This repository has been archived on 2024-06-26. You can view files and clone it, but cannot push or open issues or pull requests.
sakura/public/settings.php

1140 lines
42 KiB
PHP
Raw Normal View History

2015-05-05 06:24:19 +00:00
<?php
/*
* Sakura User Settings
*/
// Declare Namespace
namespace Sakura;
2015-12-29 21:52:19 +00:00
use Sakura\Perms\Site;
2016-03-27 22:15:51 +00:00
// Legacy support!!!!!!!!!
$renderData = [];
2015-12-29 21:52:19 +00:00
2015-05-05 06:24:19 +00:00
// Include components
require_once str_replace(basename(__DIR__), '', dirname(__FILE__)) . 'sakura.php';
2015-05-05 06:24:19 +00:00
2016-03-30 21:30:15 +00:00
if (isset($_POST['submit']) && isset($_POST['submit'])) {
$continue = true;
// Set redirector
$redirect = isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : $urls->format('SETTINGS_INDEX');
// Check if the user is logged in
if (!Users::checkLogin() || !$continue) {
$renderData['page'] = [
2015-08-21 22:07:45 +00:00
'redirect' => '/authenticate',
'message' => 'You must be logged in to edit your settings.',
'success' => 0,
2015-08-21 22:07:45 +00:00
];
2015-09-16 20:34:36 +00:00
$continue = false;
}
// Check session variables
2016-01-17 01:58:31 +00:00
if (!isset($_POST['timestamp'])
|| !isset($_POST['mode'])
|| $_POST['timestamp'] < time() - 1000
|| !isset($_POST['sessid'])
|| $_POST['sessid'] != session_id()
2015-09-14 21:41:43 +00:00
|| !$continue) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Your session has expired, please refresh the page and try again.',
'success' => 0,
];
2015-09-16 20:34:36 +00:00
$continue = false;
}
// Change settings
if ($continue) {
// Switch to the correct mode
switch ($_POST['mode']) {
2015-08-10 19:09:47 +00:00
// Avatar & Background
2015-08-09 18:26:01 +00:00
case 'avatar':
2015-08-10 19:09:47 +00:00
case 'background':
2016-01-17 01:58:31 +00:00
case 'header':
2015-08-10 19:09:47 +00:00
// Assign $_POST['mode'] to a $mode variable because I ain't typin that more than once
$mode = $_POST['mode'];
2016-01-17 01:58:31 +00:00
// Assign the correct column and title to a variable
switch ($mode) {
2015-08-10 19:09:47 +00:00
case 'background':
$column = 'user_background';
$msgTitle = 'Background';
2016-01-17 01:58:31 +00:00
$current = $currentUser->background;
$permission = $currentUser->permission(Site::CHANGE_BACKGROUND);
break;
case 'header':
$column = 'user_header';
2016-01-17 01:58:31 +00:00
$msgTitle = 'Header';
$current = $currentUser->header;
$permission = $currentUser->permission(Site::CHANGE_HEADER);
2015-08-10 19:09:47 +00:00
break;
case 'avatar':
default:
$column = 'user_avatar';
$msgTitle = 'Avatar';
2016-01-17 01:58:31 +00:00
$current = $currentUser->avatar;
2015-12-29 21:52:19 +00:00
$permission = $currentUser->permission(Site::CHANGE_AVATAR);
2015-08-21 22:07:45 +00:00
}
// Check if the user has the permissions to go ahead
if (!$permission) {
2015-08-21 22:07:45 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'You are not allowed to alter your ' . strtolower($msgTitle) . '.',
'success' => 0,
2015-08-21 22:07:45 +00:00
];
break;
2015-08-10 19:09:47 +00:00
}
2015-08-09 18:26:01 +00:00
// Set path variables
2016-01-17 01:58:31 +00:00
$filename = strtolower($msgTitle) . '_' . $currentUser->id;
2015-08-09 18:26:01 +00:00
// Check if $_FILES is set
if (!isset($_FILES[$mode]) && empty($_FILES[$mode])) {
2015-08-09 18:26:01 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'No file was uploaded.',
'success' => 0,
2015-08-09 18:26:01 +00:00
];
break;
}
// Check if the upload went properly
if ($_FILES[$mode]['error'] !== UPLOAD_ERR_OK && $_FILES[$mode]['error'] !== UPLOAD_ERR_NO_FILE) {
2015-08-09 18:26:01 +00:00
// Get the error in text
switch ($_FILES[$mode]['error']) {
2015-08-09 18:26:01 +00:00
case UPLOAD_ERR_INI_SIZE:
case UPLOAD_ERR_FORM_SIZE:
$msg = 'The uploaded file exceeds the maximum filesize!';
break;
case UPLOAD_ERR_PARTIAL:
$msg = 'The upload was interrupted!';
break;
case UPLOAD_ERR_NO_TMP_DIR:
case UPLOAD_ERR_CANT_WRITE:
