use user->is_appr() when needed
[brisk.git] / web / index_wr.php
1 <?php
2 /*
3  *  brisk - index_wr.php
4  *
5  *  Copyright (C) 2006-2015 Matteo Nastasi
6  *                          mailto: nastasi@alternativeoutput.it
7  *                                  matteo.nastasi@milug.org
8  *                          web: http://www.alternativeoutput.it
9  *
10  * This program is free software; you can redistribute it and/or modify
11  * it under the terms of the GNU General Public License as published by
12  * the Free Software Foundation; either version 2 of the License, or
13  * (at your option) any later version.
14  *
15  * This program is distributed in the hope that it will be useful, but
16  * WITHOUT ANY WARRANTY; without even the implied warranty of
17  * MERCHANTABLILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
18  * General Public License for more details. You should have received a
19  * copy of the GNU General Public License along with this program; if
20  * not, write to the Free Software Foundation, Inc, 59 Temple Place -
21  * Suite 330, Boston, MA 02111-1307, USA.
22  *
23  */
24
25 $mlang_indwr = array( 'unknownerr'    => array( 'it' => 'errore sconosciuto',
26                                                 'en' => 'unknown error'),
27                       'btn_backtotab' => array( 'it' => 'Torna ai tavoli.',
28                                                 'en' => 'Back to tables.' ),
29                       'warrrepl'  => array( 'it' => '<br>Il nominativo &egrave; stato inoltrato all\'amministratore.<br><br>Nell\'arco di pochi giorni verr&agrave;<br><br>notificata al garantito l\'avvenuta registrazione.',
30                                             'en' => '<br>The subscription was forwarded to the administrator.<br><br>In a few days we will notify<br><br>your friend the occurred registration.'),
31                       'btn_close' => array( 'it' => 'chiudi',
32                                             'en' => 'close' ),
33                       'commerr' => array( 'it' => '<b>E\' occorso un errore durante il salvataggio, riprova o contatta l\'amministratore.</b>',
34                                           'en' => '<b>An error was occurred during the saving, try again or contact the administrator.</b>'),
35                       'coerrdb' => array( 'it' => '<b>Il database è temporaneamente irraggiungibile, riprova più tardi o contatta l\'amministratore.</b>',
36                                           'en' => '<b>The database is temporarly unavailable, retry to later or conctact the administrator.</b>'),
37                       'warrmust' => array( 'it' => '<b>Per autenticare qualcuno devi a tua volta essere autenticato e certificato.</b>',
38                                            'en' => 'To authenticate somebody you have to be authenticated and certified yourown'),
39                       'mesgrepl' => array( 'it' => '<br><br>Il messaggio &egrave; stato inoltrato all\'amministratore.',
40                                            'en' => '<br><br>The message was forwarded to the administrator'),
41                       'mesgmust' => array( 'it' => '<b>Per mandare messaggi all\'amministratore devi essere autenticato.</b>',
42                                            'en' => 'To send a message to the administrator you have to be authenticated'),
43                       'shutmsg'  => array( 'it' => '<b>Il server sta per essere riavviato, non possono avere inizio nuove partite.</b>',
44                                            'en' => '<b>The server is going to be rebooted, new games are not allowed.</b>'),
45                       'mustauth' => array( 'it' => '<b>Il tavolo a cui volevi sederti richiede autentifica.</b>',
46                                            'en' => '<b>The table where you want to sit require authentication</b>'),
47                       'mustcert' => array( 'it' => '<b>Il tavolo a cui volevi sederti richiede autentifica e certificazione.</b>',
48                                            'en' => '<b>The table where you want to sit require authentication and certification</b>'),
49                       'tabwait'=> array( 'it' => '<b>Il tavolo si &egrave; appena liberato, ci si potr&agrave; sedere tra %d secondi.',
50                                            'en' => '<b>The table is only just opened, you will sit down in %d seconds.'),
51                       'mustfirst'=> array( 'it' => '<b>Il tuo utente può sedersi al tavolo solo per primo.</b>',
52                                            'en' => '<b>Your can sit down as first user only.' ),
53                       'pollmust' => array( 'it' => '<b>Per partecipare al sondaggio devi essere autenticato.</b>',
54                                            'en' => '<b>To vote for the poll you have to be authenticated</b>'),
55                       'pollnone' => array( 'it' => '<br><br>Al momento non è attivo alcun sondaggio.',
56                                            'en' => '<br><br>At this moment no polls are active.'),
57                       'pollchoo' => array( 'it' => '<br><br>Non hai espresso nessuna preferenza.',
58                                            'en' => '<br><br>You don\'t choose any preference, do it'),
59                       'pollagai' => array( 'it' => '<br>Per questo sondaggio hai già votato.<br><br>Non si può esprimere la propria preferenza più di una volta.',
60                                            'en' => '<br>You just express your preference about this poll.<br><br>You cannot do it again.'),
61                       'pollrec'  => array ('it' => '<br><br>Il tuo voto è stato registrato.',
62                                            'en' => '<br><br>Your vote had be stored.'),
63                       'badwake_a'=> array( 'it' => '<br>Ti sei alzato da un tavolo senza il consenso degli altri giocatori.<br><br>Dovrai aspettare ancora ',
64                                            'en' => '<br>You stand up without the permission of the other players.<br><br>You will wait '),
65                       'badwake_b'=> array( 'it' => ' prima di poterti sedere nuovamente.',
66                                            'en' => ' before you can sit down again.'),
67                       'btn_stays'=> array( 'it' => 'resta in piedi.',
68                                            'en' => 'stay standing.'),
69                       'badsit_a' => array( 'it' => '<br>Tu o qualcuno col tuo stesso indirizzo IP si è alzato da un tavolo senza il consenso degli altri giocatori.<br><br>Dovrai aspettare ancora ',
70                                            'en' => '<br>You or someone with your same IP address is standing up from a table without the permission of the other players <br><br>You will wait '),
71                       'badsit_b' => array( 'it' => ' prima di poterti sedere nuovamente.<br><br>Se non sei stato tu ad alzarti e possiedi un login con password, autenticandoti con quello, potrai accedere.',
72                                            'en' => ' before you can sit down again. If you don\'t leave the table and you have a login with a password, authenticating with this one you will access'),
73                       'nu_netguard' => array('it' => "Di recente è già arrivata una richiesta da un indirizzo IP simile al tuo, riprova tra qualche tempo.",
74                                              'en' => "EN di recente è già arrivata una richiesta da un indirizzo IP simile al tuo, riprova tra qualche tempo."),
75                       'nu_unkerr' => array('it' => "Si è verificato un errore inatteso, contattare l'amministratore.",
76                                            'en' => "EN Si è verificato un errore inatteso, contattare l'amministratore."),
77                       'nu_loginau' => array('it' => "login già in uso",
78                                             'en' => "login already in use"),
79                       'nu_emailau' => array('it' => "email già utilizzata",
80                                             'en' => "email already in use"),
81                       'nu_msubj' => array( 'it' => 'Brisk: verifica email',
82                                            'en' => 'Brisk: email verification'),
83                       // %s(guar) %s(login) %s(baseurl) %d(code) %s(hash)
84                       'nu_mtext' => array( 'it' =>
85 'Ciao, sono l\' amministratore del sito di Brisk.
