annotate usrajax.php @ 544:b4581dc165dc

Add output buffering.
author Matti Hamalainen <ccr@tnsp.org>
date Sun, 15 Dec 2013 23:57:05 +0200
parents 6e9d03f10328
children ed2247111fdd
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
1 <?
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
2 //
155
5b92f130ba87 Add copyright header blurbs.
Matti Hamalainen <ccr@tnsp.org>
parents: 153
diff changeset
3 // FAPWeb Simple Demoparty System
5b92f130ba87 Add copyright header blurbs.
Matti Hamalainen <ccr@tnsp.org>
parents: 153
diff changeset
4 // User actions page AJAX backend module
5b92f130ba87 Add copyright header blurbs.
Matti Hamalainen <ccr@tnsp.org>
parents: 153
diff changeset
5 // (C) Copyright 2012-2013 Tecnic Software productions (TNSP)
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
6 //
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
7 $sessionType = "user";
175
8df523e6326a User require_once instead of require.
Matti Hamalainen <ccr@tnsp.org>
parents: 165
diff changeset
8 require_once "mconfig.inc.php";
8df523e6326a User require_once instead of require.
Matti Hamalainen <ccr@tnsp.org>
parents: 165
diff changeset
9 require_once "msite.inc.php";
8df523e6326a User require_once instead of require.
Matti Hamalainen <ccr@tnsp.org>
parents: 165
diff changeset
10 require_once "msession.inc.php";
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
11
161
50032763bc79 Clean up the code a bit.
Matti Hamalainen <ccr@tnsp.org>
parents: 155
diff changeset
12 //
316
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
13 // Update one vote (prevalidated)
161
50032763bc79 Clean up the code a bit.
Matti Hamalainen <ccr@tnsp.org>
parents: 155
diff changeset
14 //
316
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
15 function stUpdateVote($key_id, $entry_id, $vote)
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
16 {
161
50032763bc79 Clean up the code a bit.
Matti Hamalainen <ccr@tnsp.org>
parents: 155
diff changeset
17 // Check if the vote already exists
316
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
18 $sql = stPrepareSQL("SELECT id FROM votes WHERE key_id=%d AND entry_id=%d",
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
19 $key_id, $entry_id);
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
20
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
21 if (($res = stFetchSQLColumn($sql)) === false)
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
22 {
161
50032763bc79 Clean up the code a bit.
Matti Hamalainen <ccr@tnsp.org>
parents: 155
diff changeset
23 // Didn't exist, insert it
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
24 $sql = stPrepareSQL(
316
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
25 "INSERT INTO votes (key_id,entry_id,value) VALUES (%d,%d,%d)",
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
26 $key_id, $entry_id, $vote);
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
27 }
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
28 else
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
29 {
161
50032763bc79 Clean up the code a bit.
Matti Hamalainen <ccr@tnsp.org>
parents: 155
diff changeset
30 // Existed, thusly update
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
31 $sql = stPrepareSQL(
316
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
32 "UPDATE votes SET value=%d WHERE key_id=%d AND entry_id=%d",
329
899a3583666d Yay, noscript voting also works now.
Matti Hamalainen <ccr@tnsp.org>
parents: 325
diff changeset
33 $vote, $key_id, $entry_id);
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
34 }
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
35
225
1bb4f4bcb027 Cleanups.
Matti Hamalainen <ccr@tnsp.org>
parents: 216
diff changeset
36 return stExecSQL($sql);
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
37 }
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
38
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
39
165
15182643d672 Cosmetics.
Matti Hamalainen <ccr@tnsp.org>
parents: 162
diff changeset
40 //
15182643d672 Cosmetics.
Matti Hamalainen <ccr@tnsp.org>
parents: 162
diff changeset
41 // Initialize
15182643d672 Cosmetics.
Matti Hamalainen <ccr@tnsp.org>
parents: 162
diff changeset
42 //
360
2af8458058ab Implement CSRF token checks.
Matti Hamalainen <ccr@tnsp.org>
parents: 332
diff changeset
43 if (!stUserSessionAuth() || !stCSRFCheck())
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
44 {
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
45 stSetupCacheControl();
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
46
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
47 stSessionEnd(SESS_USER);
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
48
123
5837b9333964 Add new "about" page, and setting for default page.
