1
|
|
|
<?php |
2
|
|
|
// This file is part of BOINC. |
3
|
|
|
// http://boinc.berkeley.edu |
4
|
|
|
// Copyright (C) 2021 University of California |
5
|
|
|
// |
6
|
|
|
// BOINC is free software; you can redistribute it and/or modify it |
7
|
|
|
// under the terms of the GNU Lesser General Public License |
8
|
|
|
// as published by the Free Software Foundation, |
9
|
|
|
// either version 3 of the License, or (at your option) any later version. |
10
|
|
|
// |
11
|
|
|
// BOINC is distributed in the hope that it will be useful, |
12
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of |
13
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. |
14
|
|
|
// See the GNU Lesser General Public License for more details. |
15
|
|
|
// |
16
|
|
|
// You should have received a copy of the GNU Lesser General Public License |
17
|
|
|
// along with BOINC. If not, see <http://www.gnu.org/licenses/>. |
18
|
|
|
|
19
|
|
|
require_once("../inc/boinc_db.inc"); |
20
|
|
|
require_once("../inc/email.inc"); |
21
|
|
|
require_once("../inc/pm.inc"); |
22
|
|
|
require_once("../inc/forum.inc"); |
23
|
|
|
require_once("../inc/akismet.inc"); |
24
|
|
|
|
25
|
|
|
check_get_args(array("replyto", "deleted", "userid", "action", "sent", "id", "tnow", "ttok", "teamid")); |
26
|
|
|
|
27
|
|
|
function show_block_link($userid) { |
28
|
|
|
echo " <a href=\"pm.php?action=block&id=$userid\">"; |
29
|
|
|
show_image(REPORT_POST_IMAGE, tra("Block messages from this user"), tra("Block user"), REPORT_POST_IMAGE_HEIGHT); |
30
|
|
|
echo "</a>"; |
31
|
|
|
} |
32
|
|
|
|
33
|
|
|
$logged_in_user = get_logged_in_user(); |
34
|
|
|
BoincForumPrefs::lookup($logged_in_user); |
35
|
|
|
|
36
|
|
|
function make_script() { |
37
|
|
|
echo " |
38
|
|
|
<script type=\"text/javascript\"> |
39
|
|
|
function set_all(val) { |
40
|
|
|
f = document.msg_list; |
41
|
|
|
n = f.elements.length; |
42
|
|
|
for (i=0; i<n; i++) { |
43
|
|
|
e = f.elements[i]; |
44
|
|
|
if (e.type=='checkbox') { |
45
|
|
|
e.checked = val; |
46
|
|
|
} |
47
|
|
|
} |
48
|
|
|
} |
49
|
|
|
</script> |
50
|
|
|
"; |
51
|
|
|
} |
52
|
|
|
|
53
|
|
|
// show all private messages, |
54
|
|
|
// and delete notifications of new messages |
55
|
|
|
// |
56
|
|
|
function do_inbox($logged_in_user) { |
57
|
|
|
page_head(tra("Private messages").": ".tra("Inbox")); |
58
|
|
|
|
59
|
|
|
make_script(); |
60
|
|
|
if (get_int("sent", true) == 1) { |
61
|
|
|
echo "<h3>".tra("Your message has been sent.")."</h3>\n"; |
62
|
|
|
} |
63
|
|
|
$options = get_output_options($logged_in_user); |
64
|
|
|
|
65
|
|
|
BoincNotify::delete_aux("userid=$logged_in_user->id and type=".NOTIFY_PM); |
66
|
|
|
|
67
|
|
|
$msgs = BoincPrivateMessage::enum( |
68
|
|
|
"userid=$logged_in_user->id ORDER BY date DESC" |
69
|
|
|
); |
70
|
|
|
if (count($msgs) == 0) { |
71
|
|
|
echo tra("You have no private messages."); |
72
|
|
|
} else { |
73
|
|
|
echo "<form name=msg_list action=pm.php method=post> |
74
|
|
|
<input type=hidden name=action value=delete_selected> |
75
|
|
|
"; |
76
|
|
|
echo form_tokens($logged_in_user->authenticator); |
77
|
|
|
start_table('table-striped'); |
78
|
|
|
row_heading_array( |
