国内流行的内容管理系统(CMS)多端全媒体解决方案 https://www.dedebiz.com
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

224 lines
8.5KB

  1. <?php
  2. /**
  3. * 图集发布
  4. *
  5. * @version $Id: album_add.php 1 13:52 2010年7月9日Z tianya $
  6. * @package DedeCMS.Member
  7. * @copyright Copyright (c) 2020, DedeBIZ.COM
  8. * @license https://www.dedebiz.com/license
  9. * @link https://www.dedebiz.com
  10. */
  11. require_once(dirname(__FILE__)."/config.php");
  12. //考虑安全原因不管是否开启游客投稿功能,都不允许用户对图集投稿
  13. CheckRank(0,0);
  14. if($cfg_mb_lit=='Y')
  15. {
  16. ShowMsg("由于系统开启了精简版会员空间,你访问的功能不可用!","-1");
  17. exit();
  18. }
  19. if($cfg_mb_album=='N')
  20. {
  21. ShowMsg("对不起,由于系统关闭了图集功能,你访问的功能不可用!","-1");
  22. exit();
  23. }
  24. require_once(DEDEINC."/dedetag.class.php");
  25. require_once(DEDEINC."/userlogin.class.php");
  26. require_once(DEDEINC."/customfields.func.php");
  27. require_once(DEDEMEMBER."/inc/inc_catalog_options.php");
  28. require_once(DEDEMEMBER."/inc/inc_archives_functions.php");
  29. $channelid = isset($channelid) && is_numeric($channelid) ? $channelid : 2;
  30. $typeid = isset($typeid) && is_numeric($typeid) ? $typeid : 0;
  31. $menutype = 'content';
  32. if(empty($formhtml)) $formhtml = 0;
  33. /*-------------
  34. function _ShowForm(){ }
  35. --------------*/
  36. if(empty($dopost))
  37. {
  38. $query = "SELECT * FROM `#@__channeltype` WHERE id='$channelid'; ";
  39. $cInfos = $dsql->GetOne($query);
  40. if(!is_array($cInfos))
  41. {
  42. ShowMsg('模型参数不正确', '-1');
  43. exit();
  44. }
  45. //检查会员等级和类型限制
  46. if($cInfos['sendrank'] > $cfg_ml->M_Rank)
  47. {
  48. $row = $dsql->GetOne("Select membername From `#@__arcrank` where rank='".$cInfos['sendrank']."' ");
  49. ShowMsg("对不起,需要[".$row['membername']."]才能在这个频道发布文档!","-1","0",5000);
  50. exit();
  51. }
  52. if($cInfos['usertype']!='' && $cInfos['usertype'] != $cfg_ml->M_MbType)
  53. {
  54. ShowMsg("对不起,需要[".$cInfos['usertype']."帐号]才能在这个频道发布文档!","-1","0",5000);
  55. exit();
  56. }
  57. include(DEDEMEMBER."/templets/album_add.htm");
  58. exit();
  59. }
  60. /*------------------------------
  61. function _SaveArticle(){ }
  62. ------------------------------*/
  63. else if($dopost=='save')
  64. {
  65. include(DEDEMEMBER.'/inc/archives_check.php');
  66. $svali = GetCkVdValue();
  67. if(preg_match("/1/",$safe_gdopen)){
  68. if(strtolower($vdcode)!=$svali || $svali=='')
  69. {
  70. ResetVdValue();
  71. ShowMsg('验证码错误!', '-1');
  72. exit();
  73. }
  74. }
  75. $cInfos = $dsql->GetOne("Select * From `#@__channeltype` where id='$channelid'; ");
  76. $maxwidth = isset($maxwidth) && is_numeric($maxwidth) ? $maxwidth : 800;
  77. $pagepicnum = isset($pagepicnum) && is_numeric($pagepicnum) ? $pagepicnum : 12;
  78. $ddmaxwidth = isset($ddmaxwidth) && is_numeric($ddmaxwidth) ? $ddmaxwidth : 200;
  79. $prow = isset($prow) && is_numeric($prow) ? $prow : 3;
  80. $pcol = isset($pcol) && is_numeric($pcol) ? $pcol : 3;
  81. $pagestyle = in_array($pagestyle,array('1','2','3')) ? $pagestyle : 2;
  82. include(DEDEMEMBER.'/inc/archives_check.php');
  83. $imgurls = "{dede:pagestyle maxwidth='$maxwidth' pagepicnum='$pagepicnum' ddmaxwidth='$ddmaxwidth' row='$prow' col='$pcol' value='$pagestyle'/}\r\n";
  84. $hasone = false;
  85. $ddisfirst=1;
  86. //只支持填写地址
  87. for($i=1;$i<=120;$i++)
  88. {
  89. if (!isset(${'imgfile'.$i})) {
  90. continue;
  91. }
  92. $f = ${'imgfile'.$i};
  93. $msg = isset(${'imgmsg'.$i})? ${'imgmsg'.$i} : "";
  94. if (!empty($f) && filter_var($f, FILTER_VALIDATE_URL)) {
  95. $u = str_replace(array("\"","'"), "`", $f);
  96. $info = str_replace(array("\"","'"), "`", $msg);
  97. $imgurls .= "{dede:img ddimg='' text='$info'} $u {/dede:img}\r\n";
  98. }
  99. }//循环结束
  100. $imgurls = addslashes($imgurls);
  101. //分析处理附加表数据
  102. $isrm = 1;
  103. if(!isset($formhtml))
  104. {
  105. $formhtml = 0;
  106. }
  107. $inadd_f = $inadd_v = '';
