Passed
Push — master ( 39c203...ca1205 )
by Michael
02:01
created

searchmembers.php (1 issue)

Labels
Severity
1
<?php
2
3
/**
4
 * Xoops Members Module
5
 *
6
 * You may not change or alter any portion of this comment or credits
7
 * of supporting developers from this source code or any supporting source code
8
 * which is considered copyrighted (c) material of the original comment or credit authors.
9
 * This program is distributed in the hope that it will be useful,
10
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
12
 *
13
 * @copyright The XOOPS Project http://sourceforge.net/projects/xoops/
14
 * @license   http://www.fsf.org/copyleft/gpl.html GNU public license
15
 * @package   Xoops Members
16
 * @since     2.3.0
17
 * @author    onokazu
18
 * @author    John Neill
19
 */
20
21
require_once  __DIR__ . '/header.php';
22
23
global $xoopsModule;
24
$pathIcon16 = $xoopsModule->getInfo('icons16');
25
26
$op = (isset($_POST['op']) && 'submit' == $_POST['op']) ? 'submit' : 'form';
27
28
if ('form' == $op) {
29
    $xoopsOption['template_main'] = 'xoopsmembers_searchform.tpl';
30
    include XOOPS_ROOT_PATH . '/header.php';
31
32
    $memberHandler = xoops_getHandler('member');
33
    $total          = $memberHandler->getUserCount(new Criteria('level', 0, '>'));
0 ignored issues
show
The method getUserCount() does not exist on XoopsObjectHandler. It seems like you code against a sub-type of XoopsObjectHandler such as XoopsPersistableObjectHandler. ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-call  annotation

33
    /** @scrutinizer ignore-call */ 
34
    $total          = $memberHandler->getUserCount(new Criteria('level', 0, '>'));
Loading history...
34
35
    include_once XOOPS_ROOT_PATH . '/class/xoopsformloader.php';
36
37
    $form        = new XoopsThemeForm('', 'searchform', 'searchmembers.php');
38
    $uname_text  = new XoopsFormText('', 'user_uname', 30, 60);
39
    $uname_match = new XoopsFormSelectMatchOption('', 'user_uname_match');
40
    $uname_tray  = new XoopsFormElementTray(_MD_XOOPSMEMBERS_UNAME, '&nbsp;');
41
    $uname_tray->addElement($uname_match);
42
    $uname_tray->addElement($uname_text);
43
    $form->addElement($uname_tray);
44
45
    if (1 == $xoopsModuleConfig['displayrealname']){
46
    $name_text  = new XoopsFormText('', 'user_name', 30, 60);
47
    $name_match = new XoopsFormSelectMatchOption('', 'user_name_match');
48
    $name_tray  = new XoopsFormElementTray(_MD_XOOPSMEMBERS_REALNAME, '&nbsp;');
49
    $name_tray->addElement($name_match);
50
    $name_tray->addElement($name_text);
51
    $form->addElement($name_tray);
52
    }
53
54
	if (1 == $xoopsModuleConfig['displayemail']){
55
    $email_text  = new XoopsFormText('', 'user_email', 30, 60);
56
    $email_match = new XoopsFormSelectMatchOption('', 'user_email_match');
57
    $email_tray  = new XoopsFormElementTray(_MD_XOOPSMEMBERS_EMAIL, '&nbsp;');
58
    $email_tray->addElement($email_match);
59
    $email_tray->addElement($email_text);
60
    $form->addElement($email_tray);
61
    }
62
63
	if (1 == $xoopsModuleConfig['displayurl']){
64
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_URLC, 'user_url', 30, 100));
65
    }
66
	if (1 == $xoopsModuleConfig['displayfrom']){
67
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_LOCATION, 'user_from', 30, 100));
68
	}
69
	if (1 == $xoopsModuleConfig['displayoccupation']){
70
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_OCCUPATION, 'user_occ', 30, 100));
71
	}
72
	if (1 == $xoopsModuleConfig['displayinterest']){
73
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_INTEREST, 'user_intrest', 30, 100));
74
	}
75
	if (1 == $xoopsModuleConfig['displaylastlogin']){
76
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_LASTLOGMORE, 'user_lastlog_more', 10, 5));
77
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_LASTLOGLESS, 'user_lastlog_less', 10, 5));
78
	}
79
	if (1 == $xoopsModuleConfig['displayregdate']){
80
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_REGMORE, 'user_reg_more', 10, 5));
81
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_REGLESS, 'user_reg_less', 10, 5));
82
	}
83
	if (1 == $xoopsModuleConfig['displayposts']){
