国内流行的内容管理系统(CMS)多端全媒体解决方案 https://www.dedebiz.com
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

233 lines
8.7KB

  1. <?php
  2. /**
  3. * 图集发布
  4. *
  5. * @version $Id: album_add.php 1 13:52 2010年7月9日Z tianya $
  6. * @package DedeCMS.Member
  7. * @copyright Copyright (c) 2007 - 2020, DesDev, Inc.
  8. * @license http://help.dedecms.com/usersguide/license.html
  9. * @link http://www.dedecms.com
  10. */
  11. require_once(dirname(__FILE__)."/config.php");
  12. //考虑安全原因不管是否开启游客投稿功能,都不允许用户对图集投稿
  13. CheckRank(0,0);
  14. if($cfg_mb_lit=='Y')
  15. {
  16. ShowMsg("由于系统开启了精简版会员空间,你访问的功能不可用!","-1");
  17. exit();
  18. }
  19. if($cfg_mb_album=='N')
  20. {
  21. ShowMsg("对不起,由于系统关闭了图集功能,你访问的功能不可用!","-1");
  22. exit();
  23. }
  24. require_once(DEDEINC."/dedetag.class.php");
  25. require_once(DEDEINC."/userlogin.class.php");
  26. require_once(DEDEINC."/customfields.func.php");
  27. require_once(DEDEMEMBER."/inc/inc_catalog_options.php");
  28. require_once(DEDEMEMBER."/inc/inc_archives_functions.php");
  29. $channelid = isset($channelid) && is_numeric($channelid) ? $channelid : 2;
  30. $typeid = isset($typeid) && is_numeric($typeid) ? $typeid : 0;
  31. $menutype = 'content';
  32. if(empty($formhtml)) $formhtml = 0;
  33. /*-------------
  34. function _ShowForm(){ }
  35. --------------*/
  36. if(empty($dopost))
  37. {
  38. $query = "SELECT * FROM `#@__channeltype` WHERE id='$channelid'; ";
  39. $cInfos = $dsql->GetOne($query);
  40. if(!is_array($cInfos))
  41. {
  42. ShowMsg('模型参数不正确', '-1');
  43. exit();
  44. }
  45. //检查会员等级和类型限制
  46. if($cInfos['sendrank'] > $cfg_ml->M_Rank)
  47. {
  48. $row = $dsql->GetOne("Select membername From `#@__arcrank` where rank='".$cInfos['sendrank']."' ");
  49. ShowMsg("对不起,需要[".$row['membername']."]才能在这个频道发布文档!","-1","0",5000);
  50. exit();
  51. }
  52. if($cInfos['usertype']!='' && $cInfos['usertype'] != $cfg_ml->M_MbType)
  53. {
  54. ShowMsg("对不起,需要[".$cInfos['usertype']."帐号]才能在这个频道发布文档!","-1","0",5000);
  55. exit();
  56. }
  57. include(DEDEMEMBER."/templets/album_add.htm");
  58. exit();
  59. }
  60. /*------------------------------
  61. function _SaveArticle(){ }
  62. ------------------------------*/
  63. else if($dopost=='save')
  64. {
  65. include(DEDEMEMBER.'/inc/archives_check.php');
  66. $svali = GetCkVdValue();
  67. if(preg_match("/1/",$safe_gdopen)){
  68. if(strtolower($vdcode)!=$svali || $svali=='')
  69. {
  70. ResetVdValue();
  71. ShowMsg('验证码错误!', '-1');
  72. exit();
  73. }
  74. }
  75. $cInfos = $dsql->GetOne("Select * From `#@__channeltype` where id='$channelid'; ");
  76. $maxwidth = isset($maxwidth) && is_numeric($maxwidth) ? $maxwidth : 800;
  77. $pagepicnum = isset($pagepicnum) && is_numeric($pagepicnum) ? $pagepicnum : 12;
  78. $ddmaxwidth = isset($ddmaxwidth) && is_numeric($ddmaxwidth) ? $ddmaxwidth : 200;
  79. $prow = isset($prow) && is_numeric($prow) ? $prow : 3;
  80. $pcol = isset($pcol) && is_numeric($pcol) ? $pcol : 3;
  81. $pagestyle = in_array($pagestyle,array('1','2','3')) ? $pagestyle : 2;
  82. include(DEDEMEMBER.'/inc/archives_check.php');
  83. $imgurls = "{dede:pagestyle maxwidth='$maxwidth' pagepicnum='$pagepicnum' ddmaxwidth='$ddmaxwidth' row='$prow' col='$pcol' value='$pagestyle'/}\r\n";
  84. $hasone = false;
  85. $ddisfirst=1;
  86. //只支持填写地址
  87. for($i=1;$i<=120;$i++)
  88. {
  89. if (!isset(${'imgfile'.$i})) {
  90. continue;
  91. }
  92. $f = ${'imgfile'.$i};
  93. $msg = isset(${'imgmsg'.$i})? ${'imgmsg'.$i} : "";
  94. if (!empty($f) && filter_var($f, FILTER_VALIDATE_URL)) {
  95. $u = str_replace(array("\"","'"), "`", $f);
  96. $info = str_replace(array("\"","'"), "`", $msg);
  97. $imgurls .= "{dede:img ddimg='' text='$info'} $u {/dede:img}\r\n";
  98. }
  99. }//循环结束
  100. $imgurls = addslashes($imgurls);
  101. //分析处理附加表数据
  102. $isrm = 1;
  103. if(!isset($formhtml))
  104. {
  105. $formhtml = 0;
  106. }
  107. $inadd_f = $inadd_v = '';
  108. if(!empty($dede_addonfields))
  109. {
