news.php3 8.11 KB
Newer Older
Chad Barb's avatar
 
Chad Barb committed
1 2 3
<?php
#
# EMULAB-COPYRIGHT
4
# Copyright (c) 2000-2004 University of Utah and the Flux Group.
Chad Barb's avatar
 
Chad Barb committed
5 6 7 8 9
# All rights reserved.
#
include("defs.php3");

#
10
# Standard Testbed Header is sent below.
Chad Barb's avatar
 
Chad Barb committed
11 12 13 14 15 16
#
#
# If user is an admin, present edit options.
#
$uid = GETLOGIN();

17 18 19 20 21
if (! isset($show_archived)) {
    $show_archived = 0;
}
$show_archived = ($show_archived ? 1 : 0);

Chad Barb's avatar
 
Chad Barb committed
22 23 24 25 26 27 28
if ($uid) {
    $isadmin = ISADMIN($uid);
} else {
    $isadmin = 0;
}

if ($isadmin) {
29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57
    if (isset($deletec)) {
	$safeid = addslashes($deletec);

	DBQueryFatal("DELETE FROM webnews WHERE msgid='$safeid'");

	header("Location: news.php3?show_archived=$show_archived");
	return;
    }
    if (isset($archive)) {
	$safeid = addslashes($archive);

	DBQueryFatal("update webnews set archived=1,archived_date=now() ".
		     "where msgid='$safeid'");

	header("Location: news.php3?show_archived=$show_archived");
	return;
    }
    if (isset($restore)) {
	$safeid = addslashes($restore);

	DBQueryFatal("update webnews set archived=0,archived_date=NULL ".
		     "where msgid='$safeid'");

	header("Location: news.php3?show_archived=$show_archived");
	return;
    }

    PAGEHEADER("News");
    
Chad Barb's avatar
 
Chad Barb committed
58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147
    if (isset($delete)) {
	$delete = addslashes($delete);
	echo "<center>";
	echo "<h2>Are you sure you want to delete message #$delete?</h2>";
	echo "<form action='news.php3' method='post'>\n";
	echo "<button name='deletec' value='$delete'>Yes</button>\n";
	echo "&nbsp;&nbsp;";
	echo "<button name='nothin'>No</button>\n";
	echo "</form>";
	echo "</center>";
	PAGEFOOTER();
	die("");
    }

    if (isset($add)) {
	if (!isset($subject) || !strcmp($subject,"") ) {
	    # USERERROR("No subject!",1);
	    $subject = "Testbed News";
	} 
	if (!isset($author) || !strcmp($author,"") ) {
	    # USERERROR("No author!",1);
	    $author = "testbed-ops";
	} 

	if (isset($bodyfile) && 
	    strcmp($bodyfile,"") &&
	    strcmp($bodyfile,"none")) {
	    $bodyfile = addslashes($bodyfile);
	    $handle = @fopen($bodyfile,"r");
	    if ($handle) {
		$body = fread($handle, filesize($bodyfile));
		fclose($handle);
	    } else {
		USERERROR("Couldn't open uploaded file!",1);
	    }
	}

	if (!isset($body) || !strcmp($body,"")) {
	    USERERROR("No message body!",1);
	} 

	$subject = addslashes($subject);
	$author  = addslashes($author);
	$body = addslashes($body);

	if (isset($msgid)) {
	    $msgid = addslashes($msgid);
	    if (!isset($date) || !strcmp($date,"") ) {
		USERERROR("No date!",1);
	    }
	    $date = addslashes($date);
	    DBQueryFatal("UPDATE webnews SET ".
			 "subject='$subject', ".
			 "author='$author', ".
			 "date='$date', ".
			 "body='$body' ".			
			 "WHERE msgid='$msgid'");
	    echo "<h2>Updated message with subject '$subject'.</h2><br />";
	} else {	    
	    DBQueryFatal("INSERT INTO webnews (subject, date, author, body) ".
			 "VALUES ('$subject', NOW(), '$author', '$body')");
	    echo "<h2>Posted message with subject '$subject'.</h2><br />";
	}

	echo "<h3><a href='news.php3'>Back to news</a></h3>";
	PAGEFOOTER();
	die("");
    }

    if (isset($edit)) {
	$edit = addslashes($edit);
	$query_result = 
	    DBQueryFatal("SELECT subject, author, body, msgid, date ".
			 "FROM webnews ".
		         "WHERE msgid='$edit'" );

	if (!mysql_num_rows($query_result)) {
	    USERERROR("No message with msgid '$edit'!",1);
	} 

