国内流行的内容管理系统(CMS)多端全媒体解决方案 https://www.dedebiz.com
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

225 lines
8.5KB

  1. <?php
  2. /**
  3. * 图集发布
  4. *
  5. * @version $Id: album_add.php 1 13:52 2010年7月9日Z tianya $
  6. * @package DedeCMS.Member
  7. * @copyright Copyright (c) 2007 - 2018, DesDev, Inc.
  8. * @copyright Copyright (c) 2020, DedeBIZ.COM
  9. * @license https://www.dedebiz.com/license/v6
  10. * @link https://www.dedebiz.com
  11. */
  12. require_once(dirname(__FILE__)."/config.php");
  13. //考虑安全原因不管是否开启游客投稿功能,都不允许用户对图集投稿
  14. CheckRank(0,0);
  15. if($cfg_mb_lit=='Y')
  16. {
  17. ShowMsg("由于系统开启了精简版会员空间,你访问的功能不可用!","-1");
  18. exit();
  19. }
  20. if($cfg_mb_album=='N')
  21. {
  22. ShowMsg("对不起,由于系统关闭了图集功能,你访问的功能不可用!","-1");
  23. exit();
  24. }
  25. require_once(DEDEINC."/dedetag.class.php");
  26. require_once(DEDEINC."/userlogin.class.php");
  27. require_once(DEDEINC."/customfields.func.php");
  28. require_once(DEDEMEMBER."/inc/inc_catalog_options.php");
  29. require_once(DEDEMEMBER."/inc/inc_archives_functions.php");
  30. $channelid = isset($channelid) && is_numeric($channelid) ? $channelid : 2;
  31. $typeid = isset($typeid) && is_numeric($typeid) ? $typeid : 0;
  32. $menutype = 'content';
  33. if(empty($formhtml)) $formhtml = 0;
  34. /*-------------
  35. function _ShowForm(){ }
  36. --------------*/
  37. if(empty($dopost))
  38. {
  39. $query = "SELECT * FROM `#@__channeltype` WHERE id='$channelid'; ";
  40. $cInfos = $dsql->GetOne($query);
  41. if(!is_array($cInfos))
  42. {
  43. ShowMsg('模型参数不正确', '-1');
  44. exit();
  45. }
  46. //检查会员等级和类型限制
  47. if($cInfos['sendrank'] > $cfg_ml->M_Rank)
  48. {
  49. $row = $dsql->GetOne("Select membername From `#@__arcrank` where rank='".$cInfos['sendrank']."' ");
  50. ShowMsg("对不起,需要[".$row['membername']."]才能在这个频道发布文档!","-1","0",5000);
  51. exit();
  52. }
  53. if($cInfos['usertype']!='' && $cInfos['usertype'] != $cfg_ml->M_MbType)
  54. {
  55. ShowMsg("对不起,需要[".$cInfos['usertype']."帐号]才能在这个频道发布文档!","-1","0",5000);
  56. exit();
  57. }
  58. include(DEDEMEMBER."/templets/album_add.htm");
  59. exit();
  60. }
  61. /*------------------------------
  62. function _SaveArticle(){ }
  63. ------------------------------*/
  64. else if($dopost=='save')
  65. {
  66. include(DEDEMEMBER.'/inc/archives_check.php');
  67. $svali = GetCkVdValue();
  68. if(preg_match("/1/",$safe_gdopen)){
  69. if(strtolower($vdcode)!=$svali || $svali=='')
  70. {
  71. ResetVdValue();
  72. ShowMsg('验证码错误!', '-1');
  73. exit();
  74. }
  75. }
  76. $cInfos = $dsql->GetOne("Select * From `#@__channeltype` where id='$channelid'; ");
  77. $maxwidth = isset($maxwidth) && is_numeric($maxwidth) ? $maxwidth : 800;
  78. $pagepicnum = isset($pagepicnum) && is_numeric($pagepicnum) ? $pagepicnum : 12;
  79. $ddmaxwidth = isset($ddmaxwidth) && is_numeric($ddmaxwidth) ? $ddmaxwidth : 200;
  80. $prow = isset($prow) && is_numeric($prow) ? $prow : 3;
  81. $pcol = isset($pcol) && is_numeric($pcol) ? $pcol : 3;
  82. $pagestyle = in_array($pagestyle,array('1','2','3')) ? $pagestyle : 2;
  83. include(DEDEMEMBER.'/inc/archives_check.php');
  84. $imgurls = "{dede:pagestyle maxwidth='$maxwidth' pagepicnum='$pagepicnum' ddmaxwidth='$ddmaxwidth' row='$prow' col='$pcol' value='$pagestyle'/}\r\n";
  85. $hasone = false;
  86. $ddisfirst=1;
  87. //只支持填写地址
  88. for($i=1;$i<=120;$i++)
  89. {
  90. if (!isset(${'imgfile'.$i})) {
  91. continue;
  92. }
  93. $f = ${'imgfile'.$i};
  94. $msg = isset(${'imgmsg'.$i})? ${'imgmsg'.$i} : "";
  95. if (!empty($f) && filter_var($f, FILTER_VALIDATE_URL)) {
  96. $u = str_replace(array("\"","'"), "`", $f);
  97. $info = str_replace(array("\"","'"), "`", $msg);
  98. $imgurls .= "{dede:img ddimg='' text='$info'} $u {/dede:img}\r\n";
  99. }
  100. }//循环结束
  101. $imgurls = addslashes($imgurls);
  102. //分析处理附加表数据
  103. $isrm = 1;
  104. if(!isset($formhtml))
  105. {
  106. $formhtml = 0;
  107. }
