Project

General

Profile

1
<?php
2
/**
3
 *
4
 * @category        module
5
 * @package         Form
6
 * @author          WebsiteBaker Project
7
 * @copyright       2009-2013, WebsiteBaker Org. e.V.
8
 * @link            http://www.websitebaker.org/
9
 * @license         http://www.gnu.org/licenses/gpl.html
10
 * @platform        WebsiteBaker 2.8.x
11
 * @requirements    PHP 5.2.2 and higher
12
 * @version         $Id: save_settings.php 1919 2013-06-07 04:21:49Z Luisehahne $
13
 * @filesource      $HeadURL: svn://isteam.dynxs.de/wb-archiv/branches/2.8.x/wb/modules/form/save_settings.php $
14
 * @lastmodified    $Date: 2013-06-07 06:21:49 +0200 (Fri, 07 Jun 2013) $
15
 * @description
16
 */
17

    
18
require('../../config.php');
19

    
20
$admin_header = false;
21
// Tells script to update when this page was last updated
22
$update_when_modified = true;
23
// Include WB admin wrapper script
24
require(WB_PATH.'/modules/admin.php');
25

    
26
if (!$admin->checkFTAN())
27
{
28
	$admin->print_header();
29
	$admin->print_error($MESSAGE['GENERIC_SECURITY_ACCESS'], ADMIN_URL.'/pages/modify.php?page_id='.$page_id);
30
}
31
$admin->print_header();
32

    
33
if (!function_exists('emailAdmin')) {
34
	function emailAdmin() {
35
		global $database,$admin;
36
        $retval = $admin->get_email();
37
        if($admin->get_user_id()!='1') {
38
			$sql  = 'SELECT `email` FROM `'.TABLE_PREFIX.'users` ';
39
			$sql .= 'WHERE `user_id`=\'1\' ';
40
	        $retval = $database->get_one($sql);
41
        }
42
		return $retval;
43
	}
44
}
45

    
46
// load module language file
47
$lang = (dirname(__FILE__)) . '/languages/' . LANGUAGE . '.php';
48
require_once(!file_exists($lang) ? (dirname(__FILE__)) . '/languages/EN.php' : $lang );
49
// later in upgrade.php (add pagination)
50
$table_name = TABLE_PREFIX.'mod_form_settings';
51
$field_name = 'perpage_submissions';
52
$description = "INT NOT NULL DEFAULT '10' AFTER `max_submissions`";
53
$database->field_add($table_name, $field_name, $description);
54

    
55
// This code removes any <?php tags and adds slashes
56
$friendly = array('&lt;', '&gt;', '?php');
57
$raw = array('<', '>', '');
58

    
59
//$header     = CleanInput('header');
60
$header = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('header'),true));
61
//$field_loop = CleanInput('field_loop');
62
$field_loop = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('field_loop'),true));
63
//$footer     = CleanInput('footer');
64
$footer = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('footer'),true));
65
//$email_to   = CleanInput('email_to');
66
$email_to = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('email_to'),true));
67
$email_to   = ($email_to != '' ? $email_to : emailAdmin());
68
$email_from = $admin->add_slashes(SERVER_EMAIL);
69
//$use_captcha =CleanInput('use_captcha');
70
$use_captcha = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('use_captcha'),true));
71

    
72
if( isset($_POST['email_fromname_field']) && ($_POST['email_fromname_field'] != '')) {
73
    $email_fromname = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('email_fromname_field'),true));
74
} else {
75
    $email_fromname = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('email_fromname'),true));
76
}
77

    
78
$email_fromname = ($email_fromname != '' ? $email_fromname : WBMAILER_DEFAULT_SENDERNAME);
79
$email_subject = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('email_subject'),true));
80
$success_page = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_page'),true));
81
$success_email_to = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_email_to'),true));
82
$success_email_from = $admin->add_slashes(SERVER_EMAIL);
83
$success_email_fromname = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_email_fromname'),true));
84
$success_email_fromname = ($success_email_fromname != '' ? $success_email_fromname : $email_fromname);
85
$success_email_text = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_email_text'),true));
86
$success_email_text = (($success_email_text != '') ? $success_email_text : '');
87
$success_email_subject = $admin->add_slashes($admin->StripCodeFromText($admin->get_post('success_email_subject'),true));
88
$success_email_subject = (($success_email_subject  != '') ? $success_email_subject : '');
89

    
90
if(!is_numeric($_POST['max_submissions'])) {
91
	$max_submissions = 50;
92
} else {
93
	$max_submissions = intval($_POST['max_submissions']);
94
}
95
if(!is_numeric($_POST['stored_submissions'])) {
96
	$stored_submissions = 100;
97
} else {
98
	$stored_submissions = intval($_POST['stored_submissions']);
99
}
100
if(!is_numeric($_POST['perpage_submissions'])) {
101
	$perpage_submissions = 10;
102
} else {
103
	$perpage_submissions = intval($_POST['perpage_submissions']);
104
}
105

    
106
// Make sure max submissions is not greater than stored submissions if stored_submissions <>0
107
if($max_submissions > $stored_submissions) {
108
	$max_submissions = $stored_submissions;
109
}
110
$sSectionIdPrefix = (defined( 'SEC_ANCHOR' ) && ( SEC_ANCHOR != '' )  ? SEC_ANCHOR : 'Sec' );
111

    
112
// Update settings
113
$sql  = 'UPDATE `'.TABLE_PREFIX.'mod_form_settings` SET ';
114
$sql .= '`header` = \''.$header.'\', ';
115
$sql .= '`field_loop` = \''.$field_loop.'\', ';
116
$sql .= '`footer` = \''.$footer.'\', ';
117
$sql .= '`email_to` = \''.$email_to.'\', ';
118
$sql .= '`email_from` = \''.$email_from.'\', ';
119
$sql .= '`email_fromname` = \''.$email_fromname.'\', ';
120
$sql .= '`email_subject` = \''.$email_subject.'\', ';
121
$sql .= '`success_page` = \''.$success_page.'\', ';
122
$sql .= '`success_email_to` = \''.$success_email_to.'\', ';
123
$sql .= '`success_email_from` = \''.$success_email_from.'\', ';
124
$sql .= '`success_email_fromname` = \''.$success_email_fromname.'\', ';
125
$sql .= '`success_email_text` = \''.$success_email_text.'\', ';
126
$sql .= '`success_email_subject` = \''.$success_email_subject.'\', ';
127
$sql .= '`max_submissions` = \''.$max_submissions.'\', ';
128
$sql .= '`stored_submissions` = \''.$stored_submissions.'\', ';
129
$sql .= '`perpage_submissions` = \''.$perpage_submissions.'\', ';
130
$sql .= '`use_captcha` = \''.$use_captcha.'\' ';
131
$sql .= 'WHERE `section_id` = '.(int)$section_id.' ';
132
$sql .= '';
133
if($database->query($sql)) {
134
	$admin->print_success($TEXT['SUCCESS'], ADMIN_URL.'/pages/modify.php?page_id='.$page_id.'#'.$sSectionIdPrefix.$section_id);
135
}
136
// Check if there is a db error, otherwise say successful
137
if($database->is_error()) {
138
	$admin->print_error($database->get_error(), ADMIN_URL.'/pages/modify.php?page_id='.$page_id.'#'.$sSectionIdPrefix.$section_id);
139
}
140
// Print admin footer
141
$admin->print_footer();
(20-20/25)