| 1 | <?php
 | 
  
    | 2 | 
 | 
  
    | 3 | // $Id: sections.php 546 2008-01-17 18:10:50Z doc $
 | 
  
    | 4 | 
 | 
  
    | 5 | /*
 | 
  
    | 6 | 
 | 
  
    | 7 |  Website Baker Project <http://www.websitebaker.org/>
 | 
  
    | 8 |  Copyright (C) 2004-2008, Ryan Djurovich
 | 
  
    | 9 | 
 | 
  
    | 10 |  Website Baker is free software; you can redistribute it and/or modify
 | 
  
    | 11 |  it under the terms of the GNU General Public License as published by
 | 
  
    | 12 |  the Free Software Foundation; either version 2 of the License, or
 | 
  
    | 13 |  (at your option) any later version.
 | 
  
    | 14 | 
 | 
  
    | 15 |  Website Baker is distributed in the hope that it will be useful,
 | 
  
    | 16 |  but WITHOUT ANY WARRANTY; without even the implied warranty of
 | 
  
    | 17 |  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | 
  
    | 18 |  GNU General Public License for more details.
 | 
  
    | 19 | 
 | 
  
    | 20 |  You should have received a copy of the GNU General Public License
 | 
  
    | 21 |  along with Website Baker; if not, write to the Free Software
 | 
  
    | 22 |  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
 | 
  
    | 23 | 
 | 
  
    | 24 | */
 | 
  
    | 25 | 
 | 
  
    | 26 | // Include config file
 | 
  
    | 27 | require('../../config.php');
 | 
  
    | 28 | 
 | 
  
    | 29 | // Make sure people are allowed to access this page
 | 
  
    | 30 | if(MANAGE_SECTIONS != 'enabled') {
 | 
  
    | 31 | 	header('Location: '.ADMIN_URL.'/pages/index.php');
 | 
  
    | 32 | 	exit(0);
 | 
  
    | 33 | }
 | 
  
    | 34 | 
 | 
  
    | 35 | // Get page id
 | 
  
    | 36 | if(!isset($_GET['page_id']) OR !is_numeric($_GET['page_id'])) {
 | 
  
    | 37 | 	header("Location: index.php");
 | 
  
    | 38 | 	exit(0);
 | 
  
    | 39 | } else {
 | 
  
    | 40 | 	$page_id = $_GET['page_id'];
 | 
  
    | 41 | }
 | 
  
    | 42 | 
 | 
  
    | 43 | // Create new admin object
 | 
  
    | 44 | require_once(WB_PATH.'/framework/class.admin.php');
 | 
  
    | 45 | $admin = new admin('Pages', 'pages_modify');
 | 
  
    | 46 | 
 | 
  
    | 47 | // Check if we are supposed to add or delete a section
 | 
  
    | 48 | if(isset($_GET['section_id']) AND is_numeric($_GET['section_id'])) {
 | 
  
    | 49 | 	// Get more information about this section
 | 
  
    | 50 | 	$section_id = $_GET['section_id'];
 | 
  
    | 51 | 	$query_section = $database->query("SELECT module FROM ".TABLE_PREFIX."sections WHERE section_id = '$section_id'");
 | 
  
    | 52 | 	if($query_section->numRows() == 0) {
 | 
  
    | 53 | 		$admin->print_error('Section not found');
 | 
  
    | 54 | 	}
 | 
  
    | 55 | 	$section = $query_section->fetchRow();
 | 
  
    | 56 | 	// Include the modules delete file if it exists
 | 
  
    | 57 | 	if(file_exists(WB_PATH.'/modules/'.$section['module'].'/delete.php')) {
 | 
  
    | 58 | 		require(WB_PATH.'/modules/'.$section['module'].'/delete.php');
 | 
  
    | 59 | 	}
 | 
  
    | 60 | 	$database->query("DELETE FROM ".TABLE_PREFIX."sections WHERE section_id = '$section_id' LIMIT 1");
 | 
  
