Passed
Push — master ( c8181e...bb1610 )
by
unknown
02:36
created
view.php 1 patch
Indentation   +3 added lines, -3 removed lines patch added patch discarded remove patch
@@ -69,7 +69,7 @@  discard block
 block discarded – undo
69 69
                 <source src="/musicfiles/' . $filename . '">
70 70
                 </audio>';
71 71
             } else if($type == "image") {
72
-              echo "<img style='max-width: 100%;' src='/images/" . $filename . "'>";
72
+                echo "<img style='max-width: 100%;' src='/images/" . $filename . "'>";
73 73
             } else if($type == "midi") {
74 74
                 echo "Note: It may take a few seconds for the MIDI to load.<br>";
75 75
                 echo "<a href='#' onClick=\"MIDIjs.play('/midis/" . $filename . "');\">Play " . $title . "</a>";
@@ -202,9 +202,9 @@  discard block
 block discarded – undo
202 202
             <script type="text/javascript" src="//cdn.jsdelivr.net/gh/deskjet/chiptune2.js@master/chiptune2.js"></script>';
203 203
             echo '<a class="song" data-modurl="/midis/' . $filename . '" href="#">Play ' . $title . '</a>';
204 204
             } else if($type == "news" || $type == "review") {
205
-              //do nothing
205
+                //do nothing
206 206
             } else if($type == "video") {
207
-              echo ' <video width="640" height="400" controls>
207
+                echo ' <video width="640" height="400" controls>
208 208
                   <source src="/videos/' . $filename . '" type="video/mp4">
209 209
                 </video> ';
210 210
             } else {
Please login to merge, or discard this patch.
func/bbcode.php 1 patch
Indentation   +121 added lines, -121 removed lines patch added patch discarded remove patch
@@ -14,32 +14,32 @@  discard block
 block discarded – undo
14 14
 
15 15
 class BBCode
16 16
 {
17
-  // Tag aliases.  Item on left translates to item on right.
18
-  const TAG_ALIAS = [
17
+    // Tag aliases.  Item on left translates to item on right.
18
+    const TAG_ALIAS = [
19 19
     'url' => 'a',
20 20
     'code' => 'pre',
21 21
     'quote' => 'blockquote',
22 22
     '*' => 'li'
23
-  ];
23
+    ];
24 24
 
25
-  // helper function: normalize a potential "tag"
26
-  //  convert to lowercase and check against the alias list
27
-  //  returns a named array with details about the tag
28
-  static private function decode_tag($input) : array
29
-  {
25
+    // helper function: normalize a potential "tag"
26
+    //  convert to lowercase and check against the alias list
27
+    //  returns a named array with details about the tag
28
+    static private function decode_tag($input) : array
29
+    {
30 30
     // first determine if it's opening on closing tag, then substr out the inner portion
31 31
     if ($input[1] === '/') {
32
-      $open = 0;
33
-      $inner = substr($input, 2, -1);
32
+        $open = 0;
33
+        $inner = substr($input, 2, -1);
34 34
     } else {
35
-      $open = 1;
36
-      $inner = substr($input, 1, -1);
35
+        $open = 1;
36
+        $inner = substr($input, 1, -1);
37 37
     }
38 38
 
39 39
     // oneliner to burst inner by spaces, then burst each of those by equals signs
40 40
     $params = array_map(
41
-      function(&$a) { return explode('=', $a, 2); },
42
-      explode(' ', $inner));
41
+        function(&$a) { return explode('=', $a, 2); },
42
+        explode(' ', $inner));
43 43
 
44 44
     // first "param" is special - it's the tag name and (optionally) the default arg
45 45
     $first = array_shift($params);
@@ -47,29 +47,29 @@  discard block
 block discarded – undo
47 47
     // tag name
48 48
     $name = strtolower($first[0]);
49 49
     if (isset(self::TAG_ALIAS[$name])) {
50
-      $name = self::TAG_ALIAS[$name];
50
+        $name = self::TAG_ALIAS[$name];
51 51
     }
52 52
 