  108. if(!empty($dede_addonfields))
  109. {
  110. $addonfields = explode(';',$dede_addonfields);
  111. $inadd_f = '';
  112. $inadd_v = '';
  113. if(is_array($addonfields))
  114. {
  115. foreach($addonfields as $v)
  116. {
  117. if($v=='')
  118. {
  119. continue;
  120. }
  121. $vs = explode(',',$v);
  122. if(!isset(${$vs[0]}))
  123. {
  124. ${$vs[0]} = '';
  125. }
  126. ${$vs[0]} = GetFieldValueA(${$vs[0]},$vs[1],0);
  127. $inadd_f .= ','.$vs[0];
  128. $inadd_v .= " ,'".${$vs[0]}."' ";
  129. }
  130. }
  131. // 这里对前台提交的附加数据进行一次校验
  132. $fontiterm = PrintAutoFieldsAdd($cInfos['fieldset'],'autofield', FALSE);
  133. if ($fontiterm != $inadd_f)
  134. {
  135. ShowMsg("提交表单同系统配置不相符,请重新提交!", "-1");
  136. exit();
  137. }
  138. }
  139. //生成文档ID
  140. $arcID = GetIndexKey($arcrank,$typeid,$sortrank,$channelid,$senddate,$mid);
  141. if(empty($arcID))
  142. {
  143. ShowMsg("无法获得主键,因此无法进行后续操作!","-1");
  144. exit();
  145. }
  146. $description = HtmlReplace($description, -1);
  147. $mtypesid = intval($mtypesid); //对输入参数mtypesid未进行int整型转义,导致SQL注入的发生。
  148. //保存到主表
  149. $inQuery = "INSERT INTO `#@__archives`(id,typeid,sortrank,flag,ismake,channel,arcrank,click,money,title,shorttitle,
  150. color,writer,source,litpic,pubdate,senddate,mid,description,keywords,mtype)
  151. VALUES ('$arcID','$typeid','$sortrank','$flag','$ismake','$channelid','$arcrank','0','$money','$title','$shorttitle',
  152. '$color','$writer','$source','','$pubdate','$senddate','$mid','$description','$keywords','$mtypesid'); ";
  153. if(!$dsql->ExecuteNoneQuery($inQuery))
  154. {
  155. $gerr = $dsql->GetError();
  156. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID' ");
  157. ShowMsg("把数据保存到数据库主表 `#@__archives` 时出错,请联系管理员。","javascript:;");
  158. exit();
  159. }
  160. //保存到附加表
  161. $addtable = trim($cInfos['addtable']);
  162. if(empty($addtable))
  163. {
  164. $dsql->ExecuteNoneQuery("DELETE FROM `#@__archives` WHERE id='$arcID'");
  165. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID'");
  166. ShowMsg("没找到当前模型[{$channelid}]的主表信息,无法完成操作!。","javascript:;");
  167. exit();
  168. }
  169. else
  170. {
  171. $query = "INSERT INTO `$addtable`(aid,typeid,userip,redirecturl,templet,pagestyle,maxwidth,imgurls,row,col,isrm,ddmaxwidth,pagepicnum{$inadd_f})
  172. Values('$arcID','$typeid','$userip','','','$pagestyle','$maxwidth','$imgurls','$prow','$pcol','$isrm','$ddmaxwidth','$pagepicnum'{$inadd_v}); ";
  173. if(!$dsql->ExecuteNoneQuery($query))
  174. {
  175. $gerr = $dsql->GetError();
  176. $dsql->ExecuteNoneQuery("DELETE FROM `#@__archives` WHERE id='$arcID'");
  177. $dsql->ExecuteNoneQuery("DELETE FROM `#@__arctiny` WHERE id='$arcID'");
  178. ShowMsg("把数据保存到数据库附加表 `{$addtable}` 时出错,请联系管理员!".$gerr,"javascript:;");
  179. exit();
  180. }
  181. }
  182. //增加积分
  183. $dsql->ExecuteNoneQuery("UPDATE `#@__member` SET scores=scores+{$cfg_sendarc_scores} WHERE mid='".$cfg_ml->M_ID."' ; ");
  184. //更新统计
  185. countArchives($channelid);
  186. //生成HTML
  187. InsertTags($tags,$arcID);
  188. $artUrl = MakeArt($arcID,true);
  189. if($artUrl=='') $artUrl = $cfg_phpurl."/view.php?aid=$arcID";
  190. ClearMyAddon($arcID, $title);
  191. //返回成功信息
  192. $msg = "
  193.   请选择你的后续操作:
  194. <a href='album_add.php?cid=$typeid' class='btn btn-secondary btn-sm'>继续发布图集</a>
  195. &nbsp;&nbsp;
  196. <a href='$artUrl' target='_blank' class='btn btn-secondary btn-sm'>查看图集</a>
  197. &nbsp;&nbsp;
  198. <a href='album_edit.php?aid=".$arcID."&channelid=$channelid' class='btn btn-secondary btn-sm'>更改图集</a>
  199. &nbsp;&nbsp;
  200. <a href='content_list.php?channelid={$channelid}' class='btn btn-secondary btn-sm'>已发布图集管理</a>
  201. ";
  202. $wintitle = "成功发布图集!";
  203. $wecome_info = "图集管理::发布图集";
  204. $win = new OxWindow();
  205. $win->AddTitle("成功发布图集:");
  206. $win->AddMsgItem($msg);
  207. $winform = $win->GetWindow("hand","&nbsp;",false);
  208. $win->Display();
  209. }