  110. $addonfields = explode(';',$dede_addonfields);
  111. $inadd_f = '';
  112. $inadd_v = '';
  113. if(is_array($addonfields))
  114. {
  115. foreach($addonfields as $v)
  116. {
  117. if($v=='')
  118. {
  119. continue;
  120. }
  121. $vs = explode(',',$v);
  122. if(!isset(${$vs[0]}))
  123. {
  124. ${$vs[0]} = '';
  125. }
  126. ${$vs[0]} = GetFieldValueA(${$vs[0]},$vs[1],0);
  127. $inadd_f .= ','.$vs[0];
  128. $inadd_v .= " ,'".${$vs[0]}."' ";
  129. }
  130. }
  131. if (empty($dede_fieldshash) || $dede_fieldshash != md5($dede_addonfields.$cfg_cookie_encode))
  132. {
  133. showMsg('数据校验不对,程序返回', '-1');
  134. exit();
  135. }
  136. // 这里对前台提交的附加数据进行一次校验
  137. $fontiterm = PrintAutoFieldsAdd($cInfos['fieldset'],'autofield', FALSE);
  138. if ($fontiterm != $inadd_f)
  139. {
  140. ShowMsg("提交表单同系统配置不相符,请重新提交!", "-1");
  141. exit();
  142. }
  143. }
  144. //生成文档ID
  145. $arcID = GetIndexKey($arcrank,$typeid,$sortrank,$channelid,$senddate,$mid);
  146. if(empty($arcID))
  147. {
  148. ShowMsg("无法获得主键,因此无法进行后续操作!","-1");
  149. exit();
  150. }
  151. $description = HtmlReplace($description, -1);
  152. $mtypesid = intval($mtypesid); //对输入参数mtypesid未进行int整型转义,导致SQL注入的发生。
  153. //保存到主表
  154. $inQuery = "INSERT INTO `#@__archives`(id,typeid,sortrank,flag,ismake,channel,arcrank,click,money,title,shorttitle,
  155. color,writer,source,litpic,pubdate,senddate,mid,description,keywords,mtype)
  156. VALUES ('$arcID','$typeid','$sortrank','$flag','$ismake','$channelid','$arcrank','0','$money','$title','$shorttitle',
  157. '$color','$writer','$source','','$pubdate','$senddate','$mid','$description','$keywords','$mtypesid'); ";
  158. if(!$dsql->ExecuteNoneQuery($inQuery))
  159. {
  160. $gerr = $dsql->GetError();
  161. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID' ");
  162. ShowMsg("把数据保存到数据库主表 `#@__archives` 时出错,请联系管理员。","javascript:;");
  163. exit();
  164. }
  165. //保存到附加表
  166. $addtable = trim($cInfos['addtable']);
  167. if(empty($addtable))
  168. {
  169. $dsql->ExecuteNoneQuery("DELETE FROM `#@__archives` WHERE id='$arcID'");
  170. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID'");
  171. ShowMsg("没找到当前模型[{$channelid}]的主表信息,无法完成操作!。","javascript:;");
  172. exit();
  173. }
  174. else
  175. {
  176. $query = "INSERT INTO `$addtable`(aid,typeid,userip,redirecturl,templet,pagestyle,maxwidth,imgurls,row,col,isrm,ddmaxwidth,pagepicnum{$inadd_f})
  177. Values('$arcID','$typeid','$userip','','','$pagestyle','$maxwidth','$imgurls','$prow','$pcol','$isrm','$ddmaxwidth','$pagepicnum'{$inadd_v}); ";
  178. if(!$dsql->ExecuteNoneQuery($query))
  179. {
  180. $gerr = $dsql->GetError();
  181. $dsql->ExecuteNoneQuery("DELETE FROM `#@__archives` WHERE id='$arcID'");
  182. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID'");
  183. ShowMsg("把数据保存到数据库附加表 `{$addtable}` 时出错,请联系管理员!".$gerr,"javascript:;");
  184. exit();
  185. }
  186. }
  187. //增加积分
  188. $dsql->ExecuteNoneQuery("UPDATE `#@__member` SET scores=scores+{$cfg_sendarc_scores} WHERE mid='".$cfg_ml->M_ID."' ; ");
  189. //更新统计
  190. countArchives($channelid);
  191. //生成HTML
  192. InsertTags($tags,$arcID);
  193. $artUrl = MakeArt($arcID,true);
  194. if($artUrl=='') $artUrl = $cfg_phpurl."/view.php?aid=$arcID";
  195. //会员动态记录
  196. $cfg_ml->RecordFeeds('add', $title, $description, $arcID);
  197. ClearMyAddon($arcID, $title);
  198. //返回成功信息
  199. $msg = "
  200.   请选择你的后续操作:
  201. <a href='album_add.php?cid=$typeid'><u>继续发布图集</u></a>
  202. &nbsp;&nbsp;
  203. <a href='$artUrl' target='_blank'><u>查看图集</u></a>
  204. &nbsp;&nbsp;
  205. <a href='album_edit.php?aid=".$arcID."&channelid=$channelid'><u>更改图集</u></a>
  206. &nbsp;&nbsp;
  207. <a href='content_list.php?channelid={$channelid}'><u>已发布图集管理</u></a>
  208. ";
  209. $wintitle = "成功发布图集!";
  210. $wecome_info = "图集管理::发布图集";
  211. $win = new OxWindow();
  212. $win->AddTitle("成功发布图集:");
  213. $win->AddMsgItem($msg);
  214. $winform = $win->GetWindow("hand","&nbsp;",false);
  215. $win->Display();
  216. }