53 53
     // "default" (unnamed) argument
54 54
     $args = null;
55 55
     if (isset ($first[1])) {
56
-      $args['default'] = $first[1];
56
+        $args['default'] = $first[1];
57 57
     }
58 58
 
59 59
     // finally, put the rest of the args in the list
60 60
     //array_walk( $params, function(&$a, $i, &$args) { print_r($args); $args[strtolower($a[1])] = $a[0]; }, $args);
61 61
     foreach ($params as &$param) {
62
-      $k = isset($param[0]) ? strtolower($param[0]) : '';
63
-      $v = isset($param[1]) ? $param[1] : '';
64
-      $args[$k] = $v;
62
+        $k = isset($param[0]) ? strtolower($param[0]) : '';
63
+        $v = isset($param[1]) ? $param[1] : '';
64
+        $args[$k] = $v;
65 65
     }
66 66
 
67 67
     return [ 'name' => $name, 'open' => $open, 'args' => $args ];
68
-  }
68
+    }
69 69
 
70
-  // helper function: normalize HTML entities, with newline handling
71
-  static private function encode($input) : string
72
-  {
70
+    // helper function: normalize HTML entities, with newline handling
71
+    static private function encode($input) : string
72
+    {
73 73
     // break substring into individual unicode chars
74 74
     $characters = preg_split('//u', $input, null, PREG_SPLIT_NO_EMPTY);
75 75
 
@@ -79,19 +79,19 @@  discard block
 block discarded – undo
79 79
     foreach ($characters as &$ch)
80 80
     {
81 81
         if ($ch === '\n') {
82
-          $output .= "\n<br>";
82
+            $output .= "\n<br>";
83 83
         }
84 84
 
85 85
         if ($ch === '<') {
86
-          $output .= '&lt;';
86
+            $output .= '&lt;';
87 87
         } elseif ($ch === '>') {
88
-          $output .= '&gt;';
88
+            $output .= '&gt;';
89 89
         } elseif ($ch === '&') {
90
-          $output .= '&amp;';
90
+            $output .= '&amp;';
91 91
         } elseif ($ch === "\u{00A0}") {
92
-          $output .= '&nbsp;';
92
+            $output .= '&nbsp;';
93 93
         } else {
94
-          $output .= $ch;
94
+            $output .= $ch;
95 95
         }
96 96
     }
97 97
 
@@ -100,11 +100,11 @@  discard block
 block discarded – undo
100 100
 
101 101
 
102 102
     return $output;
103
-  }
103
+    }
104 104
 
105
-  // Renders a BBCode string to HTML, for inclusion into a document.
106
-  static public function bbcode_to_html($input) : string
107
-  {
105
+    // Renders a BBCode string to HTML, for inclusion into a document.
106
+    static public function bbcode_to_html($input) : string
107
+    {
108 108
     // split input string into array using regex, UTF-8 aware
109 109
     //  this should give us tokens to work with
110 110
 
@@ -113,9 +113,9 @@  discard block
 block discarded – undo
113 113
     // ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789 -._~:/?#@!$&'()*+,;=%
114 114
     // Square brackets are technically allowed, but excluded here, because they interfere.
115 115
     $match_count = preg_match_all("/\[[A-Za-z0-9 \-._~:\/?#@!$&'()*+,;=%]+\]/u",
116
-      $input, $matches, PREG_OFFSET_CAPTURE);
116
+        $input, $matches, PREG_OFFSET_CAPTURE);
117 117
     if ($match_count === FALSE) {
118
-      throw new RuntimeException('Fatal error in preg_match_all for BBCode tags');
118
+        throw new RuntimeException('Fatal error in preg_match_all for BBCode tags');
119 119
     }
120 120
 
