NobuNobu
nobun****@users*****
2005年 8月 21日 (日) 13:16:53 JST
Index: xoops2jp/html/modules/mydownloads/admin/index.php diff -u xoops2jp/html/modules/mydownloads/admin/index.php:1.4 xoops2jp/html/modules/mydownloads/admin/index.php:1.4.2.1 --- xoops2jp/html/modules/mydownloads/admin/index.php:1.4 Wed Aug 3 21:39:12 2005 +++ xoops2jp/html/modules/mydownloads/admin/index.php Sun Aug 21 13:16:53 2005 @@ -1,5 +1,5 @@ <?php -// $Id: index.php,v 1.4 2005/08/03 12:39:12 onokazu Exp $ +// $Id: index.php,v 1.4.2.1 2005/08/21 04:16:53 nobunobu Exp $ // ------------------------------------------------------------------------ // // XOOPS - PHP Content Management System // // Copyright (c) 2000 XOOPS.org // @@ -267,9 +267,9 @@ function modDownload() { - global $xoopsDB, $HTTP_GET_VARS, $myts, $eh, $mytree; + global $xoopsDB, $myts, $eh, $mytree; $downimg_array = XoopsLists::getImgListAsArray(XOOPS_ROOT_PATH."/modules/mydownloads/images/shots/"); - $lid = $HTTP_GET_VARS['lid']; + $lid = $_GET['lid']; xoops_cp_header(); echo "<h4>"._MD_DLCONF."</h4>"; echo"<table width='100%' border='0' cellspacing='1' class='outer'>" @@ -417,9 +417,9 @@ function delVote() { - global $xoopsDB, $HTTP_GET_VARS, $eh; - $rid = $HTTP_GET_VARS['rid']; - $lid = $HTTP_GET_VARS['lid']; + global $xoopsDB, $eh; + $rid = $_GET['rid']; + $lid = $_GET['lid']; $sql = sprintf("DELETE FROM %s WHERE ratingid = %u", $xoopsDB->prefix("mydownloads_votedata"), $rid); $xoopsDB->query($sql) or $eh->show("0013"); updaterating($lid); @@ -494,8 +494,8 @@ function delBrokenDownloads() { - global $xoopsDB, $HTTP_GET_VARS, $eh; - $lid = $HTTP_GET_VARS['lid']; + global $xoopsDB, $eh; + $lid = $_GET['lid']; $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_broken"), $lid); $xoopsDB->query($sql) or $eh->show("0013"); $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_downloads"), $lid); @@ -505,8 +505,8 @@ function ignoreBrokenDownloads() { - global $xoopsDB, $HTTP_GET_VARS, $eh; - $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_broken"), $HTTP_GET_VARS['lid']); + global $xoopsDB, $eh; + $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_broken"), $_GET['lid']); $xoopsDB->query($sql) or $eh->show("0013"); redirect_header("index.php",1,_MD_BROKENDELETED); } @@ -630,8 +630,8 @@ function changeModReq() { - global $xoopsDB, $HTTP_GET_VARS, $eh, $myts; - $requestid = $HTTP_GET_VARS['requestid']; + global $xoopsDB, $eh, $myts; + $requestid = $_GET['requestid']; $query = "SELECT lid, cid, title, url, homepage, version, size, platform, logourl, description FROM ".$xoopsDB->prefix("mydownloads_mod")." WHERE requestid=$requestid"; $result = $xoopsDB->query($query); while(list($lid, $cid, $title, $url, $homepage, $version, $size, $platform, $logourl, $description)=$xoopsDB->fetchRow($result)) { @@ -659,51 +659,51 @@ function ignoreModReq() { - global $xoopsDB, $HTTP_GET_VARS, $eh; - $sql = sprintf("DELETE FROM %s WHERE requestid = %u", $xoopsDB->prefix("mydownloads_mod"), $HTTP_GET_VARS['requestid']); + global $xoopsDB, $eh; + $sql = sprintf("DELETE FROM %s WHERE requestid = %u", $xoopsDB->prefix("mydownloads_mod"), $_GET['requestid']); $xoopsDB->query($sql) or $eh->show("0013"); redirect_header("index.php",1,_MD_MODREQDELETED); } function modDownloadS() { - global $xoopsDB, $HTTP_POST_VARS, $myts, $eh; - $cid = $HTTP_POST_VARS["cid"]; - if (($HTTP_POST_VARS["url"]) || ($HTTP_POST_VARS["url"]!