	$row = mysql_fetch_array($query_result);
	$subject = htmlspecialchars($row[subject], ENT_QUOTES);
	$date    = htmlspecialchars($row[date],    ENT_QUOTES);
	$author  = htmlspecialchars($row[author],  ENT_QUOTES);
	$body    = htmlspecialchars($row[body],    ENT_QUOTES);
	$msgid   = htmlspecialchars($row[msgid],   ENT_QUOTES);
    }

    if (isset($edit) || isset($addnew)) {	
	if (isset($addnew)) {
Chad Barb's avatar
 
Chad Barb committed
148
	    $author = $uid;
Chad Barb's avatar
 
Chad Barb committed
149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174
	    echo "<h3>Add new message:</h3>\n";
	} else {
	    echo "<h3>Edit message:</h3>\n";
	}

	echo "<form action='news.php3' ".
             "enctype='multipart/form-data' ".
             "method='post'>\n";

	if (isset($msgid)) {
	    echo "<input type='hidden' name='msgid' value='$msgid' />";
	}
	
#	if (isset($date)) {
#	    echo "<input type='hidden' name='date' value='$date' />";
#	}
	
	echo "<b>Subject:</b><br />".
	     "<input type='text' name='subject' size='50' value='$subject'>".
	     "</input><br /><br />\n";
	if (isset($date)) {
	    echo "<b>Date:</b><br />".
	         "<input type='text' name='date' size='50' value='$date'>".
		 "</input><br /><br />\n";
	}
	echo "<b>Posted by:</b><br />". 
Chad Barb's avatar
 
Chad Barb committed
175
	     "<input type='text' name='author' size='50' value='$author'>".
Chad Barb's avatar
 
Chad Barb committed
176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205
	     "</input><br /><br />\n". 
	     "<b>Body (HTML):</b><br />".
       	     "<textarea cols='60' rows='25' name='body'>";

	if (isset($addnew)) {
	    echo "&lt;p&gt;\n&lt;!-- ".
		 "place message between 'p' elements ".
		 "--&gt;\n\n&lt;/p&gt;";
	} else {
	    echo $body;
	}
	echo "</textarea><br /><br />";
	echo "<b>or Upload Body File:</b><br />";
	echo "<input type='file' name='bodyfile' size='50'>";
	echo "</input>";
	echo "<br /><br />\n";
	if (isset($addnew)) {
	    echo "<button name='add'>Add</button>\n";
	} else {
	    echo "<button name='add'>Edit</button>\n";
	}
	echo "&nbsp;&nbsp;<button name='nothin'>Cancel</button>\n";
	echo "</form>";
	PAGEFOOTER();
	die("");
    } else {
	echo "<form action='news.php3' method='post'>\n";
	echo "<button name='addnew'>Add a new message</button>\n";
	echo "</form>";
    }
206 207 208
}
else {
    PAGEHEADER("News");
Chad Barb's avatar
 
Chad Barb committed
209 210 211 212 213 214
}

?>
<table align=center class=stealth border=0>
<tr><td class=stealth align=center><h1>News</h1></td></tr>
<tr><td class=stealth align=center>
215
    <a href = 'doc/docwrapper.php3?docname=ChangeLog.txt'>
Chad Barb's avatar
 
Chad Barb committed
216 217 218 219 220
    (Changelog/Technical Details)</a></td></tr>
</table>
<br />
<?php

221 222 223 224 225 226 227 228 229 230 231 232
# Allow admin caller to flip the archive bit. 
$show_archive_clause = "where archived=0";
if ($isadmin) {
    if ($show_archived) {
	$show_archive_clause = "";
	echo "<a href='news.php3?show_archived=0'>Hide Archived Messages</a>\n";
    }
    else {
	echo "<a href='news.php3?show_archived=1'>Show Archived Messages</a>\n";
    }
}

