5 * Copyright (C) 2014 Matteo Nastasi
6 * mailto: nastasi@alternativeoutput.it
7 * matteo.nastasi@milug.org
8 * web: http://www.alternativeoutput.it
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License as published by
12 * the Free Software Foundation; either version 2 of the License, or
13 * (at your option) any later version.
15 * This program is distributed in the hope that it will be useful, but
16 * WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABLILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
18 * General Public License for more details. You should have received a
19 * copy of the GNU General Public License along with this program; if
20 * not, write to the Free Software Foundation, Inc, 59 Temple Place -
21 * Suite 330, Boston, MA 02111-1307, USA.
25 foreach (array("HTTP_HOST", "DOCUMENT_ROOT") as $i) {
26 if (isset($_SERVER[$i])) {
31 foreach (array("pazz") as $i) {
32 if (isset($_POST[$i])) {
37 foreach (array("sess") as $i) {
38 if (isset($_COOKIE[$i])) {
43 foreach (array("sess") as $i) {
44 if (isset($_COOKIE[$i])) {
51 $mlang_umgmt = array( 'nu_psubj' => array( 'it' => 'Brisk: credenziali di accesso.',
52 'en' => 'Brisk: credentials.'),
53 'nu_ptext' => array( 'it' =>
54 'Ciao, sono l\' amministratore del sito di Brisk.
56 La verifica del tuo indirizzo di posta elettronica e del tuo nickname è andata a buon fine, per accedere al sito
57 d\'ora in poi potrai utilizzare l\' utente \'%s\' e la password \'%s\'.
59 Benvenuto e buone partite, mop.',
60 'en' => 'EN ptext [%s] [%s]'),
61 'nu_phtml' => array( 'it' => 'Ciao, sono l\' amministratore del sito di Brisk.<br><br>
62 La verifica del tuo indirizzo di posta elettronica e del tuo nickname è andata a buon fine.<br><br>Per accedere al sito d\'ora in poi potrai usare l\' utente \'%s\' e la password \'%s\'.<br><br>
63 Benvenuto e buone partite, mop.<br>',
64 'en' => 'EN phtml [%s] [%s]')
68 ini_set("max_execution_time", "240");
70 require_once($G_base."Obj/brisk.phh");
71 require_once($G_base."Obj/user.phh");
72 require_once($G_base."Obj/auth.phh");
73 require_once($G_base."Obj/mail.phh");
74 require_once($G_base."Obj/dbase_base.phh");
75 require_once($G_base."Obj/dbase_${G_dbasetype}.phh");
76 require_once($G_base."briskin5/Obj/briskin5.phh");
77 require_once($G_base."briskin5/Obj/placing.phh");
78 require_once($G_base."spush/brisk-spush.phh");
79 require_once($G_base."index_wr.php");
83 GLOBAL $G_alarm_passwd, $sess, $_POST, $_SERVER;
87 $ip = $_SERVER["REMOTE_ADDR"];
89 $private = md5($G_alarm_passwd.$ip.$sess);
90 $cmd = array ("cmd" => "userauth", "sess" => $sess, "private" => $private, "the_end" => "true");
91 $cmd_ser = cmd_serialize($cmd);
92 $cmd_len = mb_strlen($cmd_ser, "ASCII");
95 if (($socket = stream_socket_client("unix://".USOCK_PATH."2")) == FALSE)
98 if (($rwr = fwrite($socket, $cmd_ser, $cmd_len)) == FALSE
103 if (($buf = fread($socket, 4096)) == FALSE)
105 $res = cmd_deserialize($buf);
107 if (!isset($res['val']) || $res['val'] != 200)
112 if ($socket != FALSE)
116 echo "STP: $stp<br>";
124 border-collapse: collapse;
129 border: 1px solid black;
135 GLOBAL $s_style, $G_dbpfx, $G_lang, $G_alarm_passwd, $G_proto, $G_domain, $G_webbase;
136 GLOBAL $mlang_umgmt, $mlang_indwr, $f_mailusers, $sess, $_POST, $_SERVER;
142 if (check_auth() == FALSE) {
143 echo "Authentication failed";
148 if (isset($_GET['f_nocheck'])) {
152 if (isset($_GET['do']) && $_GET['do'] == 'newuser') {