84
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_POSTSMORE, 'user_posts_more', 10, 5));
85
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_POSTSLESS, 'user_posts_less', 10, 5));
86
	}
87
88
    $sort_select = new XoopsFormSelect(_MD_XOOPSMEMBERS_SORT, 'user_sort');
89
    $sort_select->addOptionArray(['uname' => _MD_XOOPSMEMBERS_UNAME, 'name' => _MD_XOOPSMEMBERS_REALNAME, 'last_login' => _MD_XOOPSMEMBERS_LASTLOGIN, 'user_regdate' => _MD_XOOPSMEMBERS_REGDATE, 'posts' => _MD_XOOPSMEMBERS_POSTS]);
90
    $form->addElement($sort_select);
91
92
    $order_select = new XoopsFormSelect(_MD_XOOPSMEMBERS_ORDER, 'user_order');
93
    $order_select->addOptionArray(['ASC' => _MD_XOOPSMEMBERS_ASC, 'DESC' => _MD_XOOPSMEMBERS_DESC]);
94
    $form->addElement($order_select);
95
96
    $form->addElement(new XoopsFormText(_MD_XOOPSMEMBERS_LIMIT, 'limit', 6, 2));
97
    $form->addElement(new XoopsFormHidden('op', 'submit'));
98
    $form->addElement(new XoopsFormButton('', 'user_submit', _SUBMIT, 'submit'));
99
    $form->assign($xoopsTpl);
100
    $xoopsTpl->assign('totalmember', $total);
101
}
102
103
if ('submit' == $op) {
104
    $xoopsOption['template_main'] = 'xoopsmembers_searchresults.tpl';
105
    include XOOPS_ROOT_PATH . '/header.php';
106
107
    $iamadmin = $xoopsUserIsAdmin;
108
    $myts     = MyTextSanitizer::getInstance();
109
    $criteria = new CriteriaCompo();
110
111
    if (!empty($_POST['user_uname'])) {
112
        $match = (!empty($_POST['user_uname_match'])) ? (int)$_POST['user_uname_match'] : XOOPS_MATCH_START;
113
        $ret   = $myts->addSlashes(trim($_POST['user_uname']));
114
        xoops_Criteria($criteria, 'uname', $ret, $match);
115
    }
116
117
    if (!empty($_POST['user_name'])) {
118
        $match = (!empty($_POST['user_name_match'])) ? (int)$_POST['user_name_match'] : XOOPS_MATCH_START;
119
        $ret   = $myts->addSlashes(trim($_POST['user_uname']));
120
        xoops_Criteria($criteria, 'name', $ret, $match);
121
    }
122
123
    if (!empty($_POST['user_email'])) {
124
        $match = (!empty($_POST['user_email_match'])) ? (int)$_POST['user_email_match'] : XOOPS_MATCH_START;
125
        $ret   = $myts->addSlashes(trim($_POST['user_email']));
126
        xoops_Criteria($criteria, 'name', $ret, $match);
127
        if (!$iamadmin) {
128
            $criteria->add(new Criteria('user_viewemail', 1));
129
        }
130
    }
131
132
    if (!empty($_POST['user_url'])) {
133
        $url = formatURL(trim($_POST['user_url']));
134
        $criteria->add(new Criteria('url', $myts->addSlashes($url) . '%', 'LIKE'));
135
    }
136
137
    if (!empty($_POST['user_from'])) {
138
        $criteria->add(new Criteria('user_from', '%' . $myts->addSlashes(trim($_POST['user_from'])) . '%', 'LIKE'));
139
    }
140
141
    if (!empty($_POST['user_intrest'])) {
142
        $criteria->add(new Criteria('user_intrest', '%' . $myts->addSlashes(trim($_POST['user_intrest'])) . '%', 'LIKE'));
143
    }
144
145
    if (!empty($_POST['user_occ'])) {
146
        $criteria->add(new Criteria('user_occ', '%' . $myts->addSlashes(trim($_POST['user_occ'])) . '%', 'LIKE'));
147
    }
148
149
    if (!empty($_POST['user_lastlog_more']) && is_numeric($_POST['user_lastlog_more'])) {
150
        $f_user_lastlog_more = (int)trim($_POST['user_lastlog_more']);
151
        $time                = time() - (60 * 60 * 24 * $f_user_lastlog_more);
152
        if ($time > 0) {
153
            $criteria->add(new Criteria('last_login', $time, '<'));
154
        }
155
    }
156
157
    if (!empty($_POST['user_lastlog_less']) && is_numeric($_POST['user_lastlog_less'])) {
158
        $f_user_lastlog_less = (int)trim($_POST['user_lastlog_less']);
159
        $time                = time() - (60 * 60 * 24 * $f_user_lastlog_less);
160
        if ($time > 0) {
161
            $criteria->add(new Criteria('last_login', $time, '>'));
162
        }
163
    }
164
165
    if (!empty($_POST['user_reg_more']) && is_numeric($_POST['user_reg_more'])) {
166
        $f_user_reg_more = (int)trim($_POST['user_reg_more']);
167
        $time            = time() - (60 * 60 * 24 * $f_user_reg_more);
168
        if ($time > 0) {