86
87 L\' utente \'%s\' ha garantito per te col nickname \'%s\',
88 vai al link: <%s>
89 per confermare il tuo indirizzo di posta elettronica.
90
91 Ciò è necessario per ottenere la password.
92
93 Saluti e buone partite, mop.',
94                                            'en' => 'EN mtext [%s] [%s] [%s]'),
95                       'nu_mhtml' => array( 'it' => 'Ciao, sono l\' amministratore del sito di Brisk.<br><br>
96 L\' utente \'%s\' ha garantito per te col nickname \'%s\',<br>
97 <a href="%s">clicca qui</a> per confermare il tuo indirizzo di posta elettronica.<br><br>
98 Ciò è necessario per ottenere la password.<br><br>
99 Saluti e buone partite, mop.<br>',
100                                            'en' => 'EN mhtml [%s] [%s] [%s]'),
101
102                       'ap_mtext' => array( 'it' =>
103 'Ciao, sono l\' amministratore del sito di Brisk.
104
105 Ti sei registrato col nickname \'%s\',
106 vai al link: <%s>
107 per confermare il tuo indirizzo di posta elettronica.
108
109 Ciò è necessario per ottenere la password.
110
111 Saluti e buone partite, mop.',
112                                            'en' => 'EN mtext [%s] [%s]'),
113
114                       'ap_mhtml' => array( 'it' => 'Ciao, sono l\' amministratore del sito di Brisk.<br><br>
115 Ti sei registrato col nickname \'%s\',<br>
116 <a href="%s">clicca qui</a> per confermare il tuo indirizzo di posta elettronica.<br><br>
117 Ciò è necessario per ottenere la password.<br><br>
118 Saluti e buone partite, mop.<br>',
119                                            'en' => 'EN mhtml [%s] [%s]'),
120                       );
121
122 define('LICMGR_CHO_ACCEPT', 0);
123 define('LICMGR_CHO_REFUSE', 1);
124 define('LICMGR_CHO_AFTER',  2);
125
126 function index_wr_main(&$brisk, $remote_addr_full, $get, $post, $cookie)
127 {
128     GLOBAL $G_domain, $G_webbase, $G_mail_seed, $G_notguar_code;
129     GLOBAL $G_shutdown, $G_alarm_passwd, $G_ban_list, $G_black_list, $G_lang, $G_room_help, $G_room_about;
130     GLOBAL $G_room_passwdhowto, $mlang_indwr;
131     GLOBAL $G_tos_vers;
132
133     log_load("index_wr.php");
134     $remote_addr = addrtoipv4($remote_addr_full);
135     $remote_ip = ip2int($remote_addr);
136
137     if (($mesg = gpcs_var('mesg', $get, $post, $cookie)) === FALSE)
138         unset($mesg);
139
140     if (($cl_step = gpcs_var('stp', $get, NULL, NULL)) === FALSE)
141         $cl_step = -2;
142
143     if (($sess = gpcs_var('sess', $get, $post, $cookie)) === FALSE)
144         $sess = "";
145
146
147     if (DEBUGGING == "local" && $remote_addr != '127.0.0.1') {
148         echo "Debugging time!";
149         return (FALSE);
150     }
151
152     /*
153      *  MAIN
154      */
155     $is_spawn = FALSE;
156
157     log_wr(0, 'index_wr.php: COMM: '.xcapemesg($mesg));
158     log_wr('COMM: '.xcapemesg($mesg));
159
160     $curtime = time();
161     $dt = date("H:i ", $curtime);
162
163     if (($user = $brisk->get_user($sess, &$idx)) == FALSE) {
164         $argz = explode('|', xcapemesg($mesg));
165
166         if ($argz[0] == 'getchallenge') {
167             if (isset($get['cli_name']))
168                 $cli_name = $get['cli_name'];
169             if (($a_sem = Challenges::lock_data(TRUE)) != FALSE) {
170                 log_main("chal lock data success");
171
172                 if (($chals = &Challenges::load_data()) != FALSE) {
173
174                     $token =  uniqid("");
175                     // echo '2|'.$argz[1].'|'.$token.'|'.$remote_addr.'|'.$curtime.'|';
176                     // exit;
177
178                     if (($login_new = validate_name(urldecode($cli_name))) != FALSE) {
179                         if ($chals->add($login_new, $token, $remote_addr, $curtime) != FALSE) {
180                             log_send("SUCCESS: token:".$token);
181                             echo '0|'.$token;
182                         }
183                         else {
184                             log_send("getchallenge FAILED");
185                             echo '1|';
186                         }
187                     }
188                     else {
189                         log_send("getchallenge FAILED");
190                         echo '1|';
191                     }
192                     if ($chals->ismod()) {
193                         Challenges::save_data(&$chals);
194                     }
195                 }
196
197
198                 Challenges::unlock_data($a_sem);
199             }
200             else {
201                 echo "CHALLENGE LOCK FAILED\n";
202                 return FALSE;
203             }
204         }
205         else if ($argz[0] == 'auth') {
206             printf("challenge|ok");
207         }
208         else if ($argz[0] == 'help') {
209             /* MLANG: "torna ai tavoli" */
210             echo show_notify(str_replace("\n", " ", $G_room_help[$G_lang]), 0, $mlang_indwr['btn_close'][$G_lang], 600, 500);
211         }
212         else if ($argz[0] == 'about') {
213             echo show_notify(str_replace("\n", " ", $G_room_about[$G_lang]), 0, $mlang_indwr['btn_close'][$G_lang], 400, 230);
214         }
215         else if ($argz[0] == 'passwdhowto') {
216             echo show_notify(str_replace("\n", " ", $G_room_passwdhowto[$G_lang]), 0, $mlang_indwr['btn_close'][$G_lang], 400, 200);
217         }
218         else if ($argz[0] == 'roadmap') {
219             echo show_notify(str_replace("\n", " ", $G_room_roadmap[$G_lang]), 0, $mlang_indwr['btn_close'][$G_lang], 400, 200);
220         }
221         else if ($argz[0] == 'placing') {
222             require_once("briskin5/Obj/briskin5.phh");
223             require_once("briskin5/Obj/placing.phh");
224