79
|
|
|
array(tra("Subject"), tra("Sender and date"), tra("Message")), |
80
|
|
|
array('style="width: 12em;"', 'style="width: 10em;"', "") |
81
|
|
|
); |
82
|
|
|
foreach($msgs as $msg) { |
83
|
|
|
$sender = BoincUser::lookup_id($msg->senderid); |
84
|
|
|
if (!$sender) { |
85
|
|
|
$msg->delete(); |
86
|
|
|
continue; |
87
|
|
|
} |
88
|
|
|
echo "<tr>\n"; |
89
|
|
|
$checkbox = "<input type=checkbox name=pm_select_$msg->id>"; |
90
|
|
|
if (!$msg->opened) { |
91
|
|
|
$msg->update("opened=1"); |
92
|
|
|
} |
93
|
|
|
echo "<td valign=top> $checkbox $msg->subject </td>\n"; |
94
|
|
|
echo "<td valign=top>".user_links($sender, BADGE_HEIGHT_SMALL); |
95
|
|
|
show_block_link($msg->senderid); |
96
|
|
|
echo "<br>".time_str($msg->date)."</td>\n"; |
97
|
|
|
echo "<td valign=top>".output_transform($msg->content, $options)."<p>"; |
98
|
|
|
$tokens = url_tokens($logged_in_user->authenticator); |
99
|
|
|
show_button("pm.php?action=new&replyto=$msg->id", tra("Reply"), tra("Reply to this message")); |
100
|
|
|
show_button("pm.php?action=delete&id=$msg->id&$tokens", tra("Delete"), tra("Delete this message")); |
101
|
|
|
echo "</ul></td></tr>\n"; |
102
|
|
|
} |
103
|
|
|
echo " |
104
|
|
|
<tr><td> |
105
|
|
|
<a href=\"javascript:set_all(1)\">".tra("Select all")."</a> |
106
|
|
|
| |
107
|
|
|
<a href=\"javascript:set_all(0)\">".tra("Unselect all")."</a> |
108
|
|
|
</td> |
109
|
|
|
<td colspan=2> |
110
|
|
|
<input class=\"btn btn-danger\" type=submit value=\"".tra("Delete selected messages")."\"> |
111
|
|
|
</td></tr> |
112
|
|
|
"; |
113
|
|
|
end_table(); |
114
|
|
|
echo "</form>\n"; |
115
|
|
|
} |
116
|
|
|
page_tail(); |
117
|
|
|
} |
118
|
|
|
|
119
|
|
|
// the following isn't currently used - we never show single messages |
120
|
|
|
// |
121
|
|
|
function do_read($logged_in_user) { |
122
|
|
|
$id = get_int("id"); |
123
|
|
|
$message = BoincPrivateMessage::lookup_id($id); |
124
|
|
|
if (!$message || $message->userid != $logged_in_user->id) { |
125
|
|
|
error_page(tra("no such message")); |
126
|
|
|
} |
127
|
|
|
page_head(tra("Private messages")." : ".$message->subject); |
128
|
|
|
pm_header(); |
129
|
|
|
|
130
|
|
|
$sender = BoincUser::lookup_id($message->senderid); |
131
|
|
|
|
132
|
|
|
start_table(); |
133
|
|
|
echo "<tr><th>".tra("Subject")."</th><td>".$message->subject."</td></tr>"; |
134
|
|
|
echo "<tr><th>".tra("Sender")."</th><td>".user_links($sender, BADGE_HEIGHT_SMALL); |
135
|
|
|
show_block_link($message->senderid); |
136
|
|
|
echo "</td></tr>"; |
137
|
|
|
echo "<tr><th>".tra("Date")."</th><td>".time_str($message->date)."</td></tr>"; |
138
|
|
|
echo "<tr><th>".tra("Message")."</th><td>".output_transform($message->content, $options)."</td></tr>"; |
|
|
|
|
139
|
|
|
echo "<tr><td></td><td>\n"; |
140
|
|
|
echo "<a href=\"pm.php?action=new&replyto=$id\">".tra("Reply")."</a>\n"; |
141
|
|
|
echo " · <a href=\"pm.php?action=delete&id=$id\">".tra("Delete")."</a>\n"; |
142
|
|
|
echo " · <a href=\"pm.php?action=inbox\">".tra("Inbox")."</a>\n"; |
143
|
|
|
end_table(); |
144
|
|
|
|
145
|
|
|
if ($message->opened == 0) { |
146
|
|
|
$message->update("opened=1"); |