169
            $criteria->add(new Criteria('user_regdate', $time, '<'));
170
        }
171
    }
172
173
    if (!empty($_POST['user_reg_less']) && is_numeric($_POST['user_reg_less'])) {
174
        $f_user_reg_less = (int)$_POST['user_reg_less'];
175
        $time            = time() - (60 * 60 * 24 * $f_user_reg_less);
176
        if ($time > 0) {
177
            $criteria->add(new Criteria('user_regdate', $time, '>'));
178
        }
179
    }
180
181
    if (isset($_POST['user_posts_more']) && is_numeric($_POST['user_posts_more'])) {
182
        $criteria->add(new Criteria('posts', (int)$_POST['user_posts_more'], '>'));
183
    }
184
185
    if (!empty($_POST['user_posts_less']) && is_numeric($_POST['user_posts_less'])) {
186
        $criteria->add(new Criteria('posts', (int)$_POST['user_posts_less'], '<'));
187
    }
188
189
    $criteria->add(new Criteria('level', 0, '>'));
190
    $validsort = ['uname', 'email', 'last_login', 'user_regdate', 'posts'];
191
    $sort      = (!in_array($_POST['user_sort'], $validsort)) ? 'uname' : $_POST['user_sort'];
192
    $order     = 'ASC';
193
    if (isset($_POST['user_order']) && 'DESC' == $_POST['user_order']) {
194
        $order = 'DESC';
195
    }
196
    $limit = (!empty($_POST['limit'])) ? (int)$_POST['limit'] : 20;
197
    if (0 == $limit || $limit > 50) {
198
        $limit = 50;
199
    }
200
201
    $start          = (!empty($_POST['start'])) ? (int)$_POST['start'] : 0;
202
    $memberHandler = xoops_getHandler('member');
203
    $total          = $memberHandler->getUserCount($criteria);
204
    $xoopsTpl->assign('total_found', $total);
205
206
    if (0 == $total) {
207
    } elseif ($start < $total) {
208
        if ($iamadmin) {
209
            $xoopsTpl->assign('is_admin', true);
210
        }
211
        $criteria->setSort($sort);
212
        $criteria->setOrder($order);
213
        $criteria->setStart($start);
214
        $criteria->setLimit($limit);
215
        $foundusers = $memberHandler->getUsers($criteria, true);
216
        foreach (array_keys($foundusers) as $j) {
217
            $userdata['avatar']   = $foundusers[$j]->getVar('user_avatar') ? '<img src="' . XOOPS_UPLOAD_URL . '/' . $foundusers[$j]->getVar('user_avatar') . '" alt="" />' : '&nbsp;';
218
            $userdata['realname'] = $foundusers[$j]->getVar('name') ?: '&nbsp;';
219
            $userdata['name']     = $foundusers[$j]->getVar('uname');
220
            $userdata['id']       = $foundusers[$j]->getVar('uid');
221
            if (1 == $foundusers[$j]->getVar('user_viewemail') || $iamadmin) {
222
                $userdata['email'] = '<a href="mailto:' . $foundusers[$j]->getVar('email') . '"><img src="' . XOOPS_URL . '/images/icons/email.gif" border="0" alt="' . sprintf(_SENDEMAILTO, $foundusers[$j]->getVar('uname', 'e')) . '" /></a>';
223
            } else {
224
                $userdata['email'] = '&nbsp;';
225
            }
226
            if ($xoopsUser) {
227
                $userdata['pmlink'] = '<a href="javascript:openWithSelfMain(\'' . XOOPS_URL . '/pmlite.php?send2=1&amp;to_userid=' . $foundusers[$j]->getVar('uid') . '\',\'pmlite\',450,370);"><img src="' . XOOPS_URL . '/images/icons/pm.gif" border="0" alt="' . sprintf(_SENDPMTO, $foundusers[$j]->getVar('uname', 'e')) . '" /></a>';
228
            } else {
229
                $userdata['pmlink'] = '&nbsp;';
230
            }
231
            if ('' != $foundusers[$j]->getVar('url', 'e')) {
232
                $userdata['website'] = '<a href="' . $foundusers[$j]->getVar('url', 'e') . '" target="_blank"><img src="' . XOOPS_URL . '/images/icons/www.gif" border="0" alt="' . _VISITWEBSITE . '" /></a>';
233
            } else {
234
                $userdata['website'] = '&nbsp;';
235
            }
236
            $userdata['registerdate'] = formatTimestamp($foundusers[$j]->getVar('user_regdate'), 's');
237
            if (0 != $foundusers[$j]->getVar('last_login')) {
238
                $userdata['lastlogin'] = formatTimestamp($foundusers[$j]->getVar('last_login'), 'm');
239
            } else {
240
                $userdata['lastlogin'] = '&nbsp;';
241
            }
242
            $userdata['posts'] = $foundusers[$j]->getVar('posts');