Matti Hamalainen <ccr@tnsp.org>
parents: 101
diff changeset
49 header("Location: ".stGetSetting("defaultPage"));
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
50 exit;
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
51 }
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
52
544
b4581dc165dc Add output buffering.
Matti Hamalainen <ccr@tnsp.org>
parents: 520
diff changeset
53 ob_start();
b4581dc165dc Add output buffering.
Matti Hamalainen <ccr@tnsp.org>
parents: 520
diff changeset
54
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
55 stSetupCacheControl();
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
56
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
57 if (!stConnectSQLDB())
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
58 die("Could not connect to SQL database.");
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
59
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
60 stReloadSettings();
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
61
310
8098b5b80f8c We won't be checking key validity while session is in progress, thus get rid
Matti Hamalainen <ccr@tnsp.org>
parents: 294
diff changeset
62 $voteKeyId = stGetSessionItem("key_id");
245
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
63 $voteMin = stGetSetting("voteMin");
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
64 $voteMax = stGetSetting("voteMax");
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
65
310
8098b5b80f8c We won't be checking key validity while session is in progress, thus get rid
Matti Hamalainen <ccr@tnsp.org>
parents: 294
diff changeset
66
161
50032763bc79 Clean up the code a bit.
Matti Hamalainen <ccr@tnsp.org>
parents: 155
diff changeset
67 //
50032763bc79 Clean up the code a bit.
Matti Hamalainen <ccr@tnsp.org>
parents: 155
diff changeset
68 // Handle the request
50032763bc79 Clean up the code a bit.
Matti Hamalainen <ccr@tnsp.org>
parents: 155
diff changeset
69 //
216
bcc3c4696b3e Some more work.
Matti Hamalainen <ccr@tnsp.org>
parents: 211
diff changeset
70 switch (stGetRequestItem("action"))
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
71 {
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
72 case "set":
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
73 //
153
aecf145e7c70 Some work on the voting backend.
Matti Hamalainen <ccr@tnsp.org>
parents: 123
diff changeset
74 // Set vote, if voting is enabled
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
75 //
245
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
76 if (!stChkSetting("allowVoting"))
294
efba5a51f8fa Fix some 10L's ... durr.
Matti Hamalainen <ccr@tnsp.org>
parents: 245
diff changeset
77 stError("Voting is not enabled.");
245
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
78 else
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
79 if (stChkRequestItem("entry_id", $entry_id,
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
80 array(CHK_TYPE, VT_INT, "Invalid data.")) &&
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
81 stChkRequestItem("vote", $vote,
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
82 array(CHK_TYPE, VT_INT, "Invalid data."),
294
efba5a51f8fa Fix some 10L's ... durr.
Matti Hamalainen <ccr@tnsp.org>
parents: 245
diff changeset
83 array(CHK_RANGE, VT_INT, array($voteMin, $voteMax), "Invalid vote value.")))
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
84 {
316
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
85 // Check if the entry_id is actually valid
520
6e9d03f10328 Add transactions to voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 368
diff changeset
86 stExecSQL("BEGIN TRANSACTION");
316
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
87 $sql = stPrepareSQL("SELECT * FROM entries WHERE id=%d", $entry_id);
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
88 if (($entry = stFetchSQL($sql)) !== false)
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
89 {
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
90 // Check if the compo is valid for the entry
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
91 $sql = stPrepareSQL("SELECT * FROM compos WHERE id=%d", $entry["compo_id"]);
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
92 if (($compo = stFetchSQL($sql)) !== false && $compo["voting"] != 0)
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
93 {
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
94 stUpdateVote($voteKeyId, $entry_id, $vote);
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
95 }
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
96 }
520
6e9d03f10328 Add transactions to voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 368
diff changeset
97 stExecSQL("COMMIT");
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
98 }
245
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
99 break;
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
100
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
101 case "submit":
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
102 if (!stChkSetting("allowVoting"))
294
efba5a51f8fa Fix some 10L's ... durr.