121 121
     // begin with the empty string
@@ -125,31 +125,31 @@  discard block
 block discarded – undo
125 125
     $stack = [];
126 126
     for ($match_idx = 0; $match_idx < $match_count; $match_idx ++)
127 127
     {
128
-      list($match, $offset) = $matches[0][$match_idx];
128
+        list($match, $offset) = $matches[0][$match_idx];
129 129
 
130
-      // pick up chars between tags and HTML-encode them
131
-      $output .= self::encode(substr($input, $input_ptr, $offset - $input_ptr));
132
-      // advance input_ptr to just past the current tag
133
-      $input_ptr = $offset + strlen($match);
130
+        // pick up chars between tags and HTML-encode them
131
+        $output .= self::encode(substr($input, $input_ptr, $offset - $input_ptr));
132
+        // advance input_ptr to just past the current tag
133
+        $input_ptr = $offset + strlen($match);
134 134
 
135
-      // decode the tag
136
-      list('name' => $name, 'open' => $open, 'args' => $args) = self::decode_tag($match);
135
+        // decode the tag
136
+        list('name' => $name, 'open' => $open, 'args' => $args) = self::decode_tag($match);
137 137
 
138
-      if (! $open) {
138
+        if (! $open) {
139 139
         // CLOSING TAG
140 140
 
141 141
         // Search the tag stack and see if the opening tag was pushed into it
142 142
         if (array_search($name, $stack, TRUE) === FALSE) {
143
-          // Attempted to close a tag that was not on the stack!
144
-          $output = $output . self::encode($match);
143
+            // Attempted to close a tag that was not on the stack!
144
+            $output = $output . self::encode($match);
145 145
         } else {
146
-          //pop repeatedly until we pop the tag, and close everything on the way
147
-          do {
146
+            //pop repeatedly until we pop the tag, and close everything on the way
147
+            do {
148 148
             $popped_name = array_pop($stack);
149 149
             $output = $output . '</' . $popped_name . '>';
150
-          } while ($name !== $popped_name);
150
+            } while ($name !== $popped_name);
151 151
         }
152
-      } else {
152
+        } else {
153 153
         // OPENING TAG
154 154
 
155 155
         // Big if / elseif ladder to handle each tag
@@ -157,77 +157,77 @@  discard block
 block discarded – undo
157 157
             $name === 'blockquote' ||
158 158
             $name === 'ol' || $name === 'ul' ||
159 159
             $name === 'table') {
160
-          // Simple tags (no validation or alternate modes)
161
-          $stack[] = $name;
162
-          $output = $output . '<' . $name . '>';
160
+            // Simple tags (no validation or alternate modes)
161
+            $stack[] = $name;
162
+            $output = $output . '<' . $name . '>';
163 163
         } elseif ($name === 'li') {
164
-          // Disallow [li] outside of [ol] or [ul]
165
-          if (array_search('ol', $stack, TRUE) !== FALSE ||
164
+            // Disallow [li] outside of [ol] or [ul]
165
+            if (array_search('ol', $stack, TRUE) !== FALSE ||
166 166
               array_search('ul', $stack, TRUE) !== FALSE) {
167 167
             $stack[] = 'li';
168 168
             $output .= '<li>';
169
-          } else {
169
+            } else {
170 170
             $output .= self::encode($match);
171
-          }
171
+            }
172 172
         } elseif ($name === 'tr') {
173
-          // Disallow [tr] outside of [table]
174
-          if (array_search('table', $stack, TRUE) !== FALSE) {
173
+            // Disallow [tr] outside of [table]
174
+            if (array_search('table', $stack, TRUE) !== FALSE) {
175 175
             $stack[] = 'tr';
176 176
             $output .= '<tr>';
177
-          } else {
177
+            } else {
178 178
             $output .= self::encode($match);
179
-          }
179
+            }
180 180
         } elseif ($name === 'td' || $name === 'th') {
181
-          // Disallow [th] / [td] outside of [tr] outside of [table]
182
-          $tr_index = array_search('tr', $stack, TRUE);
183
-          $table_index = array_search('table', $stack, TRUE);
184
-          if ($tr_index !== FALSE && $table_index !== FALSE && $table_index < $tr_index) {
181
+            // Disallow [th] / [td] outside of [tr] outside of [table]
182
+            $tr_index = array_search('tr', $stack, TRUE);
183
+            $table_index = array_search('table', $stack, TRUE);
184
+            if ($tr_index !== FALSE && $table_index !== FALSE && $table_index < $tr_index) {
185 185
             $stack[] = $name;
186 186
             $output = $output . '<' . $name . '>';
187
-          } else {
187
+            } else {
188 188
             $output .= self::encode($match);
189
-          }
189
+            }
190 190
 