225             echo show_notify(str_replace("\n", " ", placings_show(FALSE)), 0, $mlang_indwr['btn_close'][$G_lang], 800, 600);
226         }
227         else if ($argz[0] == 'whysupport') {
228             echo show_notify(str_replace("\n", " ", $G_room_whysupport[$G_lang]), 0, $mlang_indwr['btn_close'][$G_lng], 400, 200);
229         }
230         else if ($argz[0] == 'apprentice') {
231             if (($cli_name = gpcs_var('cli_name', $get, $post, $cookie)) === FALSE)
232                 $cli_name = "";
233
234             if (($cli_email = gpcs_var('cli_email', $get, $post, $cookie)) === FALSE)
235                 $cli_email = "";
236
237             $mesg_to_user = "";
238
239             // check existence of username or email
240             $is_trans = FALSE;
241             do {
242                 if (($bdb = BriskDB::create()) == FALSE) {
243                     $mesg_to_user = "Connessione al database fallita";
244                     break;
245                 }
246
247                 // check IP address as previous requirer
248                 if ($bdb->selfreg_check($remote_ip) == FALSE) {
249                     $mesg_to_user = $mlang_indwr['nu_netguard'][$G_lang];
250                     break;
251                 }
252
253                 $cli_name = urldecode($cli_name);
254                 $cli_email = urldecode($cli_email);
255
256                 // check for already used fields
257                 if (($idret = $bdb->check_record_by_login_or_email($cli_name, $cli_email)) != 0) {
258                     $mesg_to_user = ($idret == 1 ?  $mlang_indwr['nu_loginau'][$G_lang] :
259                                      ($idret == 2 ? $mlang_indwr['nu_emailau'][$G_lang] :
260                                       $mlang_indwr['unknownerr'][$G_lang]));
261                     break;
262                 }
263
264                 $bdb->transaction('BEGIN');
265                 $is_trans = TRUE;
266                 //   insert the new user disabled with reason NU_MAILED
267                 // FIXME: move 'no-guaran' user into configuration file
268                 if (($usr_obj = $bdb->user_add($cli_name, 'THE_PASS', $cli_email,
269                                                USER_FLAG_TY_DISABLE | USER_FLAG_TY_APPR,
270                                                USER_DIS_REA_NU_MAILED, $G_notguar_code)) == FALSE) {
271                     fprintf(STDERR, "ERROR: user_add FAILED\n");
272                     $mesg_to_user = "Fallito inserimento nel database.";
273                     break;
274                 }
275
276                 if (($mail_code = $bdb->mail_reserve_code()) == FALSE) {
277                     fprintf(STDERR, "ERROR: mail reserve code FAILED\n");
278                     $mesg_to_user = "Fallita creazione codice email.";
279                     break;
280                 }
281                 $hash = md5($curtime . $G_alarm_passwd . $cli_name . $cli_email);
282
283                 $confirm_page = sprintf("http://%s/%s/mailmgr.php?f_act=checkmail&f_code=%d&f_hash=%s",
284                                         $G_domain, $G_webbase, $mail_code, $hash);
285                 $subj = $mlang_indwr['nu_msubj'][$G_lang];
286                 $body_txt = sprintf($mlang_indwr['ap_mtext'][$G_lang],
287                                     $cli_name, $confirm_page);
288                 $body_htm = sprintf($mlang_indwr['ap_mhtml'][$G_lang],
289                                     $cli_name, $confirm_page);
290
291                 $mail_item = new MailDBItem($mail_code, $usr_obj->code, MAIL_TYP_CHECK,
292                                             $curtime, $subj, $body_txt, $body_htm, $hash);
293
294                 // save the mail
295                 if ($mail_item->store($bdb) == FALSE) {
296                     // store mail error
297                     fprintf(STDERR, "ERROR: store mail FAILED\n");
298                     $mesg_to_user = "Fallita procedura di store.";
299                     break;
300                 }
301
302                 // check IP address as previous requirer
303                 if ($bdb->selfreg_set($remote_ip) == FALSE) {
304                     $mesg_to_user = $mlang_indwr['nu_unkerr'][$G_lang];
305                     break;
306                 }
307
308                 if (brisk_mail($cli_email, $subj, $body_txt, $body_htm) == FALSE) {
309                     // mail error
310                     fprintf(STDERR, "ERROR: mail send FAILED\n");
311                     $mesg_to_user = "Fallito invio email.";
312                     break;
313                 }
314
315                 $bdb->transaction('COMMIT');
316                 fprintf(STDERR, "REMOTE: %d\n", $remote_ip);
317                 echo "1";
318                 return TRUE;
319             } while(FALSE);
320             if ($is_trans)
321                 $bdb->transaction('ROLLBACK');
322             echo "$mesg_to_user";
323             return FALSE;
324         }
325         else {
326             log_wr("Get User Error");
327             echo "Get User Error:" + $argz[0];
328             return FALSE;
329         }
330         return TRUE;
331     } // end if (($user = $brisk->get_user($sess, ... == FALSE) {
332
333     $brisk->sess_cur_set($user->sess);
334     $argz = explode('|', xcapemesg($mesg));
335
336     log_wr('POSTSPLIT: '.$argz[0]);
337
338     // LACC UPDATED
339     $user->lacc = $curtime;
340     if ($user->cl_step < $cl_step) {
341         log_step(sprintf("%s|%s|%d|%d|%d|%d", $user->sess, $user->name, $user->step, $user->cl_step, $cl_step, $user->step - $user->cl_step));
342         $user->cl_step = $cl_step;
343     }
344
345     if ( ( ! $user->is_auth() ) &&
346         $brisk->ban_check($user->ip)) {
347         // TODO: find a way to add a nonblocking sleep(5) here