    | 61 | 	if($database->is_error()) {
 | 
  
    | 62 | 		$admin->print_error($database->get_error());
 | 
  
    | 63 | 	} else {
 | 
  
    | 64 | 		require(WB_PATH.'/framework/class.order.php');
 | 
  
    | 65 | 		$order = new order(TABLE_PREFIX.'sections', 'position', 'section_id', 'page_id');
 | 
  
    | 66 | 		$order->clean($page_id);
 | 
  
    | 67 | 		$admin->print_success($TEXT['SUCCESS'], ADMIN_URL.'/pages/sections.php?page_id='.$page_id);
 | 
  
    | 68 | 		$admin->print_footer();
 | 
  
    | 69 | 		exit();
 | 
  
    | 70 | 	}
 | 
  
    | 71 | } elseif(isset($_POST['module']) AND $_POST['module'] != '') {
 | 
  
    | 72 | 	// Get section info
 | 
  
    | 73 | 	$module = $_POST['module'];
 | 
  
    | 74 | 	// Include the ordering class
 | 
  
    | 75 | 	require(WB_PATH.'/framework/class.order.php');
 | 
  
    | 76 | 	// Get new order
 | 
  
    | 77 | 	$order = new order(TABLE_PREFIX.'sections', 'position', 'section_id', 'page_id');
 | 
  
    | 78 | 	$position = $order->get_new($page_id);	
 | 
  
    | 79 | 	// Insert module into DB
 | 
  
    | 80 | 	$database->query("INSERT INTO ".TABLE_PREFIX."sections (page_id,module,position,block) VALUES ('$page_id','$module','$position','1')");
 | 
  
    | 81 | 	// Get the section id
 | 
  
    | 82 | 	$section_id = $database->get_one("SELECT LAST_INSERT_ID()");	
 | 
  
    | 83 | 	// Include the selected modules add file if it exists
 | 
  
    | 84 | 	if(file_exists(WB_PATH.'/modules/'.$module.'/add.php')) {
 | 
  
    | 85 | 		require(WB_PATH.'/modules/'.$module.'/add.php');
 | 
  
    | 86 | 	}	
 | 
  
    | 87 | }
 | 
  
    | 88 | 
 | 
  
    | 89 | // Get perms
 | 
  
    | 90 | $database = new database();
 | 
  
    | 91 | $results = $database->query("SELECT admin_groups,admin_users FROM ".TABLE_PREFIX."pages WHERE page_id = '$page_id'");
 | 
  
    | 92 | $results_array = $results->fetchRow();
 | 
  
    | 93 | $old_admin_groups = explode(',', $results_array['admin_groups']);
 | 
  
    | 94 | $old_admin_users = explode(',', $results_array['admin_users']);
 | 
  
    | 95 | $in_old_group = FALSE;
 | 
  
    | 96 | foreach($admin->get_groups_id() as $cur_gid){
 | 
  
    | 97 |     if (in_array($cur_gid, $old_admin_groups)) {
 | 
  
    | 98 | 	$in_old_group = TRUE;
 | 
  
    | 99 |     }
 | 
  
    | 100 | }
 | 
  
    | 101 | if((!$in_old_group) AND !is_numeric(array_search($admin->get_user_id(), $old_admin_users))) {
 | 
  
    | 102 | 	$admin->print_error($MESSAGE['PAGES']['INSUFFICIENT_PERMISSIONS']);
 | 
  
    | 103 | }
 | 
  
    | 104 | 
 | 
  
    | 105 | // Get page details
 | 
  
    | 106 | $database = new database();
 | 
  
    | 107 | $query = "SELECT * FROM ".TABLE_PREFIX."pages WHERE page_id = '$page_id'";
 | 
  