$msg = 'Unable to save file to temporary location, contact the administrator!';
break;
case UPLOAD_ERR_EXTENSION:
default:
$msg = 'An unknown exception occurred!';
break;
}
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => $msg,
'success' => 0,
2015-08-09 18:26:01 +00:00
];
break;
}
2015-08-21 22:07:45 +00:00
// Check if we're not in removal mode
if ($_FILES[$mode]['error'] != UPLOAD_ERR_NO_FILE) {
2015-08-21 22:07:45 +00:00
// Get the meta data
$metadata = getimagesize($_FILES[$mode]['tmp_name']);
2015-08-09 18:26:01 +00:00
2015-08-21 22:07:45 +00:00
// Check if the image is actually an image
2016-02-27 17:28:45 +00:00
if (!$metadata) {
2015-08-21 22:07:45 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Uploaded file is not an image.',
'success' => 0,
2015-08-21 22:07:45 +00:00
];
2015-08-09 18:26:01 +00:00
2015-08-21 22:07:45 +00:00
break;
}
2015-08-09 18:26:01 +00:00
2015-08-21 22:07:45 +00:00
// Check if the image is an allowed filetype
2015-09-14 21:41:43 +00:00
if ((($metadata[2] !== IMAGETYPE_GIF)
&& ($metadata[2] !== IMAGETYPE_JPEG)
&& ($metadata[2] !== IMAGETYPE_PNG))) {
2015-08-21 22:07:45 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'This filetype is not allowed.',
'success' => 0,
2015-08-21 22:07:45 +00:00
];
break;
}
2015-08-09 18:26:01 +00:00
2015-08-21 22:07:45 +00:00
// Check if the image is too large
2015-12-04 14:19:10 +00:00
if (($metadata[0] > Config::get($mode . '_max_width')
|| $metadata[1] > Config::get($mode . '_max_height'))) {
2015-08-21 22:07:45 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'The resolution of this picture is too big.',
'success' => 0,
2015-08-21 22:07:45 +00:00
];
break;
}
2015-08-09 18:26:01 +00:00
2015-08-21 22:07:45 +00:00
// Check if the image is too small
2015-12-04 14:19:10 +00:00
if (($metadata[0] < Config::get($mode . '_min_width')
|| $metadata[1] < Config::get($mode . '_min_height'))) {
2015-08-21 22:07:45 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'The resolution of this picture is too small.',
'success' => 0,
2015-08-21 22:07:45 +00:00
];
break;
}
2015-08-09 18:26:01 +00:00
2015-08-21 22:07:45 +00:00
// Check if the file is too large
2015-12-04 14:19:10 +00:00
if ((filesize($_FILES[$mode]['tmp_name']) > Config::get($mode . '_max_fsize'))) {
2015-08-21 22:07:45 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'The filesize of this file is too large.',
'success' => 0,
2015-08-21 22:07:45 +00:00
];
break;
}
2015-08-09 18:26:01 +00:00
}
2016-01-17 01:58:31 +00:00
// Open the old file and remove it
$oldFile = new File($current);
$oldFile->delete();
unset($oldFile);
$fileId = 0;
2015-08-09 19:19:11 +00:00
if ($_FILES[$mode]['error'] != UPLOAD_ERR_NO_FILE) {
2015-08-21 22:07:45 +00:00
// Append extension to filename
$filename .= image_type_to_extension($metadata[2]);
2015-08-09 18:26:01 +00:00
2016-01-17 01:58:31 +00:00
// Store the file
$file = File::create(file_get_contents($_FILES[$mode]['tmp_name']), $filename, $currentUser);
2015-08-09 18:26:01 +00:00
2016-01-17 01:58:31 +00:00
// Assign the file id to a variable
$fileId = $file->id;
2015-08-19 19:44:01 +00:00
}
2016-01-17 01:58:31 +00:00
// Update table
DB::table('users')
->where('user_id', $currentUser->id)
->update([
$column => $fileId,
]);
2015-08-09 18:26:01 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Updated your ' . strtolower($msgTitle) . '!',
'success' => 1,
2015-08-09 18:26:01 +00:00
];
break;
// Profile
case 'profile':
// Get profile fields and create storage var
$fields = Users::getProfileFields();
// Delete all profile fields
DB::table('user_profilefields')
->where('user_id', $currentUser->id)
->delete();
// Go over each field
foreach ($fields as $field) {
// Add to the store array
if (isset($_POST['profile_' . $field['field_identity']]) && !empty($_POST['profile_' . $field['field_identity']])) {
DB::table('user_profilefields')
->insert([
'user_id' => $currentUser->id,
'field_name' => $field['field_identity'],
