field']) && ($_POST['email_from_field'] != '')) {
72
	$email_from = $admin->add_slashes($_POST['email_from_field']);
73
} else {
74
	$email_from = $admin->add_slashes($_POST['email_from']);
75
}
76
*/
77
if( isset($_POST['email_fromname_field']) && ($_POST['email_fromname_field'] != '')) {
78
	$email_fromname = $admin->add_slashes($_POST['email_fromname_field']);
79
} else {
80
	$email_fromname = $admin->add_slashes($_POST['email_fromname']);
81
}
82

    
83
$email_subject = $admin->add_slashes($_POST['email_subject']);
84
$email_subject = (($email_subject  != '') ? $email_subject : '');
85
$success_page = $admin->add_slashes($_POST['success_page']);
86
$success_email_to = $admin->add_slashes($_POST['success_email_to']);
87
$success_email_from = $admin->add_slashes(SERVER_EMAIL);
88
$success_email_fromname = $admin->add_slashes($_POST['success_email_fromname']);
89
$success_email_fromname = ($success_email_fromname != '' ? $success_email_fromname : WBMAILER_DEFAULT_SENDERNAME);
90
$success_email_text = $admin->add_slashes($_POST['success_email_text']);
91
$success_email_text = (($success_email_text != '') ? $success_email_text : '');
92
$success_email_subject = $admin->add_slashes($_POST['success_email_subject']);
93
$success_email_subject = (($success_email_subject  != '') ? $success_email_subject : '');
94

    
95
//print '<pre style="text-align: left;"><strong>function '.__FUNCTION__.'( '.''.' );</strong>  basename: '.basename(__FILE__).'  line: '.__LINE__.' -> <br />';
96
//print_r( $_POST ); print '</pre>';
97

    
98
if(!is_numeric($_POST['max_submissions'])) {
99
	$max_submissions = 50;
100
} else {
101
	$max_submissions = $_POST['max_submissions'];
102
}
103
if(!is_numeric($_POST['stored_submissions'])) {
104
	$stored_submissions = 100;
105
} else {
106
	$stored_submissions = $_POST['stored_submissions'];
107
}
108
if(!is_numeric($_POST['perpage_submissions'])) {
109
	$perpage_submissions = 10;
110
} else {
111
	$perpage_submissions = $_POST['perpage_submissions'];
112
}
113
// Make sure max submissions is not greater than stored submissions if stored_submissions <>0
114
if($max_submissions > $stored_submissions) {
115
	$max_submissions = $stored_submissions;
116
}
117
$sec_anchor = (defined( 'SEC_ANCHOR' ) && ( SEC_ANCHOR != '' )  ? '#'.SEC_ANCHOR.$section['section_id'] : 'section_'.$section_id );
118

    
119
// Update settings
120
$sql  = 'UPDATE `'.TABLE_PREFIX.'mod_form_settings` SET ';
121
$sql .= '`header` = \''.$header.'\', ';
122
$sql .= '`field_loop` = \''.$field_loop.'\', ';
123
$sql .= '`footer` = \''.$footer.'\', ';
124
$sql .= '`email_to` = \''.$email_to.'\', ';
125
$sql .= '`email_from` = \''.$email_from.'\', ';
126
$sql .= '`email_fromname` = \''.$email_fromname.'\', ';
127
$sql .= '`email_subject` = \''.$email_subject.'\', ';
128
$sql .= '`success_page` = \''.$success_page.'\', ';
129
$sql .= '`success_email_to` = \''.$success_email_to.'\', ';
130
$sql .= '`success_email_from` = \''.$success_email_from.'\', ';
131
$sql .= '`success_email_fromname` = \''.$success_email_fromname.'\', ';
132
$sql .= '`success_email_text` = \''.$success_email_text.'\', ';
133
$sql .= '`success_email_subject` = \''.$success_email_subject.'\', ';
134
$sql .= '`max_submissions` = \''.$max_submissions.'\', ';
135
$sql .= '`stored_submissions` = \''.$stored_submissions.'\', ';
136
$sql .= '`perpage_submissions` = \''.$perpage_submissions.'\', ';
137
$sql .= '`use_captcha` = \''.$use_captcha.'\' ';
138
$sql .= 'WHERE `section_id` = '.(int)$section_id.' ';
139
$sql .= '';
140
if($database->query($sql)) {
141
	$admin->print_success($TEXT['SUCCESS'], ADMIN_URL.'/pages/modify.php?page_id='.$page_id.$sec_anchor);
142
}
143
// Check if there is a db error, otherwise say successful
144
if($database->is_error()) {
145
	$admin->print_error($database->get_error(), ADMIN_URL.'/pages/modify.php?page_id='.$page_id.$sec_anchor);
146
}
147
// Print admin footer
148
$admin->print_footer();
(20-20/25)