="")) { - $url = $myts->makeTboxData4Save($HTTP_POST_VARS["url"]); - } - $logourl = $myts->makeTboxData4Save($HTTP_POST_VARS["logourl"]); - $title = $myts->makeTboxData4Save($HTTP_POST_VARS["title"]); - $homepage = $myts->makeTboxData4Save($HTTP_POST_VARS["homepage"]); - $version = $myts->makeTboxData4Save($HTTP_POST_VARS["version"]); - $size = $myts->makeTboxData4Save($HTTP_POST_VARS["size"]); - $platform = $myts->makeTboxData4Save($HTTP_POST_VARS["platform"]); - $description = $myts->makeTareaData4Save($HTTP_POST_VARS["description"]); - $sql = sprintf("UPDATE %s SET cid = %u, title = '%s', url = '%s', homepage = '%s', version = '%s', size = %u, platform = '%s', logourl = '%s', status = %u, date = %u WHERE lid = %u", $xoopsDB->prefix("mydownloads_downloads"), $cid, $title, $url, $homepage, $version, $size, $platform, $logourl, 2, time(), $HTTP_POST_VARS['lid']); + global $xoopsDB, $myts, $eh; + $cid = $_POST["cid"]; + if (($_POST["url"]) || ($_POST["url"]!="")) { + $url = $myts->makeTboxData4Save($_POST["url"]); + } + $logourl = $myts->makeTboxData4Save($_POST["logourl"]); + $title = $myts->makeTboxData4Save($_POST["title"]); + $homepage = $myts->makeTboxData4Save($_POST["homepage"]); + $version = $myts->makeTboxData4Save($_POST["version"]); + $size = $myts->makeTboxData4Save($_POST["size"]); + $platform = $myts->makeTboxData4Save($_POST["platform"]); + $description = $myts->makeTareaData4Save($_POST["description"]); + $sql = sprintf("UPDATE %s SET cid = %u, title = '%s', url = '%s', homepage = '%s', version = '%s', size = %u, platform = '%s', logourl = '%s', status = %u, date = %u WHERE lid = %u", $xoopsDB->prefix("mydownloads_downloads"), $cid, $title, $url, $homepage, $version, $size, $platform, $logourl, 2, time(), $_POST['lid']); $xoopsDB->query($sql) or $eh->show("0013"); - $sql = sprintf("UPDATE %s SET description = '%s' WHERE lid = %u", $xoopsDB->prefix("mydownloads_text"), $description, $HTTP_POST_VARS['lid']); + $sql = sprintf("UPDATE %s SET description = '%s' WHERE lid = %u", $xoopsDB->prefix("mydownloads_text"), $description, $_POST['lid']); $xoopsDB->query($sql) or $eh->show("0013"); redirect_header("index.php",1,_MD_DBUPDATED); } function delDownload() { - global $xoopsDB, $HTTP_GET_VARS, $eh, $xoopsModule; - $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_downloads"), $HTTP_GET_VARS['lid']); + global $xoopsDB, $eh, $xoopsModule; + $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_downloads"), $_GET['lid']); $xoopsDB->query($sql) or $eh->show("0013"); - $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_text"), $HTTP_GET_VARS['lid']); + $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_text"), $_GET['lid']); $xoopsDB->query($sql) or $eh->show("0013"); - $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_votedata"), $HTTP_GET_VARS['lid']); + $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_votedata"), $_GET['lid']); $xoopsDB->query($sql) or $eh->show("0013"); // delete comments - xoops_comment_delete($xoopsModule->getVar('mid'), $HTTP_GET_VARS['lid']); + xoops_comment_delete($xoopsModule->getVar('mid'), $_GET['lid']); redirect_header("index.php",1,_MD_FILEDELETED); } function modCat() { - global $xoopsDB, $HTTP_POST_VARS, $myts, $eh, $mytree; - $cid = $HTTP_POST_VARS["cid"]; + global $xoopsDB, $myts, $eh, $mytree; + $cid = $_POST["cid"]; xoops_cp_header(); echo "<h4>"._MD_DLCONF."