'field_value' => $_POST['profile_' . $field['field_identity']],
]);
}
// Check if there's additional values we should keep in mind
if (isset($field['field_additional']) && !empty($field['field_additional'])) {
// Go over each additional value
foreach ($field['field_additional'] as $addKey => $addVal) {
// Add to the array
2016-01-17 01:58:31 +00:00
$store = (isset($_POST['profile_additional_' . $addKey]) || !empty($_POST['profile_additional_' . $addKey])) ? $_POST['profile_additional_' . $addKey] : false;
DB::table('user_profilefields')
->insert([
'user_id' => $currentUser->id,
'field_name' => $addKey,
'field_value' => $store,
]);
}
}
}
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Your profile has been updated!',
'success' => 1,
];
2015-09-08 21:57:33 +00:00
// Birthdays
2015-09-14 21:41:43 +00:00
if (isset($_POST['birthday_day'])
&& isset($_POST['birthday_month'])
&& isset($_POST['birthday_year'])) {
2015-09-08 21:57:33 +00:00
// Check if the values aren't fucked with
2015-09-14 21:41:43 +00:00
if ($_POST['birthday_day'] < 0
|| $_POST['birthday_day'] > 31
|| $_POST['birthday_month'] < 0
|| $_POST['birthday_month'] > 12
|| (
$_POST['birthday_year'] != 0
&& $_POST['birthday_year'] < (date("Y") - 100)
)
|| $_POST['birthday_year'] > date("Y")) {
2015-09-08 21:57:33 +00:00
$renderData['page']['message'] = 'Your birthdate is invalid.';
$renderData['page']['success'] = 0;
break;
}
// Check if the values aren't fucked with
2015-09-14 21:41:43 +00:00
if ((
$_POST['birthday_day'] < 1
&& $_POST['birthday_month'] > 0
)
|| (
$_POST['birthday_day'] > 0
&& $_POST['birthday_month'] < 1)
) {
2015-09-08 21:57:33 +00:00
$renderData['page']['message'] = 'Only setting a day or month is disallowed.';
$renderData['page']['success'] = 0;
break;
}
// Check if the values aren't fucked with
2015-09-14 21:41:43 +00:00
if ($_POST['birthday_year'] > 0
&& (
$_POST['birthday_day'] < 1
|| $_POST['birthday_month'] < 1
)
) {
2015-09-08 21:57:33 +00:00
$renderData['page']['message'] = 'Only setting a year is disallowed.';
$renderData['page']['success'] = 0;
break;
}
2015-09-14 21:41:43 +00:00
$birthdate = implode(
'-',
[$_POST['birthday_year'], $_POST['birthday_month'], $_POST['birthday_day']]
);
2015-09-08 21:57:33 +00:00
DB::table('users')
->where('user_id', $currentUser->id)
->update([
'user_birthday' => $birthdate,
]);
2015-09-08 21:57:33 +00:00
}
break;
2015-09-16 20:34:36 +00:00
// Site Options
2015-08-21 22:07:45 +00:00
case 'options':
// Get profile fields and create storage var
$fields = Users::getOptionFields();
// Delete all option fields for this user
DB::table('user_optionfields')
->where('user_id', $currentUser->id)
->delete();
2015-08-21 22:07:45 +00:00
// Go over each field
foreach ($fields as $field) {
2015-08-23 22:08:36 +00:00
// Make sure the user has sufficient permissions to complete this action
2015-12-29 21:52:19 +00:00
if (!$currentUser->permission(constant('Sakura\Perms\Site::' . $field['option_permission']))) {
2015-08-23 22:08:36 +00:00
continue;
2015-08-21 22:07:45 +00:00
}
2016-01-17 01:58:31 +00:00
if (isset($_POST['option_' . $field['option_id']])
&& !empty($_POST['option_' . $field['option_id']])) {
DB::table('user_optionfields')
->insert([
'user_id' => $currentUser->id,
'field_name' => $field['option_id'],
'field_value' => $_POST['option_' . $field['option_id']],
]);
2016-01-17 01:58:31 +00:00
}
2015-08-21 22:07:45 +00:00
}
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Changed your options!',
'success' => 1,
2015-08-21 22:07:45 +00:00
];
break;
2015-09-16 20:34:36 +00:00
// Usertitle
case 'usertitle':
// Check permissions
2015-12-29 21:52:19 +00:00
if (!$currentUser->permission(Site::CHANGE_USERTITLE)) {
2015-09-16 20:34:36 +00:00
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'You aren\'t allowed to change your usertitle.',
'success' => 0,
];
break;
}
// Check length
if (isset($_POST['usertitle']) ? (strlen($_POST['usertitle']) > 64) : false) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Your usertitle is too long.',