348         return (FALSE);
349     }
350
351     if ($argz[0] == 'ping') {
352         log_wr("PING RECEIVED");
353     }
354     else if ($argz[0] == 'prefs') {
355         if ($argz[1] == 'save') {
356             if (!isset($post['prefs'])) {
357                 return FALSE;
358             }
359
360             if (($prefs = Client_prefs::from_json($post['prefs'])) == FALSE) {
361                 $prefs = Client_prefs::from_user($user);
362             }
363             $prefs->store($user, TRUE);
364         }
365         else { // reset case as default
366             $prefs = Client_prefs::from_user($user);
367         }
368         $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
369         $user->comm[$user->step % COMM_N] .=  sprintf('prefs_load(\'%s\', true, %s);', json_encode($prefs),
370                                                       'false');
371         $user->step_inc();
372
373         if ($argz[1] == 'save') {
374             if ($user->stat == 'room' && $user->subst == 'standup') {
375                 $brisk->standup_update($user);
376             }
377             else if ($user->stat == 'room' && $user->subst == 'sitdown') {
378                 log_main("chatt_send pre table update");
379                 $brisk->table_update($user);
380                 log_main("chatt_send post table update");
381             }
382         }
383         echo "1";
384         return TRUE;
385     }
386     else if ($argz[0] == 'shutdown') {
387         log_auth($user->sess, "Shutdown session.");
388
389         $user->the_end = TRUE;
390
391         log_rd2("AUTO LOGOUT.");
392         if ($user->subst == 'sitdown' || $user->stat == 'table')
393             $brisk->room_wakeup($user);
394         else if ($user->subst == 'standup')
395             $brisk->room_outstandup(&$user);
396         else {
397             log_rd2("SHUTDOWN FROM WHAT ???");
398         }
399     }
400     else if ($argz[0] == 'warranty') {
401         if (($cli_name = gpcs_var('cli_name', $get, $post, $cookie)) === FALSE)
402             $cli_name = "";
403
404         if (($cli_email = gpcs_var('cli_email', $get, $post, $cookie)) === FALSE)
405             $cli_email = "";
406
407         $mesg_to_user = "";
408
409         log_wr("INFO:SKIP:argz == warranty name: [".$cli_name."] CERT: ".$user->is_cert());
410         if ($user->is_cert()) {
411             if (0 == 1) {
412                 if (($wa_lock = Warrant::lock_data(TRUE)) != FALSE) {
413                     if (($fp = @fopen(LEGAL_PATH."/warrant.txt", 'a')) != FALSE) {
414                         /* Unix time | session | nickname | IP | where was | mesg */
415                         fwrite($fp, sprintf("%ld|%s|%s|%s|\n", $curtime, xcapelt($user->name), xcapelt(urldecode($cli_name)), xcapelt(urldecode($cli_email))));
416                         fclose($fp);
417                     }
418                     Warrant::unlock_data($wa_lock);
419                     $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
420                     /* MLANG: "<br>Il nominativo &egrave; stato inoltrato all\'amministratore.<br><br>Nell\'arco di pochi giorni vi verr&agrave;<br><br>notificata l\'avvenuta registrazione." */
421                     $user->comm[$user->step % COMM_N] .=  show_notify($mlang_indwr['warrrepl'][$G_lang], 0, $mlang_indwr['btn_close'][$G_lang], 400, 150);
422                     $user->step_inc();
423                     echo "1";
424                 }
425                 else {
426                     /* MLANG: "<b>E\' occorso un errore durante il salvataggio, riprova o contatta l\'amministratore.</b>" */
427                     $mesg_to_user = nickserv_msg($dt, $mlang_indwr['commerr'][$G_lang]);
428                 }
429             } // 0 == 1
430             else {
431                 // check existence of username or email
432                 $is_trans = FALSE;
433                 do {
434                     if (($bdb = BriskDB::create()) == FALSE)
435                         break;
436
437                     $cli_name = urldecode($cli_name);
438                     $cli_email = urldecode($cli_email);
439
440                     // check for already used fields
441                     if (($idret = $bdb->check_record_by_login_or_email($cli_name, $cli_email)) != 0) {
442                         $mesg_to_user = nickserv_msg($dt, ($idret == 1 ?  $mlang_indwr['nu_loginau'][$G_lang] :
443                                                            ($idret == 2 ? $mlang_indwr['nu_emailau'][$G_lang]
444                                                             : $mlang_indwr['unknownerr'][$G_lang])));
445                         break;
446                     }
447                     $bdb->transaction('BEGIN');
448                     $is_trans = TRUE;
449                     //   insert the new user disabled with reason NU_MAILED
450                     if (($usr_obj = $bdb->user_add($cli_name, 'THE_PASS', $cli_email,
451                                                    USER_FLAG_TY_DISABLE | USER_FLAG_TY_NORM,
452                                                    USER_DIS_REA_NU_MAILED, $user->code)) == FALSE) {
453                         fprintf(STDERR, "ERROR: user_add FAILED\n");
454                         break;
455                     }
456                     if (($mail_code = $bdb->mail_reserve_code()) == FALSE) {
457                         fprintf(STDERR, "ERROR: mail reserve code FAILED\n");
458                         break;
459                     }
460                     $hash = md5($curtime . $G_alarm_passwd . $cli_name . $cli_email);
461
462                     $confirm_page = sprintf("http://%s/%s/mailmgr.php?f_act=checkmail&f_code=%d&f_hash=%s",