191 191
         } elseif ($name === 'font') {
192
-          // Font size adjustment.  This requires an argument, one of "size" or "color" (or both).
193
-          $font_param = [];
192
+            // Font size adjustment.  This requires an argument, one of "size" or "color" (or both).
193
+            $font_param = [];
194 194
 
195
-          if (isset ($args['size'])) {
195
+            if (isset ($args['size'])) {
196 196
 //TODO: size validation
197 197
             $font_param['font-size'] = $args['size'];
198
-          }
199
-          if (isset ($args['color'])) {
198
+            }
199
+            if (isset ($args['color'])) {
200 200
 //TODO: color validation
201 201
             $font_param['color'] = $args['color'];
202
-          }
202
+            }
203 203
 //TODO: handle bad settings
204 204
 
205
-          if (! empty($font_param)) {
205
+            if (! empty($font_param)) {
206 206
             $stack[] = 'font';
207 207
 
208 208
             // append all css_style params
209 209
             $css_style = [];
210 210
             foreach ($font_param as $name=>$value) {
211
-              $css_style[] = $name . ': ' . $value;
211
+                $css_style[] = $name . ': ' . $value;
212 212
             }
213 213
             $output = $output . '<span style="' . implode(';', $css_style) . '">';
214
-          } else {
214
+            } else {
215 215
             // Font tag without good args is useless.
216 216
             $output .= self::encode($match);
217
-          }
217
+            }
218 218
 
219 219
         // SPECIAL TAG HANDLING
220 220
         } elseif ($name === 'pre') {
221
-          // [pre] / [code] put us into RAW mode, where nothing is parsed except [/code]
221
+            // [pre] / [code] put us into RAW mode, where nothing is parsed except [/code]
222 222
 
223
-          for ($i = $match_idx + 1; $i < $match_count; $i ++)
224
-          {
223
+            for ($i = $match_idx + 1; $i < $match_count; $i ++)
224
+            {
225 225
             list($search_match, $search_offset) = $matches[0][$i];
226 226
             $search_tag = self::decode_tag($search_match);
227 227
             if (! $search_tag['open'] && $search_tag['name'] === 'pre') { break; }
228
-          }
228
+            }
229 229
 
230
-          if ($i < $match_count) {
230
+            if ($i < $match_count) {
231 231
             // successfully found ending tag
232 232
 
233 233
             // encode everything contained between here and there
@@ -236,31 +236,31 @@  discard block
 block discarded – undo
236 236
             $input_ptr = $search_offset + strlen($search_match);
237 237
             // update search position
238 238
             $match_idx = $i;
239
-          } else {
239
+            } else {
240 240
             // Unrecognized type!
241 241
             $output .= self::encode($match);
242
-          }
242
+            }
243 243
         } elseif ($name === 'a') {
244
-          // URL handling.  Two modes: [a=url]title[/a] and [a]url[/a].
245
-          //  Verify enclosing value first.
246
-          $buffer = null;
247
-          $i = $match_idx + 1;
248
-          if ($i < $match_count) {
244
+            // URL handling.  Two modes: [a=url]title[/a] and [a]url[/a].
245
+            //  Verify enclosing value first.
246
+            $buffer = null;
247
+            $i = $match_idx + 1;
248
+            if ($i < $match_count) {
249 249
             list($search_match, $search_offset) = $matches[0][$i];
250 250
             $search_tag = self::decode_tag($search_match);
251 251
             if (! $search_tag['open'] && $search_tag['name'] === 'a') {
252
-              $buffer = substr($input, $input_ptr, $search_offset - $input_ptr);
252
+                $buffer = substr($input, $input_ptr, $search_offset - $input_ptr);
253
+            }
253 254
             }
254
-          }
255 255
 