'success' => 0,
];
break;
}
// Update database
DB::table('users')
->where('user_id', $currentUser->id)
->update([
'user_title' => (isset($_POST['usertitle']) ? $_POST['usertitle'] : null),
]);
2015-09-16 20:34:36 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Updated your usertitle!',
'success' => 1,
];
break;
// Username changing
case 'username':
// Check permissions
2015-12-29 21:52:19 +00:00
if (!$currentUser->permission(Site::CHANGE_USERNAME)) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'You aren\'t allowed to change your username.',
'success' => 0,
];
break;
}
// Attempt username change
$userNameChange = $currentUser->setUsername(isset($_POST['username']) ? $_POST['username'] : '');
// Messages
$messages = [
'TOO_SHORT' => 'Your new name is too short!',
'TOO_LONG' => 'Your new name is too long!',
'TOO_RECENT' => 'The username you tried to use is reserved, try again later.',
'IN_USE' => 'Someone already has this username!',
'SUCCESS' => 'Successfully changed your username!',
];
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => $messages[$userNameChange[1]],
'success' => $userNameChange[0],
];
break;
// E-mail changing
case 'email':
// Check permissions
2015-12-29 21:52:19 +00:00
if (!$currentUser->permission(Site::CHANGE_EMAIL)) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'You aren\'t allowed to change your e-mail address.',
'success' => 0,
];
break;
}
// Attempt e-mail change
$emailChange = $currentUser->setEMailAddress(isset($_POST['email']) ? $_POST['email'] : '');
// Messages
$messages = [
'INVALID' => 'Your e-mail isn\'t considered valid!',
'IN_USE' => 'This e-mail address has already been used!',
'SUCCESS' => 'Successfully changed your e-mail address!',
];
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => $messages[$emailChange[1]],
'success' => $emailChange[0],
];
break;
// Password changing
case 'password':
// Check permissions
2015-12-29 21:52:19 +00:00
if (!$currentUser->permission(Site::CHANGE_PASSWORD)) {
$renderData['page'] = [
2015-08-10 19:09:47 +00:00
'redirect' => $redirect,
'message' => 'You aren\'t allowed to change your password.',
'success' => 0,
2015-08-10 19:09:47 +00:00
];
2015-08-10 19:09:47 +00:00
break;
}
2015-08-10 19:09:47 +00:00
// Attempt password change
$passChange = $currentUser->setPassword(isset($_POST['oldpassword']) ? $_POST['oldpassword'] : '', isset($_POST['newpassword']) ? $_POST['newpassword'] : '', isset($_POST['newpasswordconfirm']) ? $_POST['newpasswordconfirm'] : '');
2015-08-10 19:09:47 +00:00
// Messages
$messages = [
'NO_LOGIN' => 'How are you even logged in right now?',
'INCORRECT_PASSWORD' => 'The password you provided is incorrect!',
'PASS_TOO_SHIT' => 'Your password isn\'t strong enough!',
'PASS_NOT_MATCH' => 'Your new passwords don\'t match!',
'SUCCESS' => 'Successfully changed your password!',
];
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => $messages[$passChange[1]],
'success' => $passChange[0],
2015-08-10 19:09:47 +00:00
];
break;
2016-01-17 01:58:31 +00:00
// Userpage
case 'userpage':
if (!isset($_POST['userpage'])) {
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
2016-01-17 01:58:31 +00:00
'message' => 'No userpage was supplied.',
'success' => 0,
];
}
2016-01-17 01:58:31 +00:00
// Update database
DB::table('users')
->where('user_id', $currentUser->id)
->update([
'user_page' => $_POST['userpage'],
]);
2016-01-17 01:58:31 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
2016-01-17 01:58:31 +00:00
'message' => 'Your userpage has been updated!',
'success' => 1,
];
break;
2016-01-17 01:58:31 +00:00
// Signature
case 'signature':
if (!isset($_POST['signature'])) {
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'No signature was supplied.',
'success' => 0,
];
}
// Update database
DB::table('users')
->where('user_id', $currentUser->id)
->update([
'user_signature' => $_POST['signature'],
]);
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
2016-01-17 01:58:31 +00:00