Chad Barb's avatar
 
Chad Barb committed
233 234 235
$query_result=
    DBQueryFatal("SELECT subject, author, body, msgid, ".
		 "DATE_FORMAT(date,'%W, %M %e, %Y, %l:%i%p') as prettydate, ".
236 237 238 239
		 "(TO_DAYS(NOW()) - TO_DAYS(date)) as age, ".
		 "archived, ".
		 "DATE_FORMAT(archived_date,'%W, %M %e, %Y, %l:%i%p') as ".
		 "  archived_date ".
Chad Barb's avatar
 
Chad Barb committed
240
		 "FROM webnews ".
241
		 "$show_archive_clause ".
Chad Barb's avatar
 
Chad Barb committed
242 243 244 245 246 247 248 249
		 "ORDER BY date DESC" );

if (!mysql_num_rows($query_result)) {
    echo "<h4>No messages.</h4>";
} else {

    if ($isadmin) {
	echo "<form action='news.php3' method='post'>";
250
	echo "<input type='hidden' name=show_archived value='$show_archived'>";
Chad Barb's avatar
 
Chad Barb committed
251 252 253 254 255 256 257 258 259
    }

    while ($row = mysql_fetch_array($query_result)) {
	$subject = $row[subject];
	$date    = $row[prettydate];
	$author  = $row[author];
	$body    = $row[body];
	$msgid   = $row[msgid];
	$age     = $row[age];
260 261
	$archived = $row[archived];
	$archived_date = $row[archived_date];
Chad Barb's avatar
 
Chad Barb committed
262

263
	echo "<a name=\"$msgid\" />\n";
Chad Barb's avatar
 
Chad Barb committed
264 265 266 267 268 269 270 271 272 273 274 275 276 277
	echo "<table class='nogrid' 
                     cellpadding=0 
                     cellspacing=0 
                     border=0 width='100%'>";

	echo "<tr><th style='padding: 4px;'><font size=+1>$subject</font>";

	if ($age < 7) {
	    echo "&nbsp;<img border=0 src='new.gif' />";
	}

	echo "</th></tr>\n".
	     "<tr><td style='padding: 4px; padding-top: 2px;'><font size=-1>";
	echo "<b>$date</b>; posted by <b>$author</b>.";
278 279 280
	if ($archived) {
	    echo "<font color=red> Archived on <b>$archived_date</b></font>.\n";
	}
Chad Barb's avatar
 
Chad Barb committed
281 282 283 284 285

	if ($isadmin) {
	    echo " (Message <b>#$msgid</b>)";
	}

Chad Barb's avatar
 
Chad Barb committed
286
	echo "</font></td></tr>";
Chad Barb's avatar
 
Chad Barb committed
287 288 289 290 291 292

	if ($isadmin) {
	    echo "<tr><td>";
	    echo "<button name='edit' value='$msgid'>".
		 "Edit</button>".
	         "<button name='delete' value='$msgid'>".
293 294 295 296 297 298 299 300
		 "Delete</button>";
	    if ($archived)
		echo "<button name='restore' value='$msgid'>".
		     "Restore</button>";
	    else
		echo "<button name='archive' value='$msgid'>".
		     "Archive</button>";
	    echo "</td></tr>\n";
Chad Barb's avatar
 
Chad Barb committed
301
	}
Chad Barb's avatar
 
Chad Barb committed
302 303 304 305 306 307 308 309 310 311 312

	echo "<tr><td style='padding: 4px; padding-top: 2px;'>".
	     "<div style='background-color: #FFFFF2; ".
	     "border: 1px solid #AAAAAA; ".
      	     "padding: 6px'>".
	     $body.
	     "</div>".
	     "</td></tr>\n";

	echo "<!-- ' \" > IF YOU CAN READ THIS, YOU FORGOT AN ENDQUOTE -->\n";

Chad Barb's avatar
 
Chad Barb committed
313 314 315 316 317 318 319 320 321 322 323
	echo "</table><br />";
    } 

    if ($isadmin) { 
	echo "</form>\n"; 
    }
}		  

PAGEFOOTER();
?>