256
-          // matched something in the middle
257
-          if (isset($buffer)) {
256
+            // matched something in the middle
257
+            if (isset($buffer)) {
258 258
             if (isset($args['default'])) {
259
-              // $buffer is the title
260
-              $url = $args['default'];
259
+                // $buffer is the title
260
+                $url = $args['default'];
261 261
             } else {
262
-              // $buffer is the url
263
-              $url = $buffer;
262
+                // $buffer is the url
263
+                $url = $buffer;
264 264
             }
265 265
             // emit the tag
266 266
             $output = $output . '<a href="' . $url . '">' . self::encode($buffer) . '</a>';
@@ -268,43 +268,43 @@  discard block
 block discarded – undo
268 268
             $input_ptr = $search_offset + strlen($search_match);
269 269
             // update search position
270 270
             $match_idx = $i;
271
-          } else {
271
+            } else {
272 272
             // Unrecognized type!
273 273
             $output .= self::encode($match);
274
-          }
274
+            }
275 275
 
276 276
         } elseif ($name === 'img') {
277
-          // image handling.  [img (optional=args go=here)]url[/img].
278
-          //  Verify enclosing value first.
279
-          $buffer = null;
280
-          $i = $match_idx + 1;
281
-          if ($i < $match_count) {
277
+            // image handling.  [img (optional=args go=here)]url[/img].
278
+            //  Verify enclosing value first.
279
+            $buffer = null;
280
+            $i = $match_idx + 1;
281
+            if ($i < $match_count) {
282 282
             list($search_match, $search_offset)  = $matches[0][$i];
283 283
             $search_tag = self::decode_tag($search_match);
284 284
             if (! $search_tag['open'] && $search_tag['name'] === 'img') {
285
-              $buffer = substr($input, $input_ptr, $search_offset - $input_ptr);
285
+                $buffer = substr($input, $input_ptr, $search_offset - $input_ptr);
286
+            }
286 287
             }
287
-          }
288 288
 
289
-          // matched something in the middle
290
-          if (isset($buffer)) {
289
+            // matched something in the middle
290
+            if (isset($buffer)) {
291 291
             // Image size adjustment - accepts width and height
292 292
             $img_param = [];
293 293
 
294 294
             if (isset ($args['width'])) {
295
-  //TODO: size validation
296
-              $img_param['width'] = $args['width'];
295
+    //TODO: size validation
296
+                $img_param['width'] = $args['width'];
297 297
             }
298 298
             if (isset ($args['height'])) {
299
-  //TODO: size validation
300
-              $img_param['height'] = $args['height'];
299
+    //TODO: size validation
300
+                $img_param['height'] = $args['height'];
301 301
             }
302 302
 //TODO: handle bad settings
303 303
 
304 304
             // emit the tag
305 305
             $output = $output . '<img src="' . $buffer . '"';
306 306
             foreach ($img_param as $name=>$value) {
307
-              $output = $output . ' ' . $name . '="' . $value . '"';
307
+                $output = $output . ' ' . $name . '="' . $value . '"';
308 308
             }
309 309
             $output .= '>';
310 310
 
@@ -312,18 +312,18 @@  discard block
 block discarded – undo
312 312
             $input_ptr = $search_offset + strlen($search_match);
313 313
             // update search position
314 314
             $match_idx = $i;
315
-          } else {
315
+            } else {
316 316
             // Unrecognized type!
317 317
             $output .= self::encode($match);
318
-          }
318
+            }
319 319
 
