Passed
Push — master ( 221bdd...5b32ea )
by Michael
03:08
created

searchmembers.php (1 issue)

Severity
1
<?php
2
3
/**
4
 * Xoops Members Module
5
 *
6
 * You may not change or alter any portion of this comment or credits
7
 * of supporting developers from this source code or any supporting source code
8
 * which is considered copyrighted (c) material of the original comment or credit authors.
9
 * This program is distributed in the hope that it will be useful,
10
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
12
 *
13
 * @copyright The XOOPS Project http://sourceforge.net/projects/xoops/
14
 * @license   http://www.fsf.org/copyleft/gpl.html GNU public license
15
 * @package   Xoops Members
16
 * @since     2.3.0
17
 * @author    onokazu
18
 * @author    John Neill
19
 */
20
21
require_once  __DIR__ . '/header.php';
22
23
global $xoopsModule;
24
25
$op = (isset($_POST['op']) && 'submit' == $_POST['op']) ? 'submit' : 'form';
26
/** @var \XoopsMemberHandler $memberHandler */
27
$memberHandler = xoops_getHandler('member');
28
29
if ('form' == $op) {
30
    $xoopsOption['template_main'] = 'xoopsmembers_searchform.tpl';
31
    include XOOPS_ROOT_PATH . '/header.php';
32
33
    $total          = $memberHandler->getUserCount(new \Criteria('level', 0, '>'));
34
35
    include_once XOOPS_ROOT_PATH . '/class/xoopsformloader.php';
36
37
    $form        = new \XoopsThemeForm('', 'searchform', 'searchmembers.php');
38
    $uname_text  = new \XoopsFormText('', 'user_uname', 30, 60);
39
    $uname_match = new \XoopsFormSelectMatchOption('', 'user_uname_match');
40
    $uname_tray  = new \XoopsFormElementTray(_MD_XOOPSMEMBERS_UNAME, '&nbsp;');
41
    $uname_tray->addElement($uname_match);
42
    $uname_tray->addElement($uname_text);
43
    $form->addElement($uname_tray);
44
45
    if (1 == $xoopsModuleConfig['displayrealname']){
46
    $name_text  = new \XoopsFormText('', 'user_name', 30, 60);
47
    $name_match = new \XoopsFormSelectMatchOption('', 'user_name_match');
48
    $name_tray  = new \XoopsFormElementTray(_MD_XOOPSMEMBERS_REALNAME, '&nbsp;');
49
    $name_tray->addElement($name_match);
50
    $name_tray->addElement($name_text);
51
    $form->addElement($name_tray);
52
    }
53
54
    if (1 == $xoopsModuleConfig['displayemail']){
55
    $email_text  = new \XoopsFormText('', 'user_email', 30, 60);
56
    $email_match = new \XoopsFormSelectMatchOption('', 'user_email_match');
57
    $email_tray  = new \XoopsFormElementTray(_MD_XOOPSMEMBERS_EMAIL, '&nbsp;');
58
    $email_tray->addElement($email_match);
59
    $email_tray->addElement($email_text);
60
    $form->addElement($email_tray);
61
    }
62
63
    if (1 == $xoopsModuleConfig['displayurl']){
64
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_URLCONTAINS, 'user_url', 30, 100));
65
    }
66
    if (1 == $xoopsModuleConfig['displayfrom']){
67
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_LOCATIONCONTAINS, 'user_from', 30, 100));
68
    }
69
    if (1 == $xoopsModuleConfig['displayoccupation']){
70
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_OCCUPATIONCONTAINS, 'user_occ', 30, 100));
71
    }
72
    if (1 == $xoopsModuleConfig['displayinterest']){
73
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_INTERESTCONTAINS, 'user_intrest', 30, 100));
74
    }
75
    if (1 == $xoopsModuleConfig['displaylastlogin']){
76