463                                             $G_domain, $G_webbase, $mail_code, $hash);
464                     $subj = $mlang_indwr['nu_msubj'][$G_lang];
465                     $body_txt = sprintf($mlang_indwr['nu_mtext'][$G_lang],
466                                         $user->name, $cli_name, $confirm_page);
467                     $body_htm = sprintf($mlang_indwr['nu_mhtml'][$G_lang],
468                                         $user->name, $cli_name, $confirm_page);
469
470                     $mail_item = new MailDBItem($mail_code, $usr_obj->code, MAIL_TYP_CHECK,
471                                                 $curtime, $subj, $body_txt, $body_htm, $hash);
472
473                     if (brisk_mail($cli_email, $subj, $body_txt, $body_htm) == FALSE) {
474                         // mail error
475                         fprintf(STDERR, "ERROR: mail send FAILED\n");
476                         break;
477                     }
478                     // save the mail
479                     if ($mail_item->store($bdb) == FALSE) {
480                         // store mail error
481                         fprintf(STDERR, "ERROR: store mail FAILED\n");
482                         break;
483                     }
484                     $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
485                     /* MLANG: "<br>Il nominativo &egrave; stato inoltrato all\'amministratore.<br><br>Nell\'arco di pochi giorni vi verr&agrave;<br><br>notificata l\'avvenuta registrazione." */
486                     $user->comm[$user->step % COMM_N] .=  show_notify($mlang_indwr['warrrepl'][$G_lang], 0, $mlang_indwr['btn_close'][$G_lang], 400, 150);
487                     $user->step_inc();
488                     echo "1";
489                     $bdb->transaction('COMMIT');
490                 } while(FALSE);
491                 $bdb->transaction('ROLLBACK');
492             }
493
494         }
495         else {
496             /* MLANG: "<b>Per autenticare qualcuno devi a tua volta essere autenticato.</b>" */
497             $mesg_to_user = nickserv_msg($dt, $mlang_indwr['warrmust'][$G_lang]);
498         }
499
500         if ($mesg_to_user != "") {
501             $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
502
503             $user->comm[$user->step % COMM_N] .= $mesg_to_user;
504             $user->step_inc();
505         }
506     }
507     else if ($argz[0] == 'mesgtoadm') {
508         if (($cli_subj = gpcs_var('cli_subj', $get, $post, $cookie)) === FALSE)
509             $cli_subj = "";
510
511         if (($cli_mesg = gpcs_var('cli_mesg', $get, $post, $cookie)) === FALSE)
512             $cli_mesg = "";
513
514         $mesg_to_user = "";
515
516         log_wr("INFO:SKIP:argz == mesgtoadm name: [".$user->name."] AUTH: ".$user->is_auth());
517         if ($user->is_auth()) {
518             if (($wa_lock = Warrant::lock_data(TRUE)) != FALSE) {
519                 if (($bdb = BriskDB::create()) != FALSE) {
520                     $bdb->users_load();
521
522                     if (($ema = $bdb->getmail($user->name)) != FALSE) {
523                         //  mail("nastasi",
524                         mail("brisk@alternativeoutput.it", urldecode($cli_subj), urldecode($cli_mesg), sprintf("From: %s <%s>", $user->name, $ema));
525                     }
526
527                     if (($fp = @fopen(LEGAL_PATH."/messages.txt", 'a')) != FALSE) {
528                         /* Unix time | session | nickname | IP | where was | mesg */
529                         fwrite($fp, sprintf("%ld|%s|%s|%s\n", $curtime, $user->name,
530                                             xcapelt(urldecode($cli_subj)), xcapelt(urldecode($cli_mesg))));
531                         fclose($fp);
532                     }
533                     Warrant::unlock_data($wa_lock);
534                     $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
535                     /* MLANG: "" */
536                     $user->comm[$user->step % COMM_N] .=  show_notify($mlang_indwr['mesgrepl'][$G_lang], 0, $mlang_indwr['btn_close'][$G_lang], 400, 110);
537                     $user->step_inc();
538                     echo "1";
539                 }
540                 else {
541                     /* MLANG: "<b>Il database è temporaneamente irraggiungibile, riprova più tardi o contatta l\'amministratore.</b>" */
542                     $mesg_to_user = nickserv_msg($dt, $mlang_indwr['coerrdb'][$G_lang]);
543                     $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
544                 }
545             }
546             else {
547                 /* MLANG: "<b>E\' occorso un errore durante il salvataggio, riprova o contatta l\'amministratore.</b>" */
548                 $mesg_to_user = nickserv_msg($dt, $mlang_indwr['commerr'][$G_lang]);
549             }
550
551         }
552         else {
553             /* MLANG: "<b>Per autenticare qualcuno devi a tua volta essere autenticato.</b>" */
554             $mesg_to_user = nickserv_msg($dt, $mlang_indwr['mesgmust'][$G_lang]);
555         }
556
557         if ($mesg_to_user != "") {
558             $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
559
560             $user->comm[$user->step % COMM_N] .= $mesg_to_user;
561             $user->step_inc();
562         }
563     }
564
565
566
567     else if ($argz[0] == 'poll') {
568         GLOBAL $G_with_poll, $G_poll_name;
569         if (($cli_choose = gpcs_var('cli_choose', $get, $post, $cookie)) === FALSE)
570             $cli_choose = "";
571
572         if (($cli_poll_name = gpcs_var('cli_poll_name', $get, $post, $cookie)) === FALSE)
573             $cli_poll_name = "";
574
575         $poll_lock = FALSE;
576         $mesg_to_user = "";
577
578         $fp = FALSE;
579         $echont = "0";
