Project

General

Profile

1
<?php
2
/**
3
 *
4
 * @category        module
5
 * @package         Form
6
 * @author          WebsiteBaker Project
7
 * @copyright       2009-2012, WebsiteBaker Org. e.V.
8
 * @link			http://www.websitebaker2.org/
9
 * @license         http://www.gnu.org/licenses/gpl.html
10
 * @platform        WebsiteBaker 2.8.x
11
 * @requirements    PHP 5.2.2 and higher
12
 * @version         $Id: save_settings.php 1801 2012-10-31 17:23:46Z Luisehahne $
13
 * @filesource		$HeadURL: svn://isteam.dynxs.de/wb-archiv/branches/2.8.x/wb/modules/form/save_settings.php $
14
 * @lastmodified    $Date: 2012-10-31 18:23:46 +0100 (Wed, 31 Oct 2012) $
15
 * @description
16
 */
17

    
18
require('../../config.php');
19

    
20
$admin_header = false;
21
// Tells script to update when this page was last updated
22
$update_when_modified = true;
23
// Include WB admin wrapper script
24
require(WB_PATH.'/modules/admin.php');
25

    
26
if (!$admin->checkFTAN())
27
{
28
	$admin->print_header();
29
	$admin->print_error($MESSAGE['GENERIC_SECURITY_ACCESS'], ADMIN_URL.'/pages/modify.php?page_id='.$page_id);
30
}
31
$admin->print_header();
32

    
33
$sec_anchor = (defined( 'SEC_ANCHOR' ) && ( SEC_ANCHOR != '' )  ? '#'.SEC_ANCHOR.$section['section_id'] : 'section_'.$section_id );
34

    
35
if (!function_exists('emailAdmin')) {
36
	function emailAdmin() {
37
		global $database,$admin;
38
        $retval = $admin->get_email();
39
        if($admin->get_user_id()!='1') {
40
			$sql  = 'SELECT `email` FROM `'.TABLE_PREFIX.'users` ';
41
			$sql .= 'WHERE `user_id`=\'1\' ';
42
	        $retval = $database->get_one($sql);
43
        }
44
		return $retval;
45
	}
46
}
47

    
48
// load module language file
49
$lang = (dirname(__FILE__)) . '/languages/' . LANGUAGE . '.php';
50
require_once(!file_exists($lang) ? (dirname(__FILE__)) . '/languages/EN.php' : $lang );
51
// later in upgrade.php (add pagination)
52
$table_name = TABLE_PREFIX.'mod_form_settings';
53
$field_name = 'perpage_submissions';
54
$description = "INT NOT NULL DEFAULT '10' AFTER `max_submissions`";
55
$database->field_add($table_name, $field_name, $description);
56

    
57
// This code removes any <?php tags and adds slashes
58
$friendly = array('&lt;', '&gt;', '?php');
59
$raw = array('<', '>', '');
60

    
61
//$header     = CleanInput('header');
62
$header = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('header'),true));
63
//$field_loop = CleanInput('field_loop');
64
$field_loop = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('field_loop'),true));
65
//$footer     = CleanInput('footer');
66
$footer = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('footer'),true));
67
//$email_to   = CleanInput('email_to');
68
$email_to = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('email_to'),true));
69
$email_to   = ($email_to != '' ? $email_to : emailAdmin());
70
$email_from = $admin->add_slashes(SERVER_EMAIL);
71
//$use_captcha =CleanInput('use_captcha');
72
$use_captcha = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('use_captcha'),true));
73

    
74
if( isset($_POST['email_fromname_field']) && ($_POST['email_fromname_field'] != '')) {
75
    $email_fromname = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('email_fromname_field'),true));
76
} else {
77
    $email_fromname = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('email_fromname'),true));
78
}
79

    
80
$email_fromname = ($email_fromname != '' ? $email_fromname : WBMAILER_DEFAULT_SENDERNAME);
81
$email_subject = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('email_subject'),true));
82
$success_page = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_page'),true));
83
$success_email_to = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_email_to'),true));
84
$success_email_from = $admin->add_slashes(SERVER_EMAIL);
85
$success_email_fromname = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_email_fromname'),true));
86
$success_email_fromname = ($success_email_fromname != '' ? $success_email_fromname : $email_fromname);
87
$success_email_text = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_email_text'),true));
88
$success_email_text = (($success_email_text != '') ? $success_email_text : '');
89
$success_email_subject = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_email_subject'),true));
90
$success_email_subject = (($success_email_subject  != '') ? $success_email_subject : '');
91

    
92
if(!is_numeric($_POST['max_submissions'])) {
93
	$max_submissions = 50;
94
} else {
95
	$max_submissions = intval($_POST['max_submissions']);
96
}
97
if(!is_numeric($_POST['stored_submissions'])) {
98
	$stored_submissions = 100;
99
} else {
100
	$stored_submissions = intval($_POST['stored_submissions']);
101
}
102
if(!is_numeric($_POST['perpage_submissions'])) {
103
	$perpage_submissions = 10;
104
} else {
105
	$perpage_submissions = intval($_POST['perpage_submissions']);
106
}
107

    
108
// Make sure max submissions is not greater than stored submissions if stored_submissions <>0
109
if($max_submissions > $stored_submissions) {
110
	$max_submissions = $stored_submissions;
111
}
112
$sec_anchor = (defined( 'SEC_ANCHOR' ) && ( SEC_ANCHOR != '' )  ? '#'.SEC_ANCHOR.$section['section_id'] : 'section_'.$section_id );
113

    
114
// Update settings
115
$sql  = 'UPDATE `'.TABLE_PREFIX.'mod_form_settings` SET ';
116
$sql .= '`header` = \''.$header.'\', ';
117
$sql .= '`field_loop` = \''.$field_loop.'\', ';
118
$sql .= '`footer` = \''.$footer.'\', ';
119
$sql .= '`email_to` = \''.$email_to.'\', ';
120
$sql .= '`email_from` = \''.$email_from.'\', ';
121
$sql .= '`email_fromname` = \''.$email_fromname.'\', ';
122
$sql .= '`email_subject` = \''.$email_subject.'\', ';
123
$sql .= '`success_page` = \''.$success_page.'\', ';
124
$sql .= '`success_email_to` = \''.$success_email_to.'\', ';
125
$sql .= '`success_email_from` = \''.$success_email_from.'\', ';
126
$sql .= '`success_email_fromname` = \''.$success_email_fromname.'\', ';
127
$sql .= '`success_email_text` = \''.$success_email_text.'\', ';
128
$sql .= '`success_email_subject` = \''.$success_email_subject.'\', ';
129
$sql .= '`max_submissions` = \''.$max_submissions.'\', ';
130
$sql .= '`stored_submissions` = \''.$stored_submissions.'\', ';
131
$sql .= '`perpage_submissions` = \''.$perpage_submissions.'\', ';
132
$sql .= '`use_captcha` = \''.$use_captcha.'\' ';
133
$sql .= 'WHERE `section_id` = '.(int)$section_id.' ';
134
$sql .= '';
135
if($database->query($sql)) {
136
	$admin->print_success($TEXT['SUCCESS'], ADMIN_URL.'/pages/modify.php?page_id='.$page_id.$sec_anchor);
137
}
138
// Check if there is a db error, otherwise say successful
139
if($database->is_error()) {
140
	$admin->print_error($database->get_error(), ADMIN_URL.'/pages/modify.php?page_id='.$page_id.$sec_anchor);
141
}
142
// Print admin footer
143
$admin->print_footer();
(20-20/25)