Matti Hamalainen <ccr@tnsp.org>
parents: 245
diff changeset
103 stError("Voting is not enabled.");
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
104 else
245
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
105 {
520
6e9d03f10328 Add transactions to voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 368
diff changeset
106 stExecSQL("BEGIN TRANSACTION");
316
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
107 foreach (stExecSQL("SELECT * FROM compos WHERE visible<>0 AND voting<>0") as $compo)
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
108 {
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
109 $cid = $compo["id"];
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
110 foreach (stExecSQL("SELECT * FROM entries WHERE compo_id=".$cid) as $entry)
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
111 {
329
899a3583666d Yay, noscript voting also works now.
Matti Hamalainen <ccr@tnsp.org>
parents: 325
diff changeset
112 $value = stGetRequestItem("ventry".$entry["id"], 0);
325
aac3bdd73ec1 More work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 316
diff changeset
113 if (!stUpdateVote($voteKeyId, $entry["id"], $value))
aac3bdd73ec1 More work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 316
diff changeset
114 {
aac3bdd73ec1 More work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 316
diff changeset
115 stError("Could not set vote for compo #".$cid.", entry #".$entry["id"]);
aac3bdd73ec1 More work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 316
diff changeset
116 break;
aac3bdd73ec1 More work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 316
diff changeset
117 }
316
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
118 }
54dfab6ba12c Work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 310
diff changeset
119 }
520
6e9d03f10328 Add transactions to voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 368
diff changeset
120 stExecSQL("COMMIT");
368
cbe2693a3cd1 Error handling improvements.
Matti Hamalainen <ccr@tnsp.org>
parents: 360
diff changeset
121
cbe2693a3cd1 Error handling improvements.
Matti Hamalainen <ccr@tnsp.org>
parents: 360
diff changeset
122 if ($errorSet)
325
aac3bdd73ec1 More work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 316
diff changeset
123 {
368
cbe2693a3cd1 Error handling improvements.
Matti Hamalainen <ccr@tnsp.org>
parents: 360
diff changeset
124 stSetSessionItem("mode", "error");
cbe2693a3cd1 Error handling improvements.
Matti Hamalainen <ccr@tnsp.org>
parents: 360
diff changeset
125 stSetSessionItem("error", $errorMsgs);
cbe2693a3cd1 Error handling improvements.
Matti Hamalainen <ccr@tnsp.org>
parents: 360
diff changeset
126 }
cbe2693a3cd1 Error handling improvements.
Matti Hamalainen <ccr@tnsp.org>
parents: 360
diff changeset
127 else
325
aac3bdd73ec1 More work on voting.
Matti Hamalainen <ccr@tnsp.org>
parents: 316
diff changeset
128 stSetSessionItem("mode", "done");
368
cbe2693a3cd1 Error handling improvements.
Matti Hamalainen <ccr@tnsp.org>
parents: 360
diff changeset
129
cbe2693a3cd1 Error handling improvements.
Matti Hamalainen <ccr@tnsp.org>
parents: 360
diff changeset
130 header("Location: ".stGetRequestItem("goto", "vote"));
245
bb96aef874a9 Work on the voting backend code.
Matti Hamalainen <ccr@tnsp.org>
parents: 225
diff changeset
131 }
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
132 break;
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
133
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
134 default:
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
135 stSetStatus(404, "Not Found");
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
136 break;
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
137 }
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
138
544
b4581dc165dc Add output buffering.
Matti Hamalainen <ccr@tnsp.org>
parents: 520
diff changeset
139 if ($errorSet)
b4581dc165dc Add output buffering.
Matti Hamalainen <ccr@tnsp.org>
parents: 520
diff changeset
140 {
b4581dc165dc Add output buffering.
Matti Hamalainen <ccr@tnsp.org>
parents: 520
diff changeset
141 ob_clean();
b4581dc165dc Add output buffering.
Matti Hamalainen <ccr@tnsp.org>
parents: 520
diff changeset
142 stDumpAJAXStatusErrors();
b4581dc165dc Add output buffering.
Matti Hamalainen <ccr@tnsp.org>
parents: 520
diff changeset
143 }
b4581dc165dc Add output buffering.
Matti Hamalainen <ccr@tnsp.org>
parents: 520
diff changeset
144
b4581dc165dc Add output buffering.
Matti Hamalainen <ccr@tnsp.org>
parents: 520
diff changeset
145 ob_end_flush();
93
f36ebd03afd6 User AJAX.
Matti Hamalainen <ccr@tnsp.org>
parents:
diff changeset
146 ?>