580
581   /*
582           DONE - autorizzato ?
583           DONE - ci sono poll attivi ?
584           - verifica che il poll_name del client sia uguale a quello sul server
585           DONE - lock
586           DONE - apro file r+ con fallback in w+
587           DONE - vedo se ha già votato
588           DONE - se si: messaggio di voto già dato
589           se no: accetto il voto e lo segno; messaggio
590           chiudo file
591   */
592
593         $dobreak = FALSE;
594         do {
595             log_wr("INFO:SKIP:argz == poll name: [".$cli_poll_name."] AUTH: ".$user->is_auth());
596             if ( ! $user->is_auth() || $user->is_appr() ) {
597                 // MLANG: <b>Per partecipare al sondaggio devi essere autenticato.</b>
598                 $mesg_to_user = nickserv_msg($dt, $mlang_indwr['pollmust'][$G_lang]);
599                 log_wr("break1");
600                 break;
601             }
602
603             if ($G_with_poll == FALSE && $G_poll_name != FALSE && $G_poll_name != "") {
604                 $mesg_to_user = show_notify($mlang_indwr['pollnone'][$G_lang], 0, $mlang_indwr['btn_close'][$G_lang], 400, 110);
605                 log_wr("break2");
606                 break;
607             }
608
609             if ($cli_choose == "" || !isset($cli_choose)) {
610                 $mesg_to_user = show_notify($mlang_indwr['pollchoo'][$G_lang], 0, $mlang_indwr['btn_close'][$G_lang], 400, 110);
611                 log_wr("break2.5");
612                 break;
613             }
614
615             if (($poll_lock = Poll::lock_data(TRUE)) == FALSE) {
616                 /* MLANG: "<b>E\' occorso un errore durante il salvataggio, riprova o contatta l\'amministratore.</b>" */
617                 $mesg_to_user = nickserv_msg($dt, $mlang_indwr['commerr'][$G_lang]);
618                 log_wr("break3");
619                 break;
620             }
621
622             if (($fp = @fopen(LEGAL_PATH."/".$G_poll_name.".txt", 'r+')) == FALSE)
623                 $fp = @fopen(LEGAL_PATH."/".$G_poll_name.".txt", 'w+');
624
625             if ($fp == FALSE) {
626                 $mesg_to_user = nickserv_msg($dt, $mlang_indwr['commerr'][$G_lang]);
627                 log_wr("break4");
628                 break;
629             }
630
631             log_wr("poll: cp");
632             fseek($fp, 0);
633
634             log_wr("poll: cp2");
635             while (!feof($fp)) {
636                 log_wr("poll: cp3");
637                 $bf = fgets($fp, 4096);
638                 log_wr("poll: cp3.1");
639                 $arli = csplitter($bf, '|');
640                 if (count($arli) == 0)
641                     break;
642                 log_wr("poll: cp3.2");
643                 if (strcasecmp($arli[1], $user->name) == 0) {
644                     $mesg_to_user = show_notify($mlang_indwr['pollagai'][$G_lang], 0, $mlang_indwr['btn_close'][$G_lang], 400, 110);
645                     $dobreak = TRUE;
646                     break;
647                 }
648             }
649             log_wr("poll: cp4");
650
651             if ($dobreak) {
652                 log_wr("break5");
653                 break;
654             }
655
656             /* Unix time | nickname | choose */
657             fwrite($fp, sprintf("%ld|%s|%s\n", $curtime, xcapelt($user->name), xcapelt(urldecode($cli_choose))));
658             fflush($fp);
659             $mesg_to_user =  show_notify($mlang_indwr['pollrec'][$G_lang], 0, $mlang_indwr['btn_close'][$G_lang], 400, 110);
660             $echont = "1";
661             log_wr("poll: cp5");
662         } while (0);
663
664         if ($fp != FALSE)
665             fclose($fp);
666
667         if ($poll_lock != FALSE)
668             Poll::unlock_data($poll_lock);
669
670         if ($mesg_to_user != "") {
671             $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
672
673             $user->comm[$user->step % COMM_N] .= $mesg_to_user;
674             $user->step_inc();
675         }
676
677         echo "$echont";
678     }
679
680     /******************
681      *                *
682      *   STAT: room   *
683      *                *
684      ******************/
685     else if ($user->stat == 'room') {
686         $user->laccwr = time();
687
688         if ($argz[0] == 'help') {
689             $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
690             $user->comm[$user->step % COMM_N] .=  show_notify(str_replace("\n", " ", $G_room_help[$G_lang]), 0, $mlang_indwr['btn_backtotab'][$G_lang], 600, 500);
691
692             log_wr($user->comm[$user->step % COMM_N]);
693             $user->step_inc();
694
695         }
696         else if ($argz[0] == 'passwdhowto') {
697             $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
698             $user->comm[$user->step % COMM_N] .=  show_notify(str_replace("\n", " ", $G_room_passwdhowto[$G_lang]), 0, $mlang_indwr['btn_backtotab'][$G_lang], 600, 500);
699
700             log_wr($user->comm[$user->step % COMM_N]);
701             $user->step_inc();
702
703         }
704         else if ($argz[0] == 'splash') {
705             GLOBAL $G_with_splash, $G_splash_content, $G_splash_interval, $G_splash_idx;
706             GLOBAL $G_splash_w, $G_splash_h, $G_splash_timeout;
707             $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
708
709             $user->comm[$user->step % COMM_N] .=  show_notify_ex(str_replace("\n", " ", $G_splash_content[$G_lang]), 0, $mlang_indwr['btn_backtotab'][$G_lang], $G_splash_w, $G_splash_h, true, 0);
710
711             log_wr($user->comm[$user->step % COMM_N]);
712             $user->step_inc();
713         }
714         else if ($argz[0] == 'about') {
715             $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
716             $user->comm[$user->step % COMM_N] .=  show_notify(str_replace("\n", " ", $G_room_about[$G_lang]), 0, $mlang_indwr['btn_backtotab'][$G_lang], 400, 200);
717
718             log_wr($user->comm[$user->step % COMM_N]);
719             $user->step_inc();
720
721         }
722         else if ($argz[0] == 'placing') {
723             require_once("briskin5/Obj/briskin5.phh");
724             require_once("briskin5/Obj/placing.phh");
725
726             $user->comm[$user->step % COMM_N] =  "gst.st = ".($user->step+1)."; ";
727             $user->comm[$user->step % COMM_N] .= show_notify_ex(str_replace("\n", " ", placings_show($user)), 0, $mlang_indwr['btn_backtotab'][$G_lang], 800, 600, TRUE, 0);
728
729             log_wr($user->comm[$user->step % COMM_N]);
730             $user->step_inc();
731         }
732         else if ($argz[0] == 'roadmap') {
733             $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