147
|
|
|
} |
148
|
|
|
page_tail(); |
149
|
|
|
} |
150
|
|
|
|
151
|
|
|
function do_new($logged_in_user) { |
152
|
|
|
global $replyto, $userid; |
153
|
|
|
check_banished($logged_in_user); |
154
|
|
|
if (VALIDATE_EMAIL_TO_POST) { |
155
|
|
|
check_validated_email($logged_in_user); |
156
|
|
|
} |
157
|
|
|
pm_form($replyto, $userid); |
158
|
|
|
} |
159
|
|
|
|
160
|
|
|
function do_delete($logged_in_user) { |
161
|
|
|
$id = get_int("id", true); |
162
|
|
|
if ($id == null) { |
163
|
|
|
$id = post_int("id"); |
164
|
|
|
} |
165
|
|
|
check_tokens($logged_in_user->authenticator); |
166
|
|
|
BoincPrivateMessage::delete_aux("userid=".$logged_in_user->id." AND id=$id"); |
167
|
|
|
header("Location: pm.php"); |
168
|
|
|
} |
169
|
|
|
|
170
|
|
|
function do_send_team($logged_in_user) { |
171
|
|
|
check_tokens($logged_in_user->authenticator); |
172
|
|
|
$subject = post_str("subject", true); |
173
|
|
|
$content = post_str("content", true); |
174
|
|
|
$teamid = post_int("teamid"); |
175
|
|
|
if (post_str("preview", true) == tra("Preview")) { |
176
|
|
|
pm_team_form($logged_in_user, $teamid); |
177
|
|
|
return; |
178
|
|
|
} |
179
|
|
|
|
180
|
|
|
// make sure user is authorized, i.e. is a team admin |
181
|
|
|
// |
182
|
|
|
$team = BoincTeam::lookup_id($teamid); |
183
|
|
|
if (!$team) { |
184
|
|
|
error_page("no such team"); |
185
|
|
|
} |
186
|
|
|
if (!is_team_admin($logged_in_user, $team)) { |
187
|
|
|
error_page("no team admin"); |
188
|
|
|
} |
189
|
|
|
|
190
|
|
|
if (($subject == null) || ($content == null)) { |
|
|
|
|
191
|
|
|
pm_team_form( |
192
|
|
|
$logged_in_user, $teamid, |
193
|
|
|
tra("You need to fill all fields to send a private message") |
194
|
|
|
); |
195
|
|
|
return; |
196
|
|
|
} |
197
|
|
|
|
198
|
|
|
$subject = "Message from team ".$team->name.": ".$subject; |
199
|
|
|
// don't use tra() here because we don't know language of recipient |
200
|
|
|
// Also, we use it in pm_count() to exclude team messages from limit check |
201
|
|
|
$users = BoincUser::enum("teamid=$teamid"); |
202
|
|
|
foreach ($users as $user) { |
203
|
|
|
pm_send_msg($logged_in_user, $user, $subject, $content, true); |
204
|
|
|
} |
205
|
|
|
page_head(tra("Message sent")); |
206
|
|
|
echo tra("Your message was sent to %1 team members.", count($users)); |
207
|
|
|
page_tail(); |
208
|
|
|
} |
209
|
|
|
|
210
|
|
|
function do_send($logged_in_user) { |
211
|
|
|
global $replyto, $userid; |
212
|
|
|
check_banished($logged_in_user); |
213
|
|
|
if (VALIDATE_EMAIL_TO_POST) { |
214
|
|
|
check_validated_email($logged_in_user); |
215
|
|
|
} |
216
|
|
|
check_tokens($logged_in_user->authenticator); |
217
|
|
|
|
218
|
|
|
$to = sanitize_tags(post_str("to", true)); |
219
|
|
|
$subject = post_str("subject", true); |
220
|
|
|
$content = post_str("content", true); |
221
|
|
|
|
222
|
|
|
if (post_str("preview", true) == tra("Preview")) { |
223
|
|
|
pm_form($replyto, $userid); |
224
|
|
|
} |
225
|
|
|
if (($to == null) || ($subject == null) || ($content == null)) { |
|
|
|
|
226
|
|
|
pm_form($replyto, $userid, tra("You need to fill all fields to send a private message")); |
227
|
|
|
return; |