    | 108 | $results = $database->query($query);
 | 
  
    | 109 | if($database->is_error()) {
 | 
  
    | 110 | 	$admin->print_header();
 | 
  
    | 111 | 	$admin->print_error($database->get_error());
 | 
  
    | 112 | }
 | 
  
    | 113 | if($results->numRows() == 0) {
 | 
  
    | 114 | 	$admin->print_header();
 | 
  
    | 115 | 	$admin->print_error($MESSAGE['PAGES']['NOT_FOUND']);
 | 
  
    | 116 | }
 | 
  
    | 117 | $results_array = $results->fetchRow();
 | 
  
    | 118 | 
 | 
  
    | 119 | // Set module permissions
 | 
  
    | 120 | $module_permissions = $_SESSION['MODULE_PERMISSIONS'];
 | 
  
    | 121 | 
 | 
  
    | 122 | // Unset block var
 | 
  
    | 123 | unset($block);
 | 
  
    | 124 | // Include template info file (if it exists)
 | 
  
    | 125 | if($results_array['template'] != '') {
 | 
  
    | 126 | 	$template_location = WB_PATH.'/templates/'.$results_array['template'].'/info.php';
 | 
  
    | 127 | } else {
 | 
  
    | 128 | 	$template_location = WB_PATH.'/templates/'.DEFAULT_TEMPLATE.'/info.php';
 | 
  
    | 129 | }
 | 
  
    | 130 | if(file_exists($template_location)) {
 | 
  
    | 131 | 	require($template_location);
 | 
  
    | 132 | }
 | 
  
    | 133 | // Check if $menu is set
 | 
  
    | 134 | if(!isset($block[1]) OR $block[1] == '') {
 | 
  
    | 135 | 	// Make our own menu list
 | 
  
    | 136 | 	$block[1] = $TEXT['MAIN'];
 | 
  
    | 137 | }
 | 
  
    | 138 | 
 | 
  
    | 139 | ?>
 | 
  
    | 140 | <table cellpadding="5" cellspacing="0" border="0" align="center" width="100%" height="50" style="margin-bottom: 10px;">
 | 
  
    | 141 | <tr style="background-color: #F0F0F0;">
 | 
  
    | 142 | 	<td valign="middle" align="left">
 | 
  
    | 143 | 		<h2><?php echo $HEADING['MANAGE_SECTIONS']; ?></h2>
 | 
  
    | 144 | 	</td>
 | 
  
    | 145 | 	<td align="right">
 | 
  
    | 146 | 		<?php echo $TEXT['CURRENT_PAGE']; ?>: 
 | 
  
    | 147 | 		<b><?php echo ($results_array['page_title']); ?></b>
 | 
  
    | 148 | 		-
 | 
  
    | 149 | 		<a href="<?php echo ADMIN_URL; ?>/pages/modify.php?page_id=<?php echo $page_id; ?>"><?php echo $HEADING['MODIFY_PAGE']; ?></a>
 | 
  
    | 150 | 		-
 | 
  
    | 151 | 		<a href="<?php echo ADMIN_URL; ?>/pages/settings.php?page_id=<?php echo $page_id; ?>"><?php echo $TEXT['CHANGE_SETTINGS']; ?></a>
 | 
  
    | 152 | 	</td>
 | 
  
    | 153 | </tr>
 | 
  
    | 154 | </table>
 | 
  
    | 155 | 
 | 
  
    | 156 | <?php
 | 
  
    | 157 | $query_sections = $database->query("SELECT section_id,module,position,block FROM ".TABLE_PREFIX."sections WHERE page_id = '$page_id' ORDER BY position ASC");
 | 
  
    | 158 | if($query_sections->numRows() > 0) {
 | 
  
    | 159 | ?>
 | 
  
    | 160 | <form name="section_properties" action="<?php echo ADMIN_URL; ?>/pages/sections_save.php?page_id=<?php echo $page_id; ?>" method="post">
 | 
  
    | 161 | 
 | 
  
    | 162 | <table cellpadding="5" cellspacing="0" border="0" align="center" width="100%">
 | 
  
    | 163 | <tr>
 | 
  
    | 164 | 	<td><?php echo $TEXT['TYPE']; ?>:</td>
 | 
  
    | 165 | 	<?php if(SECTION_BLOCKS) { ?>
 | 
  
    | 166 | 	<td style="display: {DISPLAY_BLOCK}"><?php echo $TEXT['BLOCK']; ?>:</td>
 | 
  