734             $user->comm[$user->step % COMM_N] .=  show_notify(str_replace("\n", " ", $G_room_roadmap[$G_lang]), 0, $mlang_indwr['btn_backtotab'][$G_lang], 400, 200);
735
736             log_wr($user->comm[$user->step % COMM_N]);
737             $user->step_inc();
738
739         }
740         else if ($argz[0] == 'whysupport') {
741             $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
742             $user->comm[$user->step % COMM_N] .=  show_notify(str_replace("\n", " ", $G_room_whysupport[$G_lang]), 0, $mlang_indwr['btn_backtotab'][$G_lang], 400, 200);
743
744             log_wr($user->comm[$user->step % COMM_N]);
745             $user->step_inc();
746
747         }
748         else if ($argz[0] == 'chatt') {
749             $brisk->chatt_send(&$user, xcapemesg($mesg));
750         }
751         else if ($argz[0] == 'tosmgr') {
752             // check IF is authnticated user, both terms of service versions matches
753             if ($user->is_auth() && count($argz) == 5) {
754                 $f_type = $argz[1];      $f_code = $argz[2];
755                 $f_tos_curr = $argz[3]; $f_tos_vers = $argz[4];
756
757                 if ("$f_tos_curr" == $user->rec->tos_vers_get()  &&
758                     "$f_tos_vers" == "$G_tos_vers") {
759                     if ("$f_type" == "soft" || "$f_type" == "hard") {
760                         $res = 100;
761                         switch ($f_code) {
762                         case LICMGR_CHO_ACCEPT:
763                             $user->rec->tos_vers_set($G_tos_vers);
764                             $res = $user->tos_store();
765                             break;
766                         case LICMGR_CHO_REFUSE:
767                             $user->flags_set(USER_FLAG_TY_DISABLE, USER_FLAG_TY_ALL);
768                             $user->rec->disa_reas_set(USER_DIS_REA_LICENCE);
769                             $res = $user->state_store();
770
771                             $user->comm[$user->step % COMM_N] = $user->blocking_error(TRUE);
772                             $user->the_end = TRUE;
773                             $user->step_inc();
774                             break;
775                         }
776                     }
777                 }
778             }
779         }
780         /**********************
781          *                    *
782          *   SUBST: standup   *
783          *                    *
784          **********************/
785         else if ($user->subst == 'standup') {
786             if ($argz[0] == 'sitdown') {
787                 log_wr("SITDOWN command");
788
789                 if ($user->the_end == TRUE) {
790                     log_wr("INFO:SKIP:argz == sitdown && ->the_end == TRUE => ignore request.");
791                     return FALSE;
792                 }
793
794                 // Take parameters
795                 $table_idx = (int)$argz[1];
796                 $table = &$brisk->table[$table_idx];
797
798                 $not_allowed_msg = "";
799                 if ($G_shutdown) {
800                         $not_allowed_msg = nickserv_msg($dt, $mlang_indwr['shutmsg'][$G_lang]);
801                 }
802                 else if ($table->wakeup_time > $curtime) {
803                     $not_allowed_msg = nickserv_msg($dt, sprintf($mlang_indwr['tabwait'][$G_lang],
804                                                                  $table->wakeup_time - $curtime));
805                 }
806                 else if ( $table->auth_type == TABLE_AUTH_TY_CERT &&
807                           (!$user->is_cert() || $user->is_appr()) ) {
808                     $not_allowed_msg = nickserv_msg($dt, $mlang_indwr['mustcert'][$G_lang]);
809                 }
810                 else if ( $table->auth_type == TABLE_AUTH_TY_AUTH &&
811                           (!$user->is_auth() || $user->is_appr()) ) {
812                     $not_allowed_msg = nickserv_msg($dt, $mlang_indwr['mustauth'][$G_lang]);
813                 }
814                 else if ($user->flags & USER_FLAG_TY_FIRONLY && $table->player_n > 0) {
815                     $not_allowed_msg = nickserv_msg($dt, $mlang_indwr['mustfirst'][$G_lang]);
816                 }
817                 if ($not_allowed_msg != "") {
818                     $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ".$not_allowed_msg;
819                     $user->step_inc();
820                     return TRUE;
821                 }
822
823                 /* TODO: refact to a function */
824                 // if ($user->bantime > $user->laccwr) {
825                 require_once("Obj/hardban.phh");
826
827                 if (($bantime = Hardbans::check(($user->is_auth() ? $user->name : FALSE),
828                                                 $user->ip, $user->sess)) != -1) {
829                     $user->comm[$user->step % COMM_N] = "gst.st = ".($user->step+1)."; ";
830                     /* MLANG: "<br>Ti sei alzato da un tavolo senza il consenso degli altri giocatori. <br><br>Dovrai aspettare ancora ".secstoword($user->bantime - $user->laccwr)." prima di poterti sedere nuovamente.", "resta in piedi.", "<br>Tu o qualcuno col tuo stesso indirizzo IP si è alzato da un tavolo senza il consenso degli altri giocatori.<br><br>Dovrai aspettare ancora ".secstoword($bantime - $user->laccwr)." prima di poterti sedere nuovamente.<br><br>Se non sei stato tu ad alzarti e possiedi un login con password, autenticandoti con quello, potrai accedere." */
831                     if ($user->is_auth()) {
832                         $user->comm[$user->step % COMM_N] .= show_notify($mlang_indwr['badwake_a'][$G_lang].secstoword($bantime - $user->laccwr).$mlang_indwr['badwake_b'][$G_lang], 2000, $mlang_indwr['btn_stays'][$G_lang], 400, 140);
833                     }
834                     else {
835                         $user->comm[$user->step % COMM_N] .= show_notify($mlang_indwr['badsit_a'][$G_lang].secstoword($bantime - $user->laccwr).$mlang_indwr['badsit_a'][$G_lang], 2000, $mlang_indwr['btn_stays'][$G_lang], 400, 180);
836                     }
837                     $user->step_inc();
838                     return TRUE;
839                 }
840
841                 if ($table->player_n == PLAYERS_N) {
842                     log_wr("WARN:FSM: Sitdown unreachable, table full.");
843                     return FALSE;
844                 }
845
846                 // set new status
847                 $user->subst = "sitdown";
848                 $user->table = $table_idx;
849                 $user->table_pos = $table->user_add($idx);
850
851                 log_wr("MOP before");
852
853                 if ($table->player_n == PLAYERS_N) {
854                     require_once("briskin5/Obj/briskin5.phh");
855                     log_wr("MOP inall");
856
857                     // Start game for this table.