228
|
|
|
} |
229
|
|
|
if (!akismet_check($logged_in_user, $content)) { |
230
|
|
|
pm_form($replyto, $userid, tra("Your message was flagged as spam |
231
|
|
|
by the Akismet anti-spam system. |
232
|
|
|
Please modify your text and try again.") |
233
|
|
|
); |
234
|
|
|
} |
235
|
|
|
$to = str_replace(", ", ",", $to); // Filter out spaces after separator |
236
|
|
|
$users = explode(",", $to); |
237
|
|
|
|
238
|
|
|
$userlist = array(); |
239
|
|
|
$userids = array(); // To prevent from spamming a single user by adding it multiple times |
240
|
|
|
|
241
|
|
|
foreach ($users as $username) { |
242
|
|
|
$user = explode(" ", $username); |
243
|
|
|
if (is_numeric($user[0])) { // user ID is given |
244
|
|
|
$userid = $user[0]; |
245
|
|
|
$user = BoincUser::lookup_id($userid); |
246
|
|
|
if ($user == null) { |
247
|
|
|
pm_form($replyto, $userid, tra("Could not find user with id %1", $userid)); |
248
|
|
|
} |
249
|
|
|
} else { |
250
|
|
|
$users = BoincUser::lookup_name($username); |
251
|
|
|
if (count($users) == 0) { |
252
|
|
|
pm_form($replyto, $userid, tra("Could not find user with username %1", $username)); |
253
|
|
|
} elseif (count($users) > 1) { // Non-unique username |
254
|
|
|
pm_form($replyto, $userid, tra("%1 is not a unique username; you will have to use user ID", $username)); |
255
|
|
|
} |
256
|
|
|
$user = $users[0]; |
257
|
|
|
} |
258
|
|
|
BoincForumPrefs::lookup($user); |
259
|
|
|
if (is_ignoring($user, $logged_in_user)) { |
260
|
|
|
pm_form($replyto, $userid, tra("User %1 (ID: %2) is not accepting private messages from you.", $user->name, $user->id)); |
261
|
|
|
} |
262
|
|
|
if (!isset($userids[$user->id])) { |
263
|
|
|
$userlist[] = $user; |
264
|
|
|
$userids[$user->id] = true; |
265
|
|
|
} |
266
|
|
|
} |
267
|
|
|
|
268
|
|
|
foreach ($userlist as $user) { |
269
|
|
|
if (!is_moderator($logged_in_user, null)) { |
270
|
|
|
check_pm_count($logged_in_user->id); |
271
|
|
|
} |
272
|
|
|
pm_send_msg($logged_in_user, $user, $subject, $content, true); |
273
|
|
|
} |
274
|
|
|
|
275
|
|
|
Header("Location: pm.php?action=inbox&sent=1"); |
|
|
|
|
276
|
|
|
} |
277
|
|
|
|
278
|
|
|
function do_block($logged_in_user) { |
279
|
|
|
$id = get_int("id"); |
280
|
|
|
$user = BoincUser::lookup_id($id); |
281
|
|
|
if (!$user) { |
282
|
|
|
error_page(tra("No such user")); |
283
|
|
|
} |
284
|
|
|
page_head(tra("Really block %1?", $user->name)); |
285
|
|
|
echo "<div>".tra("Are you really sure you want to block user %1 from sending you private messages?", $user->name)."<br>\n"; |
286
|
|
|
echo tra("Please note that you can only block a limited amount of users.")."</div>\n"; |
287
|
|
|
echo "<div>".tra("Once the user has been blocked you can unblock it using forum preferences page.")."</div>\n"; |
288
|
|
|
|
289
|
|
|
echo "<form action=\"pm.php\" method=\"POST\">\n"; |
290
|
|
|
echo form_tokens($logged_in_user->authenticator); |
291
|
|
|
echo "<input type=\"hidden\" name=\"action\" value=\"confirmedblock\">\n"; |
292
|
|
|
echo "<input type=\"hidden\" name=\"id\" value=\"$id\">\n"; |
293
|
|
|
echo "<input class=\"btn btn-default\" type=\"submit\" value=\"".tra("Add user to filter")."\">\n"; |