'message' => 'Your signature has been updated!',
'success' => 1,
];
break;
2015-08-10 19:09:47 +00:00
2016-01-17 01:58:31 +00:00
// Ranks
case 'ranks':
// Check submit data
if (!isset($_POST['rank'])) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'No rank was set.',
'success' => 0,
];
break;
}
2016-01-17 01:58:31 +00:00
// Check if the user is part of the rank
if (!$currentUser->hasRanks([$_POST['rank']])) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'You are not in this rank.',
'success' => 0,
];
break;
}
// Leaving
if (isset($_POST['remove'])) {
// Check if we're not trying to leave hardranks
if ($_POST['rank'] <= 2) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'You can\'t remove this rank.',
'success' => 0,
];
break;
}
// Remove the rank
$currentUser->removeRanks([$_POST['rank']]);
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Removed the rank from your account.',
'success' => 0,
];
break;
}
// Set as default
$currentUser->setMainRank($_POST['rank']);
// Set render data
$renderData['page'] = [
2016-01-17 01:58:31 +00:00
'redirect' => $redirect,
'message' => 'Changed your main rank!',
'success' => 0,
];
break;
2016-01-17 01:58:31 +00:00
// Sessions
case 'sessions':
// Check if sessionid is set
if (!isset($_POST['sessionid'])) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'A required field wasn\'t set.',
'success' => 0,
];
break;
}
// Check if sessionid is set to all
if ($_POST['sessionid'] === 'all') {
// Delete all sessions assigned to the current user
DB::table('sessions')
->where('user_id', $currentUser->id)
->delete();
2016-01-17 01:58:31 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Killed all active sessions!',
'success' => 1,
];
break;
}
// Check if the session is owned by the current user
$us = DB::table('sessions')
->where('user_id', $currentUser->id)
->where('session_id', $_POST['sessionid'])
->count();
if (!$us) {
2016-01-17 01:58:31 +00:00
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'The session you tried to kill doesn\'t exist.',
'success' => 0,
];
break;
}
// Delete the session
DB::table('sessions')
->where('user_id', $currentUser->id)
->where('session_id', $_POST['sessionid'])
->delete();
2016-01-17 01:58:31 +00:00
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
2016-01-17 01:58:31 +00:00
'message' => 'Killed the session!',
'success' => 1,
2016-01-17 01:58:31 +00:00
];
break;
// Deactivation
case 'deactivate':
// Check permissions
if (!$currentUser->permission(Site::DEACTIVATE_ACCOUNT)) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'You aren\'t allowed to deactivate your account.',
'success' => 0,
];
break;
}
// Check fields
if (!isset($_POST['username'])
|| !isset($_POST['password'])
|| !isset($_POST['email'])
|| !isset($_POST['sensitive'])) {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'One or more forms wasn\'t set.',
'success' => 0,
];
break;
}
// Check values
if ($_POST['username'] !== $currentUser->username
|| !Hashing::validatePassword($_POST['password'], [$currentUser->passwordAlgo, $currentUser->passwordIter, $currentUser->passwordSalt, $currentUser->passwordHash])
|| $_POST['email'] !== $currentUser->email
|| md5($_POST['sensitive']) !== '81df445067d92dd02db9098ba82b0167') {
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'One or more forms wasn\'t correct.',
'success' => 0,
];
2016-01-17 01:58:31 +00:00
break;
}
// Deactivate account
$currentUser->removeRanks(array_keys($currentUser->ranks));
$currentUser->addRanks([1]);
$currentUser->setMainRank(1);
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'Your account has been deactivated!',
'success' => 1,
];
break;
// Fallback
default:
// Set render data
$renderData['page'] = [
'redirect' => $redirect,
'message' => 'The requested method does not exist.',
'success' => 0,
];
break;
}
}
// Print page contents or if the AJAX request is set only display the render data
2015-11-06 22:36:05 +00:00
if (isset($_REQUEST['ajax'])) {
echo $renderData['page']['message'] . '|' .