    | 167 | 	<?php } ?>
 | 
  
    | 168 | 	<td colspan="3" width="60"><?php echo $TEXT['ACTIONS']; ?>:</td>
 | 
  
    | 169 | </tr>
 | 
  
    | 170 | <?php
 | 
  
    | 171 | 	$num_sections = $query_sections->numRows();
 | 
  
    | 172 | 	while($section = $query_sections->fetchRow()) {
 | 
  
    | 173 | 		// Get the modules real name
 | 
  
    | 174 | 		$module_name=$database->get_one("SELECT name FROM ".TABLE_PREFIX."addons WHERE directory='".$section['module']."'");
 | 
  
    | 175 | 		if(!is_numeric(array_search($section['module'], $module_permissions))) {
 | 
  
    | 176 | 			?>
 | 
  
    | 177 | 			<tr>
 | 
  
    | 178 | 				<td style="width: 250px;"><a href="<?php echo ADMIN_URL; ?>/pages/modify.php?page_id=<?php echo $page_id; ?>#<?php echo $section['section_id']; ?>"><?php echo $module_name; ?></a></td>
 | 
  
    | 179 | 				<?php if(SECTION_BLOCKS) { ?>
 | 
  
    | 180 | 				<td>
 | 
  
    | 181 | 					<select name="block<?php echo $section['section_id']; ?>" style="width: 150px;">
 | 
  
    | 182 | 						<?php
 | 
  
    | 183 | 						foreach($block AS $number => $name) {
 | 
  
    | 184 | 							?>
 | 
  
    | 185 | 							<option value="<?php echo $number; ?>"<?php if($number == $section['block']) { echo ' selected'; } ?>><?php echo $name; ?></option>
 | 
  
    | 186 | 							<?php
 | 
  
    | 187 | 						}
 | 
  
    | 188 | 						?>
 | 
  
    | 189 | 					</select>
 | 
  
    | 190 | 				</td>
 | 
  
    | 191 | 				<?php } ?>
 | 
  
    | 192 | 				<td width="20">
 | 
  
    | 193 | 					<?php if($section['position'] != 1) { ?>
 | 
  
    | 194 | 					<a href="<?php echo ADMIN_URL; ?>/pages/move_up.php?page_id=<?php echo $page_id; ?>§ion_id=<?php echo $section['section_id']; ?>">
 | 
  
    | 195 | 						<img src="<?php echo ADMIN_URL; ?>/images/up_16.png" alt="^" border="0" />
 | 
  
    | 196 | 					</a>
 | 
  
    | 197 | 					<?php } ?>
 | 
  
    | 198 | 				</td>
 | 
  
    | 199 | 				<td width="20">
 | 
  
    | 200 | 					<?php if($section['position'] != $num_sections) { ?>
 | 
  
    | 201 | 					<a href="<?php echo ADMIN_URL; ?>/pages/move_down.php?page_id=<?php echo $page_id; ?>§ion_id=<?php echo $section['section_id']; ?>">
 | 
  
    | 202 | 						<img src="<?php echo ADMIN_URL; ?>/images/down_16.png" alt="v" border="0" />
 | 
  
    | 203 | 					</a>
 | 
  
    | 204 | 					<?php } ?>
 | 
  
    | 205 | 				</td>
 | 
  
    | 206 | 				<td width="20">
 | 
  
    | 207 | 					<a href="javascript: confirm_link('<?php echo $TEXT['ARE_YOU_SURE']; ?>', '<?php echo ADMIN_URL; ?>/pages/sections.php?page_id=<?php echo $page_id; ?>§ion_id=<?php echo $section['section_id']; ?>');">
 | 
  
    | 208 | 						<img src="<?php echo ADMIN_URL; ?>/images/delete_16.png" alt="Del" border="0" />
 | 
  