153 if (isset($_POST['f_accept'])) {
156 else if (isset($_POST['f_delete'])) {
163 if ($action == "accept") {
164 foreach($_POST as $key => $value) {
165 if (substr($key, 0, 9) != "f_newuser")
168 $id = (int)substr($key, 9);
172 // check existence of username or email
176 if (($bdb = BriskDB::create()) == FALSE)
179 // retrieve list added users
181 SELECT usr.*, guar.login AS guar_login
183 JOIN %susers AS guar ON guar.code = usr.guar_code
184 WHERE usr.type & (CAST (X'%x' as integer)) = (CAST (X'%x' as integer))
185 AND usr.disa_reas = %d AND usr.code = %d;",
187 USER_FLAG_TY_DISABLE, USER_FLAG_TY_DISABLE,
188 USER_DIS_REA_NU_ADDED, $id);
189 if (($usr_pg = pg_query($bdb->dbconn->db(), $usr_sql)) == FALSE) {
190 log_crit("stat-day: select from tournaments failed");
193 $usr_n = pg_numrows($usr_pg);
195 $status .= sprintf("Inconsistency for code %d, returned %d records, skipped.<br>",
200 $usr_obj = pg_fetch_object($usr_pg, 0);
202 $bdb->transaction('BEGIN');
206 if (($bdb->user_update_flag_ty($usr_obj->code, USER_FLAG_TY_DISABLE,
207 TRUE, USER_DIS_REA_NU_ADDED,
208 TRUE, USER_DIS_REA_NU_MAILED)) == FALSE) {
213 if (($mail_code = $bdb->mail_reserve_code()) == FALSE) {
214 fprintf(STDERR, "ERROR: mail reserve code FAILED\n");
217 $hash = md5($curtime . $G_alarm_passwd . $usr_obj->login . $usr_obj->email);
219 $confirm_page = sprintf("%s://%s/%s/mailmgr.php?f_act=checkmail&f_code=%d&f_hash=%s",
220 $G_proto, $G_domain, $G_webbase, $mail_code, $hash);
221 $subj = $mlang_indwr['nu_msubj'][$G_lang];
222 if (($usr_obj->type & USER_FLAG_TY_APPR) == USER_FLAG_TY_APPR) {
223 $body_txt = sprintf($mlang_indwr['ap_mtext'][$G_lang],
224 $cli_name, $confirm_page);
225 $body_htm = sprintf($mlang_indwr['ap_mhtml'][$G_lang],
226 $cli_name, $confirm_page);
229 $body_txt = sprintf($mlang_indwr['nu_mtext'][$G_lang],
230 $usr_obj->guar_login, $usr_obj->login, $confirm_page);
231 $body_htm = sprintf($mlang_indwr['nu_mhtml'][$G_lang],
232 $usr_obj->guar_login, $usr_obj->login, $confirm_page);
235 $mail_item = new MailDBItem($mail_code, $usr_obj->code, MAIL_TYP_CHECK,
236 $curtime, $subj, $body_txt, $body_htm, $hash);
238 if (brisk_mail($usr_obj->email, $subj, $body_txt, $body_htm) == FALSE) {
240 fprintf(STDERR, "ERROR: mail send FAILED\n");
244 if ($mail_item->store($bdb) == FALSE) {
246 fprintf(STDERR, "ERROR: store mail FAILED\n");
249 $status .= sprintf("status change for %s: SUCCESS<br>", $usr_obj->login);
250 $bdb->transaction('COMMIT');
254 $status .= sprintf("Error occurred during accept action<br>");
256 $bdb->transaction('ROLLBACK');
260 } // else if ($action == "accept") {
264 if (($bdb = BriskDB::create()) == FALSE) {
265 log_crit("stat-day: database connection failed");
269 // retrieve list added users
271 SELECT usr.*, guar.login AS guar_login
273 JOIN %susers AS guar ON guar.code = usr.guar_code
274 WHERE usr.type & (CAST (X'%x' as integer)) = (CAST (X'%x' as integer))
275 AND usr.disa_reas = %d ORDER BY usr.lintm;",
277 USER_FLAG_TY_DISABLE, USER_FLAG_TY_DISABLE,
278 USER_DIS_REA_NU_ADDED);
279 if (($usr_pg = pg_query($bdb->dbconn->db(), $usr_sql)) == FALSE) {
280 log_crit("stat-day: select from tournaments failed");
283 $usr_n = pg_numrows($usr_pg);
284 $tab_lines = "<tr><th></th><th>User</th><th>Guar</th><th>Date</th></tr>";
285 for ($i = 0 ; $i < $usr_n ; $i++) {
286 $usr_obj = pg_fetch_object($usr_pg, $i);