320 320
         // ADD CUSTOM TAGS HERE
321 321
 
322 322
         } else {
323
-          // Unrecognized type!
324
-          $output .= self::encode($match);
323
+            // Unrecognized type!
324
+            $output .= self::encode($match);
325
+        }
325 326
         }
326
-      }
327 327
     }
328 328
 
329 329
     // pick up any stray chars and HTML-encode them
@@ -332,16 +332,16 @@  discard block
 block discarded – undo
332 332
     // Close any remaining stray tags left on the stack
333 333
     while ($stack)
334 334
     {
335
-      $tag = array_pop($stack);
336
-      $output = $output . '</' . $tag . '>';
335
+        $tag = array_pop($stack);
336
+        $output = $output . '</' . $tag . '>';
337 337
     }
338 338
 
339 339
     return $output;
340
-  }
340
+    }
341 341
 }
342 342
 
343 343
 // procedural
344 344
 function bbcode_to_html($input) : string
345 345
 {
346
-  return BBCode::bbcode_to_html($input);
346
+    return BBCode::bbcode_to_html($input);
347 347
 }
Please login to merge, or discard this patch.
func/func.php 1 patch
Indentation   +101 added lines, -101 removed lines patch added patch discarded remove patch
@@ -12,136 +12,136 @@
 block discarded – undo
12 12
 }
13 13
 
14 14
 function validateCSS($validate) {
15
-	$DISALLOWED = array("<?php", "?>", "behavior: url", ".php", "@import", "@\import", "@/import"); 
15
+    $DISALLOWED = array("<?php", "?>", "behavior: url", ".php", "@import", "@\import", "@/import"); 
16 16
 
17
-	$validated = str_replace($DISALLOWED, "", $validate);
17
+    $validated = str_replace($DISALLOWED, "", $validate);
18 18
     return $validated;
19 19
 }
20 20
 function validateMarkdown($comment) {
21
-	$markdown = new Michelf\Markdown;
22
-	$markdown->no_markup = "true";
23
-	$transformed = $markdown->transform($comment);
24
-	return preg_replace(
25
-		"/<a href=(?:'|\")javascript:(.*?)(?:'|\")>(.*?)<\/a>/i",
26
-		"Attempted XSS: $2 ($1)",
27
-		$transformed
28
-	);
21
+    $markdown = new Michelf\Markdown;
22
+    $markdown->no_markup = "true";
23
+    $transformed = $markdown->transform($comment);
24
+    return preg_replace(
25
+        "/<a href=(?:'|\")javascript:(.*?)(?:'|\")>(.*?)<\/a>/i",
26
+        "Attempted XSS: $2 ($1)",
27
+        $transformed
28
+    );
29 29
 }
30 30
 
31 31
 function validateCaptcha($privatekey, $response) {
32
-	$responseData = json_decode(file_get_contents('https://www.google.com/recaptcha/api/siteverify?secret='.$privatekey.'&response='.$response));
33
-	return $responseData->success;
32
+    $responseData = json_decode(file_get_contents('https://www.google.com/recaptcha/api/siteverify?secret='.$privatekey.'&response='.$response));
33
+    return $responseData->success;
34 34
 }
35 35
 
36 36
 function requireLogin() {
37
-	if (!isset($_SESSION['user'])) {
38
-		header("Location: /login.php?r_login"); die();
39
-	}
37
+    if (!isset($_SESSION['user'])) {
38
+        header("Location: /login.php?r_login"); die();
39
+    }
40 40
 }
41 41
 