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_LASTLOGMORE, 'user_lastlog_more', 10, 5));
77
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_LASTLOGLESS, 'user_lastlog_less', 10, 5));
78
    }
79
    if (1 == $xoopsModuleConfig['displayregdate']){
80
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_REGMORE, 'user_reg_more', 10, 5));
81
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_REGLESS, 'user_reg_less', 10, 5));
82
    }
83
    if (1 == $xoopsModuleConfig['displayposts']){
84
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_POSTSMORE, 'user_posts_more', 10, 5));
85
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_POSTSLESS, 'user_posts_less', 10, 5));
86
    }
87
88
    $sort_select = new \XoopsFormSelect(_MD_XOOPSMEMBERS_SORT, 'user_sort');
89
    $sort_select->addOptionArray(['uname' => _MD_XOOPSMEMBERS_UNAME, 'name' => _MD_XOOPSMEMBERS_REALNAME, 'last_login' => _MD_XOOPSMEMBERS_LASTLOGIN, 'user_regdate' => _MD_XOOPSMEMBERS_REGDATE, 'posts' => _MD_XOOPSMEMBERS_POSTS]);
90
    $form->addElement($sort_select);
91
92
    $order_select = new \XoopsFormSelect(_MD_XOOPSMEMBERS_ORDER, 'user_order');
93
    $order_select->addOptionArray(['ASC' => _MD_XOOPSMEMBERS_ASC, 'DESC' => _MD_XOOPSMEMBERS_DESC]);
94
    $form->addElement($order_select);
95
96
    $form->addElement(new \XoopsFormText(_MD_XOOPSMEMBERS_LIMIT, 'limit', 6, 2));
97
    $form->addElement(new \XoopsFormHidden('op', 'submit'));
98
    $form->addElement(new \XoopsFormButton('', 'user_submit', _SUBMIT, 'submit'));
99
    $form->assign($xoopsTpl);
100
    $xoopsTpl->assign('totalmember', $total);
101
}
102
103
if ('submit' == $op) {
104
    $xoopsOption['template_main'] = 'xoopsmembers_searchresults.tpl';
105
    include XOOPS_ROOT_PATH . '/header.php';
106
107
    $iamadmin = $xoopsUserIsAdmin;
108
    $myts     = MyTextSanitizer::getInstance();
109
    $criteria = new \CriteriaCompo();
110
111
    if (!empty($_POST['user_uname'])) {
112
        $match = (!empty($_POST['user_uname_match'])) ? (int)$_POST['user_uname_match'] : XOOPS_MATCH_START;
113
        $ret   = $myts->addSlashes(trim($_POST['user_uname']));
114
        xoops_Criteria($criteria, 'uname', $ret, $match);
115
    }
116
117
    if (!empty($_POST['user_name'])) {
118
        $match = (!empty($_POST['user_name_match'])) ? (int)$_POST['user_name_match'] : XOOPS_MATCH_START;
119
        $ret   = $myts->addSlashes(trim($_POST['user_uname']));
120
        xoops_Criteria($criteria, 'name', $ret, $match);
121
    }
122
123
    if (!empty($_POST['user_email'])) {
124
        $match = (!empty($_POST['user_email_match'])) ? (int)$_POST['user_email_match'] : XOOPS_MATCH_START;
125
        $ret   = $myts->addSlashes(trim($_POST['user_email']));
126
        xoops_Criteria($criteria, 'name', $ret, $match);
127
        if (!$iamadmin) {
128
            $criteria->add(new \Criteria('user_viewemail', 1));
129
        }
130
    }
131
132
    if (!empty($_POST['user_url'])) {
133
        $url = formatURL(trim($_POST['user_url']));
134
        $criteria->add(new \Criteria('url', $myts->addSlashes($url) . '%', 'LIKE'));
135
    }
136
137
    if (!empty($_POST['user_from'])) {
138
        $criteria->add(new \Criteria('user_from', '%' . $myts->addSlashes(trim($_POST['user_from'])) . '%', 'LIKE'));
139
    }
140
141
    if (!empty($_POST['user_intrest'])) {
142
        $criteria->add(new \Criteria('user_intrest', '%' . $myts->addSlashes(trim($_POST['user_intrest'])) . '%', 'LIKE'));