243
            if ($iamadmin) {
244
                $userdata['adminlink'] = '<a href="' . XOOPS_URL . '/modules/system/admin.php?fct=users&amp;uid=' . $foundusers[$j]->getVar('uid') . '&amp;op=users_edit">' . '<img src=' . $pathIcon16 . '/edit.png' . " alt='" . _EDIT . "' title='" . _EDIT . "' />"
245
246
                                         . '</a> | <a href="' . XOOPS_URL . '/modules/system/admin.php?fct=users&amp;op=users_delete&amp;uid=' . $foundusers[$j]->getVar('uid') . '">' . '<img src=' . $pathIcon16 . '/delete.png' . " alt='" . _DELETE . "' title='" . _DELETE . "' />" . '</a>';
247
            }
248
            $xoopsTpl->append('users', $userdata);
249
        }
250
251
        $totalpages = ceil($total / $limit);
252
        if ($totalpages > 1) {
253
            $hiddenform = '<form name="findnext" action="searchmembers.php" method="post">';
254
            foreach ($_POST as $k => $v) {
255
                $hiddenform .= '<input type="hidden" name="' . $myts->htmlSpecialChars($k) . '" value="' . $myts->previewTarea($v) . '" />';
256
            }
257
            if (!isset($_POST['limit'])) {
258
                $hiddenform .= '<input type="hidden" name="limit" value="' . $limit . '" />';
259
            }
260
            if (!isset($_POST['start'])) {
261
                $hiddenform .= '<input type="hidden" name="start" value="' . $start . '" />';
262
            }
263
            $prev = $start - $limit;
264
            if ($start - $limit >= 0) {
265
                $hiddenform .= '<a href="#0" onclick="javascript:document.findnext.start.value=' . $prev . ';document.findnext.submit();">' . _MD_XOOPSMEMBERS_PREVIOUS . '</a>&nbsp;';
266
            }
267
            $counter     = 1;
268
            $currentpage = ($start + $limit) / $limit;
269
            while ($counter <= $totalpages) {
270
                if ($counter == $currentpage) {
271
                    $hiddenform .= '<b>' . $counter . '</b> ';
272
                } elseif (($counter > $currentpage - 4 && $counter < $currentpage + 4) || 1 == $counter || $counter == $totalpages) {
273
                    if ($counter == $totalpages && $currentpage < $totalpages - 4) {
274
                        $hiddenform .= '... ';
275
                    }
276
                    $hiddenform .= '<a href="#' . $counter . '" onclick="javascript:document.findnext.start.value=' . ($counter - 1) * $limit . ';document.findnext.submit();">' . $counter . '</a> ';
277
                    if (1 == $counter && $currentpage > 5) {
278
                        $hiddenform .= '... ';
279
                    }
280
                }
281
                $counter++;
282
            }
283
            $next = $start + $limit;
284
            if ($total > $next) {
285
                $hiddenform .= '&nbsp;<a href="#' . $total . '" onclick="javascript:document.findnext.start.value=' . $next . ';document.findnext.submit();">' . _MD_XOOPSMEMBERS_NEXT . '</a>';
286
            }
287
            $hiddenform .= '</form>';
288
            $xoopsTpl->assign('pagenav', $hiddenform);
289
            $xoopsTpl->assign('lang_numfound', sprintf(_MD_XOOPSMEMBERS_USERSFOUND, $total));
290
        }
291
    }
292
}
293
294
include 'footer.php';
295
include_once XOOPS_ROOT_PATH . '/footer.php';
296
exit();
297
298
/**
299
 * xoops_Criteria()
300
 *
301
 * @param        $criteria
302
 * @param string $name
303
 * @param string $ret
304
 * @param string $match
305
 * @return void
306
 */
307
function xoops_Criteria(&$criteria, $name = '', $ret = '', $match = '')
308
{
309
    global $criteria;
310
311
    switch ($match) {
312
        case XOOPS_MATCH_START:
313
            $criteria->add(new Criteria($name, $ret . '%', 'LIKE'));
314
            break;
315
        case XOOPS_MATCH_END:
316
            $criteria->add(new Criteria($name, '%' . $ret . '%', 'LIKE'));
317
            break;
318
        case XOOPS_MATCH_EQUAL:
319
            $criteria->add(new Criteria($name, $ret));
320
            break;
321
        case XOOPS_MATCH_CONTAIN:
322
            $criteria->add(new Criteria($name, '%' . $ret . '%', 'LIKE'));
323
            break;
324
    }
325
}
326