858                     log_wr("Start game!");
859         
860                     //
861                     //  START THE SPAWN HERE!!!!
862                     //
863
864                     // Create new spawned table
865                     // $bin5_sem = Bin5::lock_data(TRUE, $table_idx);
866                     $table_token = uniqid("");
867                     $brisk->table[$table_idx]->table_token = $table_token;
868                     $brisk->table[$table_idx]->table_start = $curtime;
869
870                     $plist = "$table_token|$user->table|$table->player_n";
871                     for ($i = 0 ; $i < $table->player_n ; $i++) {
872                         $plist .= '|'.$brisk->user[$table->player[$i]]->sess;
873                     }
874                     log_legal($curtime, $user->ip, $user, "STAT:CREATE_GAME", $plist);
875
876                     log_wr("pre new Bin5");
877                     if (($bin5 = new Bin5($brisk, $table_idx, $table_token, $get, $post, $cookie)) == FALSE)
878                         log_wr("bri create: FALSE");
879                     else
880                         log_wr("bri create: ".serialize($bin5));
881
882                     log_wr("pre init table");
883                     // init table
884                     $bin5_table = $bin5->table[0];
885                     $bin5_table->init($bin5->user);
886                     $bin5_table->game_init($bin5->user);
887                     //
888                     // Init spawned users.
889                     //
890                     //  MULTIGAME: here init of selected game instead of hardcabled briskin5 init (look subst status)
891                     //
892                     log_wr("game_init after");
893                     for ($i = 0 ; $i < $table->player_n ; $i++) {
894                         $bin5_user_cur = $bin5->user[$i];
895                         $user_cur = $brisk->user[$table->player[$i]];
896
897                         $bin5_user_cur->laccwr = $curtime;
898                         $bin5_user_cur->trans_step = $user_cur->step + 1;
899                         $bin5_user_cur->comm[$bin5_user_cur->step % COMM_N] = "";
900                         $bin5_user_cur->step_inc();
901                         $bin5_user_cur->comm[$bin5_user_cur->step % COMM_N] = show_table(&$bin5,&$bin5_user_cur,$bin5_user_cur->step+1,TRUE,FALSE);
902                         $bin5_user_cur->step_inc();
903
904                         log_wr("TRY PRESAVE: ".$bin5_user_cur->step." TRANS STEP: ".$bin5_user_cur->trans_step);
905
906                         log_wr("Pre if!");
907
908                         //          ARRAY_POP DISABLED
909                         //          // CHECK
910                         while (array_pop($user_cur->comm) != NULL);
911
912                         $user_cur->trans_step = $user_cur->step + 1;
913                         $user_cur->comm[$user_cur->step % COMM_N] = sprintf('gst.st_loc++; gst.st=%d; createCookie("table_idx", %d, 24*365, cookiepath); createCookie("table_token", "%s", 24*365, cookiepath); createCookie("lang", "%s", 24*365, cookiepath); xstm.stop(); window.onunload = null ; window.onbeforeunload = null ; document.location.assign("briskin5/index.php");|', $user_cur->step+1, $table_idx, $table_token, $G_lang);
914                         log_wr("TRANS ATTIVATO");
915
916                         $user_cur->stat_set('table');
917                         $user_cur->subst = 'asta';
918                         $user_cur->laccwr = $curtime;
919                         $user_cur->step_inc();
920                     }
921                     log_wr("presave bri");
922                     $brisk->match_add($table_idx, $bin5);
923                     log_wr("postsave bri");
924                 }
925                 // change room
926                 $brisk->room_sitdown($user, $table_idx);
927
928                 log_wr("MOP finish");
929             }
930             else if ($argz[0] == 'logout') {
931                 $brisk->ghost_sess->push($curtime, $user->sess, GHOST_SESS_REAS_LOUT);
932                 $user->the_end = TRUE;
933
934                 if ($user->subst == 'sitdown') {
935                     log_load("ROOM WAKEUP");
936                     $brisk->room_wakeup($user);
937                 }
938                 else if ($user->subst == 'standup')
939                     $brisk->room_outstandup($user);
940                 else
941                     log_rd2("LOGOUT FROM WHAT ???");
942             }
943         }
944         /**********************
945          *                    *
946          *   SUBST: sitdown   *
947          *                    *
948          **********************/
949         else if ($user->subst == 'sitdown') {
950             if ($user->the_end == TRUE) {
951                 log_wr("INFO:SKIP:argz == sitdown && ->the_end == TRUE => ignore request.");
952                 return FALSE;
953             }
954
955             if ($argz[0] == 'wakeup') {
956                 $brisk->room_wakeup($user);
957             }
958             else if ($argz[0] == 'logout') {
959                 $brisk->ghost_sess->push($curtime, $user->sess, GHOST_SESS_REAS_LOUT);
960                 $user->the_end = TRUE;
961
962                 $brisk->room_wakeup($user);
963             }
964         }
965     }
966
967     return (FALSE);
968 }
969 ?>