$renderData['page']['success'] . '|' .
$renderData['page']['redirect'];
} else {
// If not allowed print the restricted page
2016-02-04 20:56:40 +00:00
Template::vars($renderData);
2015-11-06 22:36:05 +00:00
// Print page contents
2016-02-04 20:56:40 +00:00
echo Template::render('global/information');
2015-11-06 22:36:05 +00:00
}
exit;
2015-05-09 00:56:55 +00:00
}
if (Users::checkLogin()) {
2015-06-20 19:25:41 +00:00
// Settings page list
$pages = [
2015-08-23 22:08:36 +00:00
'general' => [
'title' => 'General',
'modes' => [
'home' => [
'title' => 'Home',
'description' => [
2015-09-14 21:41:43 +00:00
'Welcome to the Settings Panel.
From here you can monitor, view and update your profile and preferences.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => !$currentUser->permission(Site::DEACTIVATED),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'profile' => [
'title' => 'Edit Profile',
'description' => [
2015-09-14 21:41:43 +00:00
'These are the external account links etc.
on your profile, shouldn\'t need any additional explanation for this one.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::ALTER_PROFILE),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'options' => [
'title' => 'Site Options',
'description' => [
'These are a few personalisation options for the site while you\'re logged in.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => !$currentUser->permission(Site::DEACTIVATED),
'menu' => true,
],
],
2015-08-23 22:08:36 +00:00
],
'friends' => [
'title' => 'Friends',
'modes' => [
'listing' => [
'title' => 'Listing',
'description' => [
'Manage your friends.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::MANAGE_FRIENDS),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'requests' => [
'title' => 'Requests',
'description' => [
'Handle friend requests.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::MANAGE_FRIENDS),
'menu' => true,
],
],
2016-01-18 20:21:08 +00:00
]/*,
2015-08-23 22:08:36 +00:00
'messages' => [
'title' => 'Messages',
'modes' => [
'inbox' => [
'title' => 'Inbox',
'description' => [
'The list of messages you\'ve received.',
],
'access' => $currentUser->permission(Site::USE_MESSAGES),
'menu' => true,
],
'sent' => [
'title' => 'Sent',
'description' => [
'The list of messages you\'ve sent to other users.',
],
'access' => $currentUser->permission(Site::USE_MESSAGES),
'menu' => true,
],
'compose' => [
'title' => 'Compose',
'description' => [
'Write a new message.',
],
'access' => $currentUser->permission(Site::SEND_MESSAGES),
'menu' => true,
],
'read' => [
'title' => 'Read',
'description' => [
'Read a message.',
],
'access' => $currentUser->permission(Site::USE_MESSAGES),
'menu' => false,
],
],
2016-01-18 20:21:08 +00:00
]*/,
2015-08-23 22:08:36 +00:00
'notifications' => [
'title' => 'Notifications',
'modes' => [
'history' => [
'title' => 'History',
'description' => [
'The history of notifications that have been sent to you in the last month.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => !$currentUser->permission(Site::DEACTIVATED),
'menu' => true,
],
],
2015-08-23 22:08:36 +00:00
],
'appearance' => [
'title' => 'Appearance',
'modes' => [
'avatar' => [
'title' => 'Avatar',
'description' => [
'Your avatar which is displayed all over the site and on your profile.',
2015-09-14 21:41:43 +00:00
'Maximum image size is {{ avatar.max_width }}x{{ avatar.max_height }},
minimum image size is {{ avatar.min_width }}x{{ avatar.min_height }},
maximum file size is {{ avatar.max_size_view }}.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::CHANGE_AVATAR),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'background' => [
'title' => 'Background',
'description' => [
'The background that is displayed on your profile.',
2015-09-14 21:41:43 +00:00