288 $tab_lines .= sprintf("<tr><td><input name=\"f_newuser%d\" type=\"checkbox\" %s></td><td>%s</td><td>%s</td><td>%s</td></tr>\n",
289 $usr_obj->code, ($nocheck ? "" : "CHECKED"),
290 eschtml($usr_obj->login), eschtml($usr_obj->guar_login), $usr_obj->lintm);
297 <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
298 <title>Brisk: new imported users management.</title>
299 <?php echo "$s_style"; ?>
302 <h2> New imported users management.</h2>
303 <?php if ($status != "") { echo "$status"; } ?>
304 <form action="<?php echo $_SERVER['REQUEST_URI']; ?>" method="POST">
305 <table class="the_tab">
310 <input type="submit" name="f_accept" value="Newuser Accept">
311 <input type="submit" name="f_delete" value="Newuser Delete">
318 printf("Some error occurred during newuser visualization\n");
322 if (isset($_GET['do']) && $_GET['do'] == 'mailed') {
323 if (isset($_POST['f_resend'])) {
326 else if (isset($_POST['f_delete'])) {
333 if ($action == "resend") {
334 foreach($_POST as $key => $value) {
335 if (substr($key, 0, 9) != "f_newuser")
338 $id = (int)substr($key, 9);
344 if (($bdb = BriskDB::create()) == FALSE) {
348 // retrieve list added users
350 SELECT mail.*, usr.email AS email
352 JOIN %smails AS mail ON mail.ucode = usr.code
353 WHERE mail.ucode = %d AND mail.type = %d",
354 $G_dbpfx, $G_dbpfx, $id, MAIL_TYP_CHECK);
355 if (($mai_pg = pg_query($bdb->dbconn->db(), $mai_sql)) == FALSE) {
356 log_crit("retrieve mail failed");
360 $mai_n = pg_numrows($mai_pg);
362 $status .= sprintf("Inconsistency for code %d, returned %d records, skipped.<br>",
366 $mai_obj = pg_fetch_object($mai_pg, 0);
367 $mail = MailDBItem::MailDBItemFromRecord($mai_obj);
369 if (brisk_mail($mai_obj->email, $mail->subj, $mail->body_txt, $mail->body_htm) == FALSE) {
371 $status .= sprintf("Send mail filed for user id %d<br>\n", $id);
377 $status .= sprintf("Error occurred during resend action<br>");
384 if (($bdb = BriskDB::create()) == FALSE) {
385 log_crit("stat-day: database connection failed");
389 // retrieve list added users
391 SELECT usr.*, guar.login AS guar_login
393 JOIN %susers AS guar ON guar.code = usr.guar_code
394 WHERE usr.type & (CAST (X'%x' as integer)) = (CAST (X'%x' as integer))
395 AND usr.disa_reas = %d ORDER BY usr.lintm;",
397 USER_FLAG_TY_DISABLE, USER_FLAG_TY_DISABLE,
398 USER_DIS_REA_NU_MAILED);
399 if (($usr_pg = pg_query($bdb->dbconn->db(), $usr_sql)) == FALSE) {
400 log_crit("stat-day: select from tournaments failed");
403 $usr_n = pg_numrows($usr_pg);
404 $tab_lines = "<tr><th></th><th>User</th><th>Guar</th><th>Date</th></tr>";
405 for ($i = 0 ; $i < $usr_n ; $i++) {
406 $usr_obj = pg_fetch_object($usr_pg, $i);
408 $tab_lines .= sprintf("<tr><td><input name=\"f_newuser%d\" type=\"checkbox\" %s></td><td>%s</td><td>%s</td><td>%s</td></tr>\n",
409 $usr_obj->code, ($nocheck ? "" : "CHECKED"),
410 eschtml($usr_obj->login), eschtml($usr_obj->guar_login), $usr_obj->lintm);
415 <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
416 <title>Brisk: new mailed users management.</title>
417 <?php echo "$s_style"; ?>
420 <h2> New mailed users management.</h2>
421 <?php if ($status != "") { echo "$status"; } ?>
422 <form action="<?php echo $_SERVER['REQUEST_URI']; ?>" method="POST">
423 <table class="the_tab">
428 <input type="submit" name="f_resend" value="Mailed Resend">
429 <input type="submit" name="f_delete" value="Mailed Delete">
436 printf("Some error occurred during newuser visualization\n");
439 else { // if ($_GET['do'] ...