143
    }
144
145
    if (!empty($_POST['user_occ'])) {
146
        $criteria->add(new \Criteria('user_occ', '%' . $myts->addSlashes(trim($_POST['user_occ'])) . '%', 'LIKE'));
147
    }
148
149
    if (!empty($_POST['user_lastlog_more']) && is_numeric($_POST['user_lastlog_more'])) {
150
        $f_user_lastlog_more = (int)trim($_POST['user_lastlog_more']);
151
        $time                = time() - (60 * 60 * 24 * $f_user_lastlog_more);
152
        if ($time > 0) {
153
            $criteria->add(new \Criteria('last_login', $time, '<'));
154
        }
155
    }
156
157
    if (!empty($_POST['user_lastlog_less']) && is_numeric($_POST['user_lastlog_less'])) {
158
        $f_user_lastlog_less = (int)trim($_POST['user_lastlog_less']);
159
        $time                = time() - (60 * 60 * 24 * $f_user_lastlog_less);
160
        if ($time > 0) {
161
            $criteria->add(new \Criteria('last_login', $time, '>'));
162
        }
163
    }
164
165
    if (!empty($_POST['user_reg_more']) && is_numeric($_POST['user_reg_more'])) {
166
        $f_user_reg_more = (int)trim($_POST['user_reg_more']);
167
        $time            = time() - (60 * 60 * 24 * $f_user_reg_more);
168
        if ($time > 0) {
169
            $criteria->add(new \Criteria('user_regdate', $time, '<'));
170
        }
171
    }
172
173
    if (!empty($_POST['user_reg_less']) && is_numeric($_POST['user_reg_less'])) {
174
        $f_user_reg_less = (int)$_POST['user_reg_less'];
175
        $time            = time() - (60 * 60 * 24 * $f_user_reg_less);
176
        if ($time > 0) {
177
            $criteria->add(new \Criteria('user_regdate', $time, '>'));
178
        }
179
    }
180
181
    if (isset($_POST['user_posts_more']) && is_numeric($_POST['user_posts_more'])) {
182
        $criteria->add(new \Criteria('posts', (int)$_POST['user_posts_more'], '>'));
183
    }
184
185
    if (!empty($_POST['user_posts_less']) && is_numeric($_POST['user_posts_less'])) {
186
        $criteria->add(new \Criteria('posts', (int)$_POST['user_posts_less'], '<'));
187
    }
188
189
    $criteria->add(new \Criteria('level', 0, '>'));
190
    $validsort = ['uname', 'email', 'last_login', 'user_regdate', 'posts'];
191
    $sort      = (!in_array($_POST['user_sort'], $validsort)) ? 'uname' : $_POST['user_sort'];
192
    $order     = 'ASC';
193
    if (isset($_POST['user_order']) && 'DESC' == $_POST['user_order']) {
194
        $order = 'DESC';
195
    }
196
    $limit = (!empty($_POST['limit'])) ? (int)$_POST['limit'] : 20;
197
    if (0 == $limit || $limit > 50) {
198
        $limit = 50;
199
    }
200
201
    $start          = (!empty($_POST['start'])) ? (int)$_POST['start'] : 0;
202
    $total          = $memberHandler->getUserCount($criteria);
203
    $xoopsTpl->assign('total_found', $total);
204
205
    if (0 == $total) {
206
    } elseif ($start < $total) {
207
        if ($iamadmin) {
208
            $xoopsTpl->assign('is_admin', true);
209
        }
210
        $criteria->setSort($sort);
211
        $criteria->setOrder($order);
212
        $criteria->setStart($start);
213
        $criteria->setLimit($limit);
214
        $foundusers = $memberHandler->getUsers($criteria, true);
215
        foreach (array_keys($foundusers) as $j) {
216
            $userdata['avatar']   = $foundusers[$j]->getVar('user_avatar');
217