  108. $inadd_f = $inadd_v = '';
  109. if(!empty($dede_addonfields))
  110. {
  111. $addonfields = explode(';',$dede_addonfields);
  112. $inadd_f = '';
  113. $inadd_v = '';
  114. if(is_array($addonfields))
  115. {
  116. foreach($addonfields as $v)
  117. {
  118. if($v=='')
  119. {
  120. continue;
  121. }
  122. $vs = explode(',',$v);
  123. if(!isset(${$vs[0]}))
  124. {
  125. ${$vs[0]} = '';
  126. }
  127. ${$vs[0]} = GetFieldValueA(${$vs[0]},$vs[1],0);
  128. $inadd_f .= ','.$vs[0];
  129. $inadd_v .= " ,'".${$vs[0]}."' ";
  130. }
  131. }
  132. // 这里对前台提交的附加数据进行一次校验
  133. $fontiterm = PrintAutoFieldsAdd($cInfos['fieldset'],'autofield', FALSE);
  134. if ($fontiterm != $inadd_f)
  135. {
  136. ShowMsg("提交表单同系统配置不相符,请重新提交!", "-1");
  137. exit();
  138. }
  139. }
  140. //生成文档ID
  141. $arcID = GetIndexKey($arcrank,$typeid,$sortrank,$channelid,$senddate,$mid);
  142. if(empty($arcID))
  143. {
  144. ShowMsg("无法获得主键,因此无法进行后续操作!","-1");
  145. exit();
  146. }
  147. $description = HtmlReplace($description, -1);
  148. $mtypesid = intval($mtypesid); //对输入参数mtypesid未进行int整型转义,导致SQL注入的发生。
  149. //保存到主表
  150. $inQuery = "INSERT INTO `#@__archives`(id,typeid,sortrank,flag,ismake,channel,arcrank,click,money,title,shorttitle,
  151. color,writer,source,litpic,pubdate,senddate,mid,description,keywords,mtype)
  152. VALUES ('$arcID','$typeid','$sortrank','$flag','$ismake','$channelid','$arcrank','0','$money','$title','$shorttitle',
  153. '$color','$writer','$source','','$pubdate','$senddate','$mid','$description','$keywords','$mtypesid'); ";
  154. if(!$dsql->ExecuteNoneQuery($inQuery))
  155. {
  156. $gerr = $dsql->GetError();
  157. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID' ");
  158. ShowMsg("把数据保存到数据库主表 `#@__archives` 时出错,请联系管理员。","javascript:;");
  159. exit();
  160. }
  161. //保存到附加表
  162. $addtable = trim($cInfos['addtable']);
  163. if(empty($addtable))
  164. {
  165. $dsql->ExecuteNoneQuery("DELETE FROM `#@__archives` WHERE id='$arcID'");
  166. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID'");
  167. ShowMsg("没找到当前模型[{$channelid}]的主表信息,无法完成操作!。","javascript:;");
  168. exit();
  169. }
  170. else
  171. {
  172. $query = "INSERT INTO `$addtable`(aid,typeid,userip,redirecturl,templet,pagestyle,maxwidth,imgurls,row,col,isrm,ddmaxwidth,pagepicnum{$inadd_f})
  173. Values('$arcID','$typeid','$userip','','','$pagestyle','$maxwidth','$imgurls','$prow','$pcol','$isrm','$ddmaxwidth','$pagepicnum'{$inadd_v}); ";
  174. if(!$dsql->ExecuteNoneQuery($query))
  175. {
  176. $gerr = $dsql->GetError();
  177. $dsql->ExecuteNoneQuery("DELETE FROM `#@__archives` WHERE id='$arcID'");
  178. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID'");
  179. ShowMsg("把数据保存到数据库附加表 `{$addtable}` 时出错,请联系管理员!".$gerr,"javascript:;");
  180. exit();
  181. }
  182. }
  183. //增加积分
  184. $dsql->ExecuteNoneQuery("UPDATE `#@__member` SET scores=scores+{$cfg_sendarc_scores} WHERE mid='".$cfg_ml->M_ID."' ; ");
  185. //更新统计
  186. countArchives($channelid);
  187. //生成HTML
  188. InsertTags($tags,$arcID);
  189. $artUrl = MakeArt($arcID,true);
  190. if($artUrl=='') $artUrl = $cfg_phpurl."/view.php?aid=$arcID";
  191. ClearMyAddon($arcID, $title);
  192. //返回成功信息
  193. $msg = "
  194.   请选择你的后续操作:
  195. <a href='album_add.php?cid=$typeid' class='btn btn-secondary btn-sm'>继续发布图集</a>
  196. &nbsp;&nbsp;
  197. <a href='$artUrl' target='_blank' class='btn btn-secondary btn-sm'>查看图集</a>
  198. &nbsp;&nbsp;
  199. <a href='album_edit.php?aid=".$arcID."&channelid=$channelid' class='btn btn-secondary btn-sm'>更改图集</a>
  200. &nbsp;&nbsp;
  201. <a href='content_list.php?channelid={$channelid}' class='btn btn-secondary btn-sm'>已发布图集管理</a>
  202. ";
  203. $wintitle = "成功发布图集!";
  204. $wecome_info = "图集管理::发布图集";
  205. $win = new OxWindow();
  206. $win->AddTitle("成功发布图集:");
  207. $win->AddMsgItem($msg);
  208. $winform = $win->GetWindow("hand","&nbsp;",false);
  209. $win->Display();
  210. }