440 if (isset($_POST['f_accept'])) {
443 else if (isset($_POST['f_delete'])) {
450 if ($action == "accept") {
451 if (($bdb = BriskDB::create()) == FALSE) {
452 log_crit("stat-day: database connection failed");
456 foreach($_POST as $key => $value) {
457 if (substr($key, 0, 9) != "f_newuser")
460 $id = (int)substr($key, 9);
465 // retrieve list of active tournaments
467 SELECT usr.*, guar.login AS guar_login
469 JOIN %susers AS guar ON guar.code = usr.guar_code
470 WHERE usr.type & (CAST (X'%x' as integer)) = (CAST (X'%x' as integer))
471 AND usr.disa_reas = %d AND usr.code = %d;",
473 USER_FLAG_TY_DISABLE, USER_FLAG_TY_DISABLE,
474 USER_DIS_REA_NU_TOBECHK, $id);
475 if (($usr_pg = pg_query($bdb->dbconn->db(), $usr_sql)) == FALSE) {
476 log_crit("stat-day: select from tournaments failed");
479 $usr_obj = pg_fetch_object($usr_pg, 0);
481 printf("KEY: %s: %s %s<br>\n", $id, $value, $usr_obj->login);
483 $passwd = passwd_gen();
485 if (($bdb->user_update_passwd($usr_obj->code, $passwd)) == FALSE) {
490 if (($bdb->user_update_flag_ty($usr_obj->code, USER_FLAG_TY_DISABLE,
491 TRUE, USER_DIS_REA_NU_TOBECHK,
492 FALSE, USER_DIS_REA_NONE)) == FALSE) {
497 $bdb->user_update_login_time($usr_obj->code, 0);
500 $subj = $mlang_umgmt['nu_psubj'][$G_lang];
501 $body_txt = sprintf($mlang_umgmt['nu_ptext'][$G_lang],
502 $usr_obj->login, $passwd);
503 $body_htm = sprintf($mlang_umgmt['nu_phtml'][$G_lang],
504 $usr_obj->login, $passwd);
506 log_step(sprintf("[%s], [%s], [%s], [%s]\n", $usr_obj->email, $subj, $body_txt, $body_htm));
509 if (brisk_mail($usr_obj->email, $subj, $body_txt, $body_htm) == FALSE) {
511 fprintf(STDERR, "ERROR: mail send FAILED\n");
519 else if ($action == "delete") {
520 foreach($_POST as $key => $value) {
521 if (substr($key, 0, 9) != "f_newuser")
524 $id = (int)substr($key, 9);
528 // check existence of username or email
532 if (($bdb = BriskDB::create()) == FALSE)
535 // retrieve list added users
537 SELECT usr.*, guar.login AS guar_login
539 JOIN %susers AS guar ON guar.code = usr.guar_code
540 WHERE usr.type & (CAST (X'%x' as integer)) = (CAST (X'%x' as integer))
541 AND usr.disa_reas = %d AND usr.code = %d;",
543 USER_FLAG_TY_DISABLE, USER_FLAG_TY_DISABLE,
544 USER_DIS_REA_NU_TOBECHK, $id);
547 if (($usr_pg = pg_query($bdb->dbconn->db(), $usr_sql)) == FALSE) {
548 log_crit("stat-day: select from tournaments failed");
551 $usr_n = pg_numrows($usr_pg);
553 $status .= sprintf("Inconsistency for code %d, returned %d records, skipped.<br>",
558 $usr_obj = pg_fetch_object($usr_pg, 0);
560 $bdb->transaction('BEGIN');
563 $del_sql = sprintf("DELETE FROM %susers WHERE code = %d;",
564 $G_dbpfx, $usr_obj->code);
566 if (($del_pg = pg_query($bdb->dbconn->db(), $del_sql)) == FALSE) {
567 log_crit("stat-day: select from tournaments failed");
571 // FIXME: add to index_wr.php strings
572 $subj = "Brisk: nickname rifiutato";
573 // the same for both cases:
574 // if (($usr_obj->type & USER_FLAG_TY_APPR) == USER_FLAG_TY_APPR) {
575 $body_txt = sprintf('Ciao, sono l\' amministratore del sito di Brisk.