            $userdata['realname'] = $foundusers[$j]->getVar('name');
218
            $userdata['name']     = $foundusers[$j]->getVar('uname');
219
            $userdata['id']       = $foundusers[$j]->getVar('uid');
220
            if (1 == $foundusers[$j]->getVar('user_viewemail') || $iamadmin) {
221
                $userdata['email'] = '<a href="mailto:' . $foundusers[$j]->getVar('email') . '"><img src="' . XOOPS_URL . '/images/icons/email.gif" border="0" alt="' . sprintf(_SENDEMAILTO, $foundusers[$j]->getVar('uname', 'e')) . '" ></a>';
222
            } else {
223
                $userdata['email'] = '&nbsp;';
224
            }
225
            if ($xoopsUser) {
226
                $userdata['pmlink'] = '<a href="javascript:openWithSelfMain(\'' . XOOPS_URL . '/pmlite.php?send2=1&amp;to_userid=' . $foundusers[$j]->getVar('uid') . '\',\'pmlite\',450,370);"><img src="' . XOOPS_URL . '/images/icons/pm.gif" border="0" alt="' . sprintf(_SENDPMTO, $foundusers[$j]->getVar('uname', 'e')) . '" ></a>';
227
            } else {
228
                $userdata['pmlink'] = '&nbsp;';
229
            }
230
            if ('' != $foundusers[$j]->getVar('url', 'e')) {
231
                $userdata['website'] = '<a href="' . $foundusers[$j]->getVar('url', 'e') . '" target="_blank"><img src="' . XOOPS_URL . '/images/icons/www.gif" border="0" alt="' . _VISITWEBSITE . '" ></a>';
232
            } else {
233
                $userdata['website'] = '&nbsp;';
234
            }
235
            $userdata['registerdate'] = formatTimestamp($foundusers[$j]->getVar('user_regdate'), 's');
236
            if (0 != $foundusers[$j]->getVar('last_login')) {
237
                $userdata['lastlogin'] = formatTimestamp($foundusers[$j]->getVar('last_login'), 'm');
238
            } else {
239
                $userdata['lastlogin'] = _MD_XOOPSMEMBERS_NEVERLOGIN;
240
            }
241
            $userdata['posts'] = $foundusers[$j]->getVar('posts');
242
            if ($iamadmin) {
243
                $userdata['adminlink'] = '<a href="' . XOOPS_URL . '/modules/system/admin.php?fct=users&amp;uid=' . $foundusers[$j]->getVar('uid') . '&amp;op=users_edit">' . '<img src=' . $pathIcon16 . '/edit.png' . " alt='" . _EDIT . "' title='" . _EDIT . "' >"
244
245
                                         . '</a>  <a href="' . XOOPS_URL . '/modules/system/admin.php?fct=users&amp;op=users_delete&amp;uid=' . $foundusers[$j]->getVar('uid') . '">' . '<img src=' . $pathIcon16 . '/delete.png' . " alt='" . _DELETE . "' title='" . _DELETE . "' >" . '</a>';
246
            }
247
			$userdata['location']       = $foundusers[$j]->getVar('user_from');
248
			$userdata['occupation']     = $foundusers[$j]->getVar('user_occ');
249
			$userdata['interest']       = $foundusers[$j]->getVar('user_intrest');
250
            $xoopsTpl->append('users', $userdata);
251
        }
252
253
        $totalpages = ceil($total / $limit);
254
        if ($totalpages > 1) {
255
            $hiddenform = '<form name="findnext" action="searchmembers.php" method="post">';
256
            foreach ($_POST as $k => $v) {
257
                $hiddenform .= '<input type="hidden" name="' . $myts->htmlSpecialChars($k) . '" value="' . $myts->previewTarea($v) . '" >';
258
            }
259
            if (!isset($_POST['limit'])) {
260
                $hiddenform .= '<input type="hidden" name="limit" value="' . $limit . '" >';
261
            }
262
