国内流行的内容管理系统(CMS)多端全媒体解决方案 https://www.dedebiz.com
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

202 lines
8.4KB

  1. <?php
  2. /**
  3. * 图集发布
  4. *
  5. * @version $Id: album_add.php 1 13:52 2010年7月9日Z tianya $
  6. * @package DedeBIZ.Member
  7. * @copyright Copyright (c) 2020, DedeBIZ.COM
  8. * @license https://www.dedebiz.com/license
  9. * @link https://www.dedebiz.com
  10. */
  11. require_once(dirname(__FILE__) . "/config.php");
  12. //考虑安全原因不管是否开启游客投稿功能,都不允许用户对图集投稿
  13. CheckRank(0, 0);
  14. if ($cfg_mb_lit == 'Y') {
  15. ShowMsg("由于系统开启了精简版会员空间,你访问的功能不可用!", "-1");
  16. exit();
  17. }
  18. if ($cfg_mb_album == 'N') {
  19. ShowMsg("对不起,由于系统关闭了图集功能,你访问的功能不可用!", "-1");
  20. exit();
  21. }
  22. require_once(DEDEINC . "/dedetag.class.php");
  23. require_once(DEDEINC . "/userlogin.class.php");
  24. require_once(DEDEINC . "/customfields.func.php");
  25. require_once(DEDEMEMBER . "/inc/inc_catalog_options.php");
  26. require_once(DEDEMEMBER . "/inc/inc_archives_functions.php");
  27. $channelid = isset($channelid) && is_numeric($channelid) ? $channelid : 2;
  28. $typeid = isset($typeid) && is_numeric($typeid) ? $typeid : 0;
  29. $menutype = 'content';
  30. if (empty($formhtml)) $formhtml = 0;
  31. /*-------------
  32. function _ShowForm(){ }
  33. --------------*/
  34. if (empty($dopost)) {
  35. $query = "SELECT * FROM `#@__channeltype` WHERE id='$channelid'; ";
  36. $cInfos = $dsql->GetOne($query);
  37. if (!is_array($cInfos)) {
  38. ShowMsg('模型参数不正确', '-1');
  39. exit();
  40. }
  41. //检查会员等级和类型限制
  42. if ($cInfos['sendrank'] > $cfg_ml->M_Rank) {
  43. $row = $dsql->GetOne("Select membername From `#@__arcrank` where rank='" . $cInfos['sendrank'] . "' ");
  44. ShowMsg("对不起,需要[" . $row['membername'] . "]才能在这个频道发布文档!", "-1", "0", 5000);
  45. exit();
  46. }
  47. if ($cInfos['usertype'] != '' && $cInfos['usertype'] != $cfg_ml->M_MbType) {
  48. ShowMsg("对不起,需要[" . $cInfos['usertype'] . "帐号]才能在这个频道发布文档!", "-1", "0", 5000);
  49. exit();
  50. }
  51. include(DEDEMEMBER . "/templets/album_add.htm");
  52. exit();
  53. }
  54. /*------------------------------
  55. function _SaveArticle(){ }
  56. ------------------------------*/ else if ($dopost == 'save') {
  57. include(DEDEMEMBER . '/inc/archives_check.php');
  58. $svali = GetCkVdValue();
  59. if (preg_match("/1/", $safe_gdopen)) {
  60. if (strtolower($vdcode) != $svali || $svali == '') {
  61. ResetVdValue();
  62. ShowMsg('验证码错误!', '-1');
  63. exit();
  64. }
  65. }
  66. $cInfos = $dsql->GetOne("Select * From `#@__channeltype` where id='$channelid'; ");
  67. $maxwidth = isset($maxwidth) && is_numeric($maxwidth) ? $maxwidth : 800;
  68. $pagepicnum = isset($pagepicnum) && is_numeric($pagepicnum) ? $pagepicnum : 12;
  69. $ddmaxwidth = isset($ddmaxwidth) && is_numeric($ddmaxwidth) ? $ddmaxwidth : 200;
  70. $prow = isset($prow) && is_numeric($prow) ? $prow : 3;
  71. $pcol = isset($pcol) && is_numeric($pcol) ? $pcol : 3;
  72. $pagestyle = in_array($pagestyle, array('1', '2', '3')) ? $pagestyle : 2;
  73. include(DEDEMEMBER . '/inc/archives_check.php');
  74. $imgurls = "{dede:pagestyle maxwidth='$maxwidth' pagepicnum='$pagepicnum' ddmaxwidth='$ddmaxwidth' row='$prow' col='$pcol' value='$pagestyle'/}\r\n";
  75. $hasone = false;
  76. $ddisfirst = 1;
  77. //只支持填写地址
  78. for ($i = 1; $i <= 120; $i++) {
  79. if (!isset(${'imgfile' . $i})) {
  80. continue;
  81. }
  82. $f = ${'imgfile' . $i};
  83. $msg = isset(${'imgmsg' . $i}) ? ${'imgmsg' . $i} : "";
  84. if (!empty($f) && filter_var($f, FILTER_VALIDATE_URL)) {
  85. $u = str_replace(array("\"", "'"), "`", $f);
  86. $info = str_replace(array("\"", "'"), "`", $msg);
  87. $imgurls .= "{dede:img ddimg='' text='$info'} $u {/dede:img}\r\n";
  88. }
  89. } //循环结束
  90. $imgurls = addslashes($imgurls);
  91. //分析处理附加表数据
  92. $isrm = 1;
  93. if (!isset($formhtml)) {
  94. $formhtml = 0;
  95. }