</h4>"; echo"<table width='100%' border='0' cellspacing='1' class='outer'>" @@ -728,16 +728,16 @@ function modCatS() { - global $xoopsDB, $HTTP_POST_VARS, $myts, $eh; - $cid = $HTTP_POST_VARS['cid']; - $sid = $HTTP_POST_VARS['pid']; - $title = $myts->makeTboxData4Save($HTTP_POST_VARS['title']); + global $xoopsDB, $myts, $eh; + $cid = $_POST['cid']; + $sid = $_POST['pid']; + $title = $myts->makeTboxData4Save($_POST['title']); if (empty($title)) { redirect_header("index.php", 2, _MD_ERRORTITLE); exit(); } - if (($HTTP_POST_VARS["imgurl"]) || ($HTTP_POST_VARS["imgurl"]!="")) { - $imgurl = $myts->makeTboxData4Save($HTTP_POST_VARS["imgurl"]); + if (($_POST["imgurl"]) || ($_POST["imgurl"]!="")) { + $imgurl = $myts->makeTboxData4Save($_POST["imgurl"]); } $sql = sprintf("UPDATE %s SET title = '%s', imgurl = '%s', pid = %u WHERE cid = %u", $xoopsDB->prefix("mydownloads_cat"), $title, $imgurl, $sid, $cid); $xoopsDB->query($sql) or $eh->show("0013"); @@ -746,9 +746,9 @@ function delCat() { - global $xoopsDB, $HTTP_GET_VARS, $HTTP_POST_VARS, $eh, $mytree, $xoopsModule; - $cid = isset($HTTP_POST_VARS['cid']) ? intval($HTTP_POST_VARS['cid']) : intval($HTTP_GET_VARS['cid']); - $ok = isset($HTTP_POST_VARS['ok']) ? intval($HTTP_POST_VARS['ok']) : 0; + global $xoopsDB, $eh, $mytree, $xoopsModule; + $cid = isset($_POST['cid']) ? intval($_POST['cid']) : intval($_GET['cid']); + $ok = isset($_POST['ok']) ? intval($_POST['ok']) : 0; if ($ok == 1) { //get all subcategories under the specified category $arr=$mytree->getAllChildId($cid); @@ -798,26 +798,26 @@ function delNewDownload() { - global $xoopsDB, $HTTP_GET_VARS, $eh, $xoopsModule; - $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_downloads"), $HTTP_GET_VARS['lid']); + global $xoopsDB, $eh, $xoopsModule; + $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_downloads"), $_GET['lid']); $xoopsDB->query($sql) or $eh->show("0013"); - $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_text"), $HTTP_GET_VARS['lid']); + $sql = sprintf("DELETE FROM %s WHERE lid = %u", $xoopsDB->prefix("mydownloads_text"), $_GET['lid']); $xoopsDB->query($sql) or $eh->show("0013"); // delete comments - xoops_comment_delete($xoopsModule->getVar('mid'), $HTTP_GET_VARS['lid']); + xoops_comment_delete($xoopsModule->getVar('mid'), $_GET['lid']); redirect_header("index.php",1,_MD_FILEDELETED); } function addCat() { - global $xoopsDB, $HTTP_POST_VARS, $myts, $eh; - $pid = $HTTP_POST_VARS["cid"]; - $title = $myts->makeTboxData4Save($HTTP_POST_VARS["title"]); + global $xoopsDB, $myts, $eh; + $pid = $_POST["cid"]; + $title = $myts->makeTboxData4Save($_POST["title"]); if (empty($title)) { redirect_header("index.php", 2, _MD_ERRORTITLE); } - if (($HTTP_POST_VARS["imgurl"]) || ($HTTP_POST_VARS["imgurl"]!="")) { - $imgurl = $myts->makeTboxData4Save($HTTP_POST_VARS["imgurl"]); + if (($_POST["imgurl"]) || ($_POST["imgurl"]!="")) { + $imgurl = $myts->makeTboxData4Save($_POST["imgurl"]); } $newid = $xoopsDB->genId($xoopsDB->prefix("mydownloads_cat")."_cid_seq"); $sql = sprintf("INSERT INTO %s (cid, pid, title, imgurl) VALUES (%u, %u, '%s', '%s')", $xoopsDB->prefix("mydownloads_cat"), $newid, $pid, $title, $imgurl); @@ -837,15 +837,15 @@ function addDownload() { - global $xoopsDB, $xoopsUser, $xoopsModule, $HTTP_POST_VARS, $myts, $eh; - $url = $myts->makeTboxData4Save(formatURL($HTTP_POST_VARS["url"])); - $logourl = $myts->makeTboxData4Save($HTTP_POST_VARS["logourl"]); - $title = $myts->makeTboxData4Save($HTTP_POST_VARS["title"]); - $homepage = $myts->makeTboxData4Save(formatURL($HTTP_POST_VARS["homepage"])); - $version = $myts->makeTboxData4Save($HTTP_POST_VARS["version"]); - $size = $myts->makeTboxData4Save($HTTP_POST_VARS["size"]); - $platform = $myts->makeTboxData4Save($HTTP_POST_VARS["platform"]); - $description = $myts->makeTareaData4Save($HTTP_POST_VARS["description"]); + global $xoopsDB, $xoopsUser, $xoopsModule, $myts, $eh; + $url = $myts->makeTboxData4Save(formatURL($_POST["url"])); + $logourl = $myts->makeTboxData4Save($_POST["logourl"]); + $title = $myts->makeTboxData4Save($_POST["title"]); + $homepage = $myts->makeTboxData4Save(formatURL($_POST["homepage"])); + $version = $myts->makeTboxData4Save($_POST["version"]); + $size = $myts->makeTboxData4Save($_POST["size"]); + $platform = $myts->makeTboxData4Save($_POST["platform"]); + $description = $myts->makeTareaData4Save($_POST["description"]); $submitter = $xoopsUser->uid(); $result = $xoopsDB->query("SELECT COUNT(*) FROM ".$xoopsDB->prefix("mydownloads_downloads")." WHERE url='$url'"); list($numrows) = $xoopsDB->fetchRow($result); @@ -877,8 +877,8 @@ xoops_cp_footer(); exit(); } - if ( !empty($HTTP_POST_VARS['cid']) ) { - $cid = $HTTP_POST_VARS['cid']; + if ( !empty($_POST['cid']) ) { + $cid = $_POST['cid']; } else { $cid = 0; } @@ -907,27 +907,27 @@ function approve() { - global $xoopsConfig, $xoopsDB, $HTTP_POST_VARS, $myts, $eh; - $lid = $HTTP_POST_VARS['lid']; - $title = $HTTP_POST_VARS['title']; - $cid = $HTTP_POST_VARS['cid']; + global $xoopsConfig, $xoopsDB, $myts, $eh; + $lid = $_POST['lid']; + $title = $_POST['title']; + $cid = $_POST['cid']; if ( empty($cid) ) { $cid = 0; } - $homepage = $HTTP_POST_VARS['homepage']; - $version = $HTTP_POST_VARS['version']; - $size = $HTTP_POST_VARS['size']; - $platform = $HTTP_POST_VARS['platform']; - $description = $HTTP_POST_VARS['description']; - if (($HTTP_POST_VARS["url"]) || ($HTTP_POST_VARS["url"]!="")) { - $url = $myts->makeTboxData4Save($HTTP_POST_VARS["url"]); + $homepage = $_POST['homepage']; + $version = $_POST['version']; + $size = $_POST['size']; + $platform = $_POST['platform']; + $description = $_POST['description']; + if (($_POST["url"]) || ($_POST["url"]!="")) { + $url = $myts->makeTboxData4Save($_POST["url"]); } - $logourl = $myts->makeTboxData4Save($HTTP_POST_VARS["logourl"]); + $logourl = $myts->makeTboxData4Save($_POST["logourl"]); $title = $myts->makeTboxData4Save($title); $homepage = $myts->makeTboxData4Save($homepage); - $version = $myts->makeTboxData4Save($HTTP_POST_VARS["version"]); - $size = $myts->makeTboxData4Save($HTTP_POST_VARS["size"]); - $platform = $myts->makeTboxData4Save($HTTP_POST_VARS["platform"]); + $version = $myts->makeTboxData4Save($_POST["version"]); + $size = $myts->makeTboxData4Save($_POST["size"]); + $platform = $myts->makeTboxData4Save($_POST["platform"]); $description = $myts->makeTareaData4Save($description); $sql = sprintf("UPDATE %s SET cid = %u, title = '%s', url = '%s', homepage = '%s', version = '%s', size = %u, platform = '%s', logourl = '%s', status = %u, date = %u WHERE lid = %u", $xoopsDB->prefix("mydownloads_downloads"), $cid, $title, $url, $homepage, $version, $size, $platform, $logourl, 1, time(), $lid); $xoopsDB->query($sql) or $eh->show("0013"); @@ -948,10 +948,10 @@ $notification_handler->triggerEvent('file', $lid, 'approve', $tags); redirect_header("index.php",1,_MD_NEWDLADDED); } -if(!isset($HTTP_POST_VARS['op'])) { - $op = isset($HTTP_GET_VARS['op']) ? $HTTP_GET_VARS['op'] : 'main'; +if(!isset($_POST['op'])) { + $op = isset($_GET['op']) ? $_GET['op'] : 'main'; } else { - $op = $HTTP_POST_VARS['op']; + $op = $_POST['op']; } switch ($op) { case "delNewDownload":