    | 209 | 					</a>
 | 
  
    | 210 | 				</td>
 | 
  
    | 211 | 			</tr>
 | 
  
    | 212 | 			<?php
 | 
  
    | 213 | 			}
 | 
  
    | 214 | 	}
 | 
  
    | 215 | 	?>
 | 
  
    | 216 | 	<tr>
 | 
  
    | 217 | 		<td> </td>
 | 
  
    | 218 | 		<?php if(SECTION_BLOCKS) { ?>
 | 
  
    | 219 | 		<td><input type="submit" name="save" value="<?php echo $TEXT['SAVE']; ?>" style="width: 150px;" /></td>
 | 
  
    | 220 | 		<?php } ?>
 | 
  
    | 221 | 		<td colspan="3" width="60"> </td>
 | 
  
    | 222 | 	</tr>
 | 
  
    | 223 | 	</table>
 | 
  
    | 224 | 
 | 
  
    | 225 | </form>
 | 
  
    | 226 | 
 | 
  
    | 227 | <?php
 | 
  
    | 228 | }
 | 
  
    | 229 | 
 | 
  
    | 230 | // Work-out if we should show the "Add Section" form
 | 
  
    | 231 | $query_sections = $database->query("SELECT section_id FROM ".TABLE_PREFIX."sections WHERE page_id = '$page_id' AND module = 'menu_link'");
 | 
  
    | 232 | if($query_sections->numRows() == 0) {
 | 
  
    | 233 | 	?>
 | 
  
    | 234 | 	<h2><?php echo $TEXT['ADD_SECTION']; ?></h2>
 | 
  
    | 235 | 	
 | 
  
    | 236 | 	<form name="add" action="<?php echo ADMIN_URL; ?>/pages/sections.php?page_id=<?php echo $page_id; ?>" method="post">
 | 
  
    | 237 | 	
 | 
  
    | 238 | 	<table cellpadding="5" cellspacing="0" border="0" align="center" width="100%">
 | 
  
    | 239 | 	<tr>
 | 
  
    | 240 | 		<td>
 | 
  
    | 241 | 			<select name="module" style="width: 100%;">
 | 
  
    | 242 | 			<?php
 | 
  
    | 243 | 			// Insert module list
 | 
  
    | 244 | 			$result = $database->query("SELECT * FROM ".TABLE_PREFIX."addons WHERE type = 'module' AND function = 'page' AND directory != 'menu_link' order by name");
 | 
  
    | 245 | 			if($result->numRows() > 0) {
 | 
  
    | 246 | 				while($module = $result->fetchRow()) {
 | 
  
    | 247 | 					// Check if user is allowed to use this module
 | 
  
    | 248 | 					if(!is_numeric(array_search($module['directory'], $module_permissions))) {
 | 
  
    | 249 | 						?>
 | 
  
    | 250 | 						<option value="<?php echo $module['directory']; ?>"<?php if($module['directory'] == 'wysiwyg') { echo 'selected'; } ?>><?php echo $module['name']; ?></option>
 | 
  
    | 251 | 						<?php
 | 
  
    | 252 | 					}
 | 
  
    | 253 | 				}
 | 
  
    | 254 | 			}
 | 
  
    | 255 | 			?>
 | 
  
    | 256 | 			</select>
 | 
  
    | 257 | 		</td>
 | 
  
    | 258 | 		<td width="100">
 | 
  
    | 259 | 			<input type="submit" name="submit" value="<?php echo $TEXT['ADD']; ?>" style="width: 100px" />
 | 
  
    | 260 | 		</td>
 | 
  
    | 261 | 	</tr>
 | 
  
    | 262 | 	</table>
 | 
  
    | 263 | 	
 | 
  
    | 264 | 	</form>
 | 
  
    | 265 | 	<?php
 | 
  
    | 266 | }
 | 
  
    | 267 | 
 | 
  
    | 268 | // Print admin footer
 | 
  
    | 269 | $admin->print_footer();
 | 
  
    | 270 | 
 | 
  
    | 271 | ?>
 |