'Maximum image size is {{ background.max_width }}x{{ background.max_height }},
minimum image size is {{ background.min_width }}x{{ background.min_height }},
maximum file size is {{ background.max_size_view }}.',
2015-08-23 22:08:36 +00:00
],
2016-01-17 01:58:31 +00:00
'access' => $currentUser->permission(Site::CHANGE_BACKGROUND),
'menu' => true,
],
'header' => [
'title' => 'Header',
'description' => [
'The header that is displayed on your profile.',
'Maximum image size is {{ header.max_width }}x{{ header.max_height }},
minimum image size is {{ header.min_width }}x{{ header.min_height }},
maximum file size is {{ header.max_size_view }}.',
],
'access' => $currentUser->permission(Site::CHANGE_HEADER),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'userpage' => [
'title' => 'Userpage',
'description' => [
'The custom text that is displayed on your profile.',
2015-08-23 22:08:36 +00:00
],
2015-09-14 21:41:43 +00:00
'access' => (
2016-01-17 01:58:31 +00:00
$currentUser->page
2015-12-29 21:52:19 +00:00
&& $currentUser->permission(Site::CHANGE_USERPAGE)
) || $currentUser->permission(Site::CREATE_USERPAGE),
'menu' => true,
],
'signature' => [
'title' => 'Signature',
'description' => [
'This signature is displayed at the end of all your posts (unless you choose not to show it).',
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::CHANGE_SIGNATURE),
'menu' => true,
],
],
2015-08-23 22:08:36 +00:00
],
'account' => [
'title' => 'Account',
'modes' => [
'email' => [
'title' => 'E-mail Address',
'description' => [
'You e-mail address is used for password recovery and stuff like that, we won\'t spam you ;).',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::CHANGE_EMAIL),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'username' => [
'title' => 'Username',
'description' => [
'Probably the biggest part of your identity on a site.',
'<b>You can only change this once every 30 days so choose wisely.</b>',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::CHANGE_USERNAME),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'usertitle' => [
2015-09-16 20:34:36 +00:00
'title' => 'Usertitle',
2015-08-23 22:08:36 +00:00
'description' => [
'That little piece of text displayed under your username on your profile.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::CHANGE_USERTITLE),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'password' => [
'title' => 'Password',
'description' => [
'Used to authenticate with the site and certain related services.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::CHANGE_PASSWORD),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'ranks' => [
'title' => 'Ranks',
'description' => [
2015-09-14 21:41:43 +00:00
'Manage what ranks you\'re in and what is set as your main rank.
Your main rank is highlighted.
You get the permissions of all of the ranks you\'re in combined.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::ALTER_RANKS),
'menu' => true,
],
],
2015-08-23 22:08:36 +00:00
],
'advanced' => [
'title' => 'Advanced',
'modes' => [
'sessions' => [
'title' => 'Sessions',
'description' => [
2015-09-14 21:41:43 +00:00
'Session keys are a way of identifying yourself with the system without keeping
your password in memory.',
'If someone finds one of your session keys they could possibly compromise your account,
if you see any sessions here that shouldn\'t be here hit the Kill button to kill the
selected session.',
'If you get logged out after clicking one you\'ve most likely killed your current session,
to make it easier to avoid this from happening your current session is highlighted.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::MANAGE_SESSIONS),
'menu' => true,
2015-08-23 22:08:36 +00:00
],
'deactivate' => [
'title' => 'Deactivate Account',
'description' => [