577 Ti volevo segnalare che il nickname \'%s\' con cui ti volevi registrare
578 non ha superato la fase di verifica manuale; il motivo può essere
579 la sua illeggibilità per gli altri utenti o il contenuto poco ortodosso
580 o troppo aggressivo o ci sono troppe cifre consecutive o qualcosa del genere.
582 La procedura di registrazione va ripetuta.
584 Saluti e buone partite, mop.', $usr_obj->login);
586 $body_htm = sprintf('Ciao, sono l\' amministratore del sito di Brisk.<br><br>
587 Ti volevo segnalare che il nickname \'%s\' con cui ti volevi registrare
588 non ha superato la fase di verifica manuale; il motivo può essere
589 la sua illeggibilità per gli altri utenti o il contenuto poco ortodosso
590 o troppo aggressivo o ci sono troppe cifre consecutive o qualcosa del genere.<br><br>
591 La procedura di registrazione va ripetuta.<br><br>
592 Saluti e buone partite, mop.', $usr_obj->login);
595 /* $body_txt = sprintf($mlang_indwr['nu_mtext'][$G_lang], */
596 /* $usr_obj->guar_login, $usr_obj->login, $confirm_page); */
597 /* $body_htm = sprintf($mlang_indwr['nu_mhtml'][$G_lang], */
598 /* $usr_obj->guar_login, $usr_obj->login, $confirm_page); */
601 if (brisk_mail($usr_obj->email, $subj, $body_txt, $body_htm) == FALSE) {
603 fprintf(STDERR, "ERROR: mail send FAILED\n");
606 $status .= sprintf("user delete for %s: SUCCESS<br>", $usr_obj->login);
607 $bdb->transaction('COMMIT');
611 $status .= sprintf("Error occurred during accept action<br>");
613 $bdb->transaction('ROLLBACK');
616 printf("Registration %s for login %s deleted<br>\n", $usr_obj->code, $usr_obj->login);
621 if (($bdb = BriskDB::create()) == FALSE) {
622 log_crit("stat-day: database connection failed");
626 // retrieve list of active tournaments
628 SELECT usr.*, guar.login AS guar_login
630 JOIN %susers AS guar ON guar.code = usr.guar_code
631 WHERE usr.type & (CAST (X'%x' as integer)) = (CAST (X'%x' as integer))
632 AND usr.disa_reas = %d ORDER BY usr.lintm;",
634 USER_FLAG_TY_DISABLE, USER_FLAG_TY_DISABLE,
635 USER_DIS_REA_NU_TOBECHK);
636 if (($usr_pg = pg_query($bdb->dbconn->db(), $usr_sql)) == FALSE) {
637 log_crit("stat-day: select from tournaments failed");
641 $usr_n = pg_numrows($usr_pg);
642 $tab_lines = "<tr><th></th><th>User</th><th>EMail</th><th>Guar</th><th>Apprendice</th><th>Date</th></tr>";
643 for ($i = 0 ; $i < $usr_n ; $i++) {
644 $usr_obj = pg_fetch_object($usr_pg, $i);
646 $tab_lines .= sprintf("<tr><td><input name=\"f_newuser%d\" type=\"checkbox\" %s></td><td>%s</td><td>%s</td><td>%s</td><td>%s</td><td>%s</td></tr>\n",
647 $usr_obj->code, ($nocheck ? "" : "CHECKED"),
648 eschtml($usr_obj->login), eschtml($usr_obj->email), eschtml($usr_obj->guar_login),
649 ($usr_obj->type & USER_FLAG_TY_APPR ? "Yes" : "No"),
655 <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
656 <title>Brisk: email verified user management.</title>
657 <?php echo "$s_style"; ?>
660 <h2> E-mail verified user management.</h2>
661 <?php if ($status != "") { echo "$status"; } ?>
662 <form action="<?php echo $_SERVER['REQUEST_URI']; ?>" method="POST">
663 <table class="the_tab">
668 <input type="submit" name="f_accept" value="Accept">
669 <input type="submit" name="f_delete" value="Delete">
675 } // else of if ($action ...
676 } // else of if ($do ...