            if (!isset($_POST['start'])) {
263
                $hiddenform .= '<input type="hidden" name="start" value="' . $start . '" >';
264
            }
265
            $prev = $start - $limit;
266
            if ($start - $limit >= 0) {
267
                $hiddenform .= '<a href="#0" onclick="javascript:document.findnext.start.value=' . $prev . ';document.findnext.submit();">' . _MD_XOOPSMEMBERS_PREVIOUS . '</a>&nbsp;';
268
            }
269
            $counter     = 1;
270
            $currentpage = ($start + $limit) / $limit;
271
            while ($counter <= $totalpages) {
272
                if ($counter == $currentpage) {
273
                    $hiddenform .= '<b>' . $counter . '</b> ';
274
                } elseif (($counter > $currentpage - 4 && $counter < $currentpage + 4) || 1 == $counter || $counter == $totalpages) {
275
                    if ($counter == $totalpages && $currentpage < $totalpages - 4) {
276
                        $hiddenform .= '... ';
277
                    }
278
                    $hiddenform .= '<a href="#' . $counter . '" onclick="javascript:document.findnext.start.value=' . ($counter - 1) * $limit . ';document.findnext.submit();">' . $counter . '</a> ';
279
                    if (1 == $counter && $currentpage > 5) {
280
                        $hiddenform .= '... ';
281
                    }
282
                }
283
                $counter++;
284
            }
285
            $next = $start + $limit;
286
            if ($total > $next) {
287
                $hiddenform .= '&nbsp;<a href="#' . $total . '" onclick="javascript:document.findnext.start.value=' . $next . ';document.findnext.submit();">' . _MD_XOOPSMEMBERS_NEXT . '</a>';
288
            }
289
            $hiddenform .= '</form>';
290
            $xoopsTpl->assign('pagenav', $hiddenform);
291
            $xoopsTpl->assign('lang_numfound', sprintf(_MD_XOOPSMEMBERS_USERSFOUND, $total));
292
        }
293
    }
294
}
295
296
require __DIR__ . '/footer.php';
297
require_once XOOPS_ROOT_PATH . '/footer.php';
298
exit();
299
300
/**
301
 * xoops_Criteria()
302
 *
303
 * @param \CriteriaCompo $criteria
304
 * @param string $name
305
 * @param string $ret
306
 * @param string $match
307
 * @return void
308
 */
309
function xoops_Criteria(&$criteria, $name = '', $ret = '', $match = '')
0 ignored issues
show
The parameter $criteria is not used and could be removed. ( Ignorable by Annotation )

If this is a false-positive, you can also ignore this issue in your code via the ignore-unused  annotation

309
function xoops_Criteria(/** @scrutinizer ignore-unused */ &$criteria, $name = '', $ret = '', $match = '')

This check looks for parameters that have been defined for a function or method, but which are not used in the method body.

Loading history...
310
{
311
    global $criteria;
312
313
    switch ($match) {
314
        case XOOPS_MATCH_START:
315
            $criteria->add(new \Criteria($name, $ret . '%', 'LIKE'));
316
            break;
317
        case XOOPS_MATCH_END:
318
            $criteria->add(new \Criteria($name, '%' . $ret . '%', 'LIKE'));
319
            break;
320
        case XOOPS_MATCH_EQUAL:
321
            $criteria->add(new \Criteria($name, $ret));
322
            break;
323
        case XOOPS_MATCH_CONTAIN:
324
            $criteria->add(new \Criteria($name, '%' . $ret . '%', 'LIKE'));
325
            break;
326
    }
327
}
328