42 42
 function getID($user, $connection) {
43
-	$stmt = $connection->prepare("SELECT * FROM users WHERE username = ?");
44
-	$stmt->bind_param("s", $user);
45
-	$stmt->execute();
46
-	$result = $stmt->get_result();
47
-	if($result->num_rows === 0) return 'error';
48
-	while($row = $result->fetch_assoc()) {
49
-		$id = $row['id'];
50
-	} 
51
-	$stmt->close();
52
-	return $id;
43
+    $stmt = $connection->prepare("SELECT * FROM users WHERE username = ?");
44
+    $stmt->bind_param("s", $user);
45
+    $stmt->execute();
46
+    $result = $stmt->get_result();
47
+    if($result->num_rows === 0) return 'error';
48
+    while($row = $result->fetch_assoc()) {
49
+        $id = $row['id'];
50
+    } 
51
+    $stmt->close();
52
+    return $id;
53 53
 }
54 54
 
55 55
 function getName($id, $connection) {
56
-	$stmt = $connection->prepare("SELECT * FROM users WHERE id = ?");
57
-	$stmt->bind_param("s", $id);
58
-	$stmt->execute();
59
-	$result = $stmt->get_result();
60
-	if($result->num_rows === 0) return('error');
61
-	while($row = $result->fetch_assoc()) {
62
-		$name = htmlspecialchars($row['username']);
63
-	} 
64
-	$stmt->close();
65
-	return $name;
56
+    $stmt = $connection->prepare("SELECT * FROM users WHERE id = ?");
57
+    $stmt->bind_param("s", $id);
58
+    $stmt->execute();
59
+    $result = $stmt->get_result();
60
+    if($result->num_rows === 0) return('error');
61
+    while($row = $result->fetch_assoc()) {
62
+        $name = htmlspecialchars($row['username']);
63
+    } 
64
+    $stmt->close();
65
+    return $name;
66 66
 }
67 67
 
68 68
 function getPFP($user, $connection) {
69
-	$stmt = $connection->prepare("SELECT * FROM users WHERE username = ?");
70
-	$stmt->bind_param("s", $user);
71
-	$stmt->execute();
72
-	$result = $stmt->get_result();
73
-	if($result->num_rows === 0) return('error');
74
-	while($row = $result->fetch_assoc()) {
75
-		$pfp = htmlspecialchars($row['pfp']);
76
-	} 
77
-	$stmt->close();
78
-	return $pfp;
69
+    $stmt = $connection->prepare("SELECT * FROM users WHERE username = ?");
70
+    $stmt->bind_param("s", $user);
71
+    $stmt->execute();
72
+    $result = $stmt->get_result();
73
+    if($result->num_rows === 0) return('error');
74
+    while($row = $result->fetch_assoc()) {
75
+        $pfp = htmlspecialchars($row['pfp']);
76
+    } 
77
+    $stmt->close();
78
+    return $pfp;
79 79
 }
80 80
 
81 81
 function checkIfFriended($friend1, $friend2, $connection)
82 82
 {
83
-	$stmt = $connection->prepare("SELECT * FROM `friends` WHERE reciever = ? AND sender = ? OR reciever = ? AND sender = ?");
84
-	$stmt->bind_param("ssss", $friend1, $friend2, $friend2, $friend1);
85
-	$stmt->execute();
86
-	$result = $stmt->get_result();
87
-	if($result->num_rows === 1){ return true; }
88
-	return false;
83
+    $stmt = $connection->prepare("SELECT * FROM `friends` WHERE reciever = ? AND sender = ? OR reciever = ? AND sender = ?");
84
+    $stmt->bind_param("ssss", $friend1, $friend2, $friend2, $friend1);
85
+    $stmt->execute();
86
+    $result = $stmt->get_result();
87
+    if($result->num_rows === 1){ return true; }
88
+    return false;
89 89
 }
90 90
 
91 91
 //thanks dzhaugasharov https://gist.github.com/afsalrahim/bc8caf497a4b54c5d75d
92 92
 function replaceBBcodes($text) {
93
-	return bbcode_to_html($text);
93
+    return bbcode_to_html($text);
94 94
 }
95 95
 