'You can deactivate your account here if you want to leave :(.',
2015-08-23 22:08:36 +00:00
],
2015-12-29 21:52:19 +00:00
'access' => $currentUser->permission(Site::DEACTIVATE_ACCOUNT),
'menu' => true,
],
],
],
2015-06-20 19:25:41 +00:00
];
// Current settings page
2015-09-14 21:41:43 +00:00
$category = isset($_GET['cat']) ? (
array_key_exists($_GET['cat'], $pages) ? $_GET['cat'] : false
) : array_keys($pages)[0];
$mode = false;
// Only continue setting mode if $category is true
if ($category) {
2015-09-14 21:41:43 +00:00
$mode = isset($_GET['mode']) && $category ? (
array_key_exists($_GET['mode'], $pages[$category]['modes']) ? $_GET['mode'] : false
) : array_keys($pages[$category]['modes'])[0];
}
2015-08-23 22:08:36 +00:00
// Not found
2015-09-14 21:41:43 +00:00
if (!$category
|| empty($category)
|| !$mode
|| empty($mode)
|| !$pages[$category]['modes'][$mode]['access']) {
2015-08-23 22:08:36 +00:00
header('HTTP/1.0 404 Not Found');
// Set parse variables
2016-02-04 20:56:40 +00:00
Template::vars($renderData);
// Print page contents
2016-02-04 20:56:40 +00:00
echo Template::render('global/notfound');
2015-08-23 22:08:36 +00:00
exit;
}
2015-06-20 19:25:41 +00:00
// Set templates directory
$renderData['templates'] = 'settings';
2015-06-20 19:25:41 +00:00
// Render data
$renderData['current'] = $category . '.' . $mode;
2015-08-23 22:08:36 +00:00
// Settings pages
$renderData['pages'] = $pages;
// Page data
2015-06-20 19:25:41 +00:00
$renderData['page'] = [
'category' => $pages[$category]['title'],
'mode' => $pages[$category]['modes'][$mode]['title'],
'description' => $pages[$category]['modes'][$mode]['description'],
2015-06-20 19:25:41 +00:00
];
// Section specific
switch ($category . '.' . $mode) {
2015-06-27 11:03:11 +00:00
// Profile
2015-08-23 22:08:36 +00:00
case 'general.profile':
2015-06-27 11:03:11 +00:00
$renderData['profile'] = [
'fields' => Users::getProfileFields(),
'months' => [
1 => 'January',
2 => 'February',
3 => 'March',
4 => 'April',
5 => 'May',
6 => 'June',
7 => 'July',
8 => 'August',
9 => 'September',
10 => 'October',
11 => 'November',
12 => 'December',
],
2015-08-21 22:07:45 +00:00
];
break;
// Options
2015-08-23 22:08:36 +00:00
case 'general.options':
2015-08-21 22:07:45 +00:00
$renderData['options'] = [
'fields' => Users::getOptionFields(),
2015-06-27 11:03:11 +00:00
];
break;
2015-08-23 22:08:36 +00:00
// PM inbox
case 'messages.inbox':
$renderData['messages'] = [];
2015-08-23 22:08:36 +00:00
break;
// Avatar and background sizes
case 'appearance.avatar':
case 'appearance.background':
2016-01-17 01:58:31 +00:00
case 'appearance.header':
2015-08-23 22:08:36 +00:00
$renderData[$mode] = [
2015-12-04 14:19:10 +00:00
'max_width' => Config::get($mode . '_max_width'),
'max_height' => Config::get($mode . '_max_height'),
'min_width' => Config::get($mode . '_min_width'),
'min_height' => Config::get($mode . '_min_height'),
'max_size' => Config::get($mode . '_max_fsize'),
2016-01-17 01:58:31 +00:00
'max_size_view' => Utils::getByteSymbol(Config::get($mode . '_max_fsize')),
2015-08-23 22:08:36 +00:00
];
break;
2016-01-14 20:43:33 +00:00
// Sessions
case 'advanced.sessions':
$sessions = DB::table('sessions')
->where('user_id', $currentUser->id)
->get();
2016-02-18 23:28:44 +00:00
$renderData['sessions'] = $sessions;
2016-01-14 20:43:33 +00:00
break;
2015-06-20 19:25:41 +00:00
}
// Set parse variables
2016-02-04 20:56:40 +00:00
Template::vars($renderData);
2015-06-20 19:25:41 +00:00
// Print page contents
2016-03-28 14:47:43 +00:00
echo Template::render('meta/settings');
2015-06-20 19:25:41 +00:00
} else {
// If not allowed print the restricted page
2016-02-04 20:56:40 +00:00
Template::vars($renderData);
// Print page contents
2016-02-04 20:56:40 +00:00
echo Template::render('global/restricted');
2015-06-20 19:25:41 +00:00
}