294
|
|
|
echo "<a href=\"pm.php?action=inbox\">".tra("No, cancel")."</a>\n"; |
295
|
|
|
echo "</form>\n"; |
296
|
|
|
page_tail(); |
297
|
|
|
} |
298
|
|
|
|
299
|
|
|
function do_confirmedblock($logged_in_user) { |
300
|
|
|
check_tokens($logged_in_user->authenticator); |
301
|
|
|
$id = post_int("id"); |
302
|
|
|
$blocked_user = BoincUser::lookup_id($id); |
303
|
|
|
if (!$blocked_user) error_page(tra("no such user")); |
304
|
|
|
add_ignored_user($logged_in_user, $blocked_user); |
305
|
|
|
|
306
|
|
|
page_head(tra("User %1 blocked", $blocked_user->name)); |
307
|
|
|
|
308
|
|
|
echo "<div>".tra("User %1 has been blocked from sending you private messages.", $blocked_user->name)."\n"; |
309
|
|
|
echo tra("To unblock, visit %1 message board preferences %2", "<a href=\"edit_forum_preferences_form.php\">", "</a>")."</div>\n"; |
310
|
|
|
page_tail(); |
311
|
|
|
} |
312
|
|
|
|
313
|
|
|
function do_delete_selected($logged_in_user) { |
314
|
|
|
check_tokens($logged_in_user->authenticator); |
315
|
|
|
|
316
|
|
|
$msgs = BoincPrivateMessage::enum( |
317
|
|
|
"userid=$logged_in_user->id" |
318
|
|
|
); |
319
|
|
|
foreach($msgs as $msg) { |
320
|
|
|
$x = "pm_select_$msg->id"; |
321
|
|
|
if (post_str($x, true)) { |
322
|
|
|
$msg = BoincPrivateMessage::lookup_id($msg->id); |
323
|
|
|
$msg->delete(); |
324
|
|
|
} |
325
|
|
|
} |
326
|
|
|
Header("Location: pm.php?action=inbox&deleted=1"); |
|
|
|
|
327
|
|
|
} |
328
|
|
|
|
329
|
|
|
$replyto = get_int("replyto", true); |
330
|
|
|
$userid = get_int("userid", true); |
331
|
|
|
$teamid = get_int("teamid", true); |
332
|
|
|
if (!$teamid) { |
333
|
|
|
$teamid = post_int("teamid", true); |
334
|
|
|
} |
335
|
|
|
|
336
|
|
|
$action = sanitize_tags(get_str("action", true)); |
337
|
|
|
if (!$action) { |
338
|
|
|
$action = sanitize_tags(post_str("action", true)); |
339
|
|
|
} |
340
|
|
|
|
341
|
|
|
if (!$action) { |
342
|
|
|
$action = "inbox"; |
343
|
|
|
} |
344
|
|
|
|
345
|
|
|
if ($action == "inbox") { |
346
|
|
|
do_inbox($logged_in_user); |
347
|
|
|
} elseif ($action == "read") { |
348
|
|
|
do_read($logged_in_user); |
349
|
|
|
} elseif ($action == "new") { |
350
|
|
|
if (!$teamid) $teamid = post_int("teamid", true); |
351
|
|
|
if ($teamid) { |
352
|
|
|
pm_team_form($logged_in_user, $teamid); |
353
|
|
|
} else { |
354
|
|
|
do_new($logged_in_user); |
355
|
|
|
} |
356
|
|
|
} elseif ($action == "delete") { |
357
|
|
|
do_delete($logged_in_user); |
358
|
|
|
} elseif ($action == "send") { |
359
|
|
|
if ($teamid) { |
360
|
|
|
do_send_team($logged_in_user); |
361
|
|
|
} else { |
362
|
|
|
do_send($logged_in_user); |
363
|
|
|
} |
364
|
|
|
} elseif ($action == "block") { |
365
|
|
|
do_block($logged_in_user); |
366
|
|
|
} elseif ($action == "confirmedblock") { |
367
|
|
|
do_confirmedblock($logged_in_user); |
368
|
|
|
} elseif ($action == "delete_selected") { |
369
|
|
|
do_delete_selected($logged_in_user); |
370
|
|
|
} else { |
371
|
|
|
error_page(tra("Unknown action")); |
372
|
|
|
} |
373
|
|
|
|
374
|
|
|
$cvs_version_tracker[]="\$Id: pm.php 14077 2007-11-03 04:26:47Z davea $"; |
375
|
|
|
?> |
376
|
|
|
|