96 96
 function getUser($id) {
97
-	$stmt = $conn->prepare("SELECT * FROM users WHERE id = ?");
98
-	$stmt->bind_param("i", $id);
99
-	$stmt->execute();
100
-	$result = $stmt->get_result();
101
-	if($result->num_rows === 0) echo('That user does not exist.');
102
-	while($row = $result->fetch_assoc()) {
103
-		$username = $row['username'];
104
-		$id = $row['id'];
105
-		$date = $row['date'];
106
-		$bio = $row['bio'];
107
-		$css = $row['css'];
108
-		$pfp = $row['pfp'];
109
-		$badges = explode(';', $row['badges']);
110
-		$music = $row['music'];
111
-	}
112
-	$stmt->close();
113
-
114
-	$stmt = $conn->prepare("SELECT * FROM gamecomments WHERE author = ?");
115
-	$stmt->bind_param("s", $username);
116
-	$stmt->execute();
117
-	$result = $stmt->get_result();
118
-
119
-	$comments = 0;
120
-	while($row = $result->fetch_assoc()) {
121
-		$comments++;
122
-	}
123
-	$stmt->close();
124
-
125
-	$stmt = $conn->prepare("SELECT * FROM comments WHERE author = ?");
126
-	$stmt->bind_param("s", $username);
127
-	$stmt->execute();
128
-	$result = $stmt->get_result();
129
-
130
-	$profilecomments = 0;
131
-	while($row = $result->fetch_assoc()) {
132
-		$profilecomments++;
133
-	}
134
-	$stmt->close();
135
-
136
-	$stmt = $conn->prepare("SELECT * FROM files WHERE author = ? AND status='y'");
137
-	$stmt->bind_param("s", $username);
138
-	$stmt->execute();
139
-	$result = $stmt->get_result();
140
-
141
-	$filesuploaded = 0;
142
-	while($row = $result->fetch_assoc()) {
143
-		$filesuploaded++;
144
-	}
145
-	$stmt->close();
97
+    $stmt = $conn->prepare("SELECT * FROM users WHERE id = ?");
98
+    $stmt->bind_param("i", $id);
99
+    $stmt->execute();
100
+    $result = $stmt->get_result();
101
+    if($result->num_rows === 0) echo('That user does not exist.');
102
+    while($row = $result->fetch_assoc()) {
103
+        $username = $row['username'];
104
+        $id = $row['id'];
105
+        $date = $row['date'];
106
+        $bio = $row['bio'];
107
+        $css = $row['css'];
108
+        $pfp = $row['pfp'];
109
+        $badges = explode(';', $row['badges']);
110
+        $music = $row['music'];
111
+    }
112
+    $stmt->close();
113
+
114
+    $stmt = $conn->prepare("SELECT * FROM gamecomments WHERE author = ?");
115
+    $stmt->bind_param("s", $username);
116
+    $stmt->execute();
117
+    $result = $stmt->get_result();
118
+
119
+    $comments = 0;
120
+    while($row = $result->fetch_assoc()) {
121
+        $comments++;
122
+    }
123
+    $stmt->close();
124
+
125
+    $stmt = $conn->prepare("SELECT * FROM comments WHERE author = ?");
126
+    $stmt->bind_param("s", $username);
127
+    $stmt->execute();
128
+    $result = $stmt->get_result();
129
+
130
+    $profilecomments = 0;
131
+    while($row = $result->fetch_assoc()) {
132
+        $profilecomments++;
133
+    }
134
+    $stmt->close();
135
+
136
+    $stmt = $conn->prepare("SELECT * FROM files WHERE author = ? AND status='y'");
137
+    $stmt->bind_param("s", $username);
138
+    $stmt->execute();
139
+    $result = $stmt->get_result();
140
+
141
+    $filesuploaded = 0;
142
+    while($row = $result->fetch_assoc()) {
143
+        $filesuploaded++;
144
+    }
145
+    $stmt->close();
146 146
 }
147 147
 ?>
148 148
\ No newline at end of file
Please login to merge, or discard this patch.