Файл: mail.php
Строк: 480
<?
session_start();
$title="Внутрення почтаn";
$font='<font color="#ffd022">';
$fend='</font>';
include ("header.php");
include ("func/aut.php");
echo $div["im"];
echo "<img src="/logo.gif" alt=""/><br/>";
echo $div["end"];
echo $div["okcent"];
echo $div["gif"];
$data=date("YmdHi");
$data4=date("Ymd");
$ref=rand(100000,1000000);
if (empty($mod)) $mod="index";
switch ($mod) {
///////////////////////////////////////////////////////////////////////////////
case "index":
$qi = mysql_query("select * from `letters` where ((`read`='0')and(`komu`='$login')and(`inout`='in'));");
$i=mysql_num_rows($qi);
$qip = mysql_query("select * from `letters` where ((`komu`='$login')and(`inout`='in'));");
$is=mysql_num_rows($qip);
if ($autorize['id'] == '1'){
echo $div["ten"];
echo "<b><a href="mail.php?mod=sub&".session_name()."=".session_id()."">Заспамить нах всех!Ггг</a></b><br/>";
echo $div["end"];
}
$qir = mysql_query("select * from `letters` where ((`komu`='$login')and(`inout`='out'));");
$ir=mysql_num_rows($qir);
echo $div["ten"];
echo "<a href="mail.php?mod=input&".session_name()."=".session_id()."">Входящие</a> (".($font)."$is".($fend).") [".($font)."$i".($fend)."]<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=output&".session_name()."=".session_id()."">Исходящие</a> (".($font)."$ir".($fend).")<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=sent&".session_name()."=".session_id()."">Написать</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=delall&".session_name()."=".session_id()."">Удалить все сообщения</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">В панель</a><br/>";
echo $div["end"];
break;
///////////////////////////////////////////////////////////////////////////////
case "sub":
if (empty($message)){
if ($_SESSION['wap']=="xml"){
echo $div["ten"];
echo "<form action="mail.php?mod=sub&".session_name()."=".session_id()."" method="post">";
echo "Сообщение: <br/>";
echo "<input class="ibutton" name="message" maxlength="1500" value="$msg_db" title="Text"/><br/>";
echo "<input class="ibutton" type="submit" value="Отправить"/>";
echo "</form>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?op=default&".session_name()."=".session_id()."">Внутреняя почта</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">В панель</a><br/>";
echo $div["end"];
}
}else{
$mess = htmlspecialchars($message);
$mess = stripslashes($mess);
$xfile = mysql_query("select * from `uzvers`;");
$datamsg=date("d.m.Y H:i");
while ($udata = @mysql_fetch_array ($xfile)){
$radd = mysql_query("insert into letters set who='Admin',komu='".$udata['log']."',msg='".$mess."', data='".$datamsg."', inout='in';") or die ('Error!');}
echo $div["ten"];
echo "Рассылка успешно завершена!<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?op=default&".session_name()."=".session_id()."">Внутреняя почта</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">В панель</a><br/>";
echo $div["end"];
}
include ("footergl.php");
exit();
break;
///////////////////////////////////////////////////////////////////////////////
case "input":
$page=@$_GET['page'];
if (!isset($page) || $page=='' || $page<1 ) {
$page=1;}
$max_lines_on_page=$autorize['letmsg'];
$maxpages=5;
$t=2;
$limit=($page-1)* $max_lines_on_page;
$q=mysql_query("select * from `letters` where ((`komu`='$login')and(`inout`='in'));");
$all=mysql_num_rows($q);
$query = mysql_query("select * from `letters` where ((`komu`='$login')and(`inout`='in')) order by `id` DESC;");
if ($_SESSION['wap']!="xml") {print "-<br/>";}
if (mysql_affected_rows()==0)
{
echo $div["ten"];
echo "Сообщений нет!<br/>";
echo $div["end"];
}
else
{
while ($field=mysql_fetch_array($query))
{
$id=$field['id'];
$who=$field['who'];
$data_msg=$field['data'];
$read=$field['read'];
echo $div["ten"];
echo "От: <a href="mail.php?mod=read&msgid=$id&".session_name()."=".session_id()."">$who</a><br/>Дата: ".($font)."$data_msg".($fend)."";
if ($read==0){ echo "".($font)."New".($fend).""; }
echo $div["end"];
}}
function PRINT_NUM_PAGE(){ ##функция навигации
//global $page,$all, $max_lines_on_page, $max_pages_on_page, $maxpages, $t, $p;
//$maxpage=ceil($all/$max_lines_on_page);
if ($maxpage>0&&$maxpage!=1){
if ($page>1)
echo " <a href="".$PHP_SELF."?mod=input&page=".($page-1)."&".session_name()."=".session_id()."">«-</a>";
else
echo "«-";
echo " | </small><input name="page" maxlength="3" value="1" size="3"/><small>";
echo " <a href="".$PHP_SELF."?mod=input&page=$(page)&".session_name()."=".session_id()."">»</a> | ";
if ($page<$maxpage)
echo " <a href="".$PHP_SELF."?mod=input&page=".($page+1)."&".session_name()."=".session_id()."">-»</a> <br/>";
else
echo " -» <br/>";
if ($page>4) {echo "<a href="".$PHP_SELF."?mod=input&page=1">1</a> ... "; }
if ($t=='2'){
$l=$page - floor($maxpages/2);
$r=$page + floor($maxpages/2);
if ($l<1){$l='1'; $r=$maxpages;}
if ($r>$maxpage){$r=$r+$r/2;}
if (($page-1)>$maxpages-3/2){ $ll=$l+1;
echo "<a href="".$PHP_SELF."?mod=input&page=$ll&".session_name()."=".session_id()."">«</a> ";
}
}else{
$l = ceil($page/$maxpages)*$maxpages+1- $maxpages;
$r = ceil($page/$maxpages)*$maxpages;
}
$l=$l;
for ($l; $