  96. $inadd_f = $inadd_v = '';
  97. if (!empty($dede_addonfields)) {
  98. $addonfields = explode(';', $dede_addonfields);
  99. $inadd_f = '';
  100. $inadd_v = '';
  101. if (is_array($addonfields)) {
  102. foreach ($addonfields as $v) {
  103. if ($v == '') {
  104. continue;
  105. }
  106. $vs = explode(',', $v);
  107. if (!isset(${$vs[0]})) {
  108. ${$vs[0]} = '';
  109. }
  110. ${$vs[0]} = GetFieldValueA(${$vs[0]}, $vs[1], 0);
  111. $inadd_f .= ',' . $vs[0];
  112. $inadd_v .= " ,'" . ${$vs[0]} . "' ";
  113. }
  114. }
  115. // 这里对前台提交的附加数据进行一次校验
  116. $fontiterm = PrintAutoFieldsAdd($cInfos['fieldset'], 'autofield', FALSE);
  117. if ($fontiterm != $inadd_f) {
  118. ShowMsg("提交表单同系统配置不相符,请重新提交!", "-1");
  119. exit();
  120. }
  121. }
  122. //生成文档ID
  123. $arcID = GetIndexKey($arcrank, $typeid, $sortrank, $channelid, $senddate, $mid);
  124. if (empty($arcID)) {
  125. ShowMsg("无法获得主键,因此无法进行后续操作!", "-1");
  126. exit();
  127. }
  128. $description = HtmlReplace($description, -1);
  129. $mtypesid = intval($mtypesid); //对输入参数mtypesid未进行int整型转义,导致SQL注入的发生。
  130. //保存到主表
  131. $inQuery = "INSERT INTO `#@__archives`(id,typeid,sortrank,flag,ismake,channel,arcrank,click,money,title,shorttitle,
  132. color,writer,source,litpic,pubdate,senddate,mid,description,keywords,mtype)
  133. VALUES ('$arcID','$typeid','$sortrank','$flag','$ismake','$channelid','$arcrank','0','$money','$title','$shorttitle',
  134. '$color','$writer','$source','','$pubdate','$senddate','$mid','$description','$keywords','$mtypesid'); ";
  135. if (!$dsql->ExecuteNoneQuery($inQuery)) {
  136. $gerr = $dsql->GetError();
  137. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID' ");
  138. ShowMsg("把数据保存到数据库主表 `#@__archives` 时出错,请联系管理员。", "javascript:;");
  139. exit();
  140. }
  141. //保存到附加表
  142. $addtable = trim($cInfos['addtable']);
  143. if (empty($addtable)) {
  144. $dsql->ExecuteNoneQuery("DELETE FROM `#@__archives` WHERE id='$arcID'");
  145. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID'");
  146. ShowMsg("没找到当前模型[{$channelid}]的主表信息,无法完成操作!。", "javascript:;");
  147. exit();
  148. } else {
  149. $query = "INSERT INTO `$addtable`(aid,typeid,userip,redirecturl,templet,pagestyle,maxwidth,imgurls,row,col,isrm,ddmaxwidth,pagepicnum{$inadd_f})
  150. Values('$arcID','$typeid','$userip','','','$pagestyle','$maxwidth','$imgurls','$prow','$pcol','$isrm','$ddmaxwidth','$pagepicnum'{$inadd_v}); ";
  151. if (!$dsql->ExecuteNoneQuery($query)) {
  152. $gerr = $dsql->GetError();
  153. $dsql->ExecuteNoneQuery("DELETE FROM `#@__archives` WHERE id='$arcID'");
  154. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID'");
  155. ShowMsg("把数据保存到数据库附加表 `{$addtable}` 时出错,请联系管理员!" . $gerr, "javascript:;");
  156. exit();
  157. }
  158. }
  159. //增加积分
  160. $dsql->ExecuteNoneQuery("UPDATE `#@__member` SET scores=scores+{$cfg_sendarc_scores} WHERE mid='" . $cfg_ml->M_ID . "' ; ");
  161. //更新统计
  162. countArchives($channelid);
  163. //生成HTML
  164. InsertTags($tags, $arcID);
  165. $artUrl = MakeArt($arcID, true);
  166. if ($artUrl == '') $artUrl = $cfg_phpurl . "/view.php?aid=$arcID";
  167. ClearMyAddon($arcID, $title);
  168. //返回成功信息
  169. $msg = "
  170.   请选择你的后续操作:
  171. <a href='album_add.php?cid=$typeid' class='btn btn-secondary btn-sm'>继续发布图集</a>
  172. &nbsp;&nbsp;
  173. <a href='$artUrl' target='_blank' class='btn btn-secondary btn-sm'>查看图集</a>
  174. &nbsp;&nbsp;
  175. <a href='album_edit.php?aid=" . $arcID . "&channelid=$channelid' class='btn btn-secondary btn-sm'>更改图集</a>
  176. &nbsp;&nbsp;
  177. <a href='content_list.php?channelid={$channelid}' class='btn btn-secondary btn-sm'>已发布图集管理</a>
  178. ";
  179. $wintitle = "成功发布图集!";
  180. $wecome_info = "图集管理::发布图集";
  181. $win = new OxWindow();
  182. $win->AddTitle("成功发布图集:");
  183. $win->AddMsgItem($msg);
  184. $winform = $win->GetWindow("hand", "&nbsp;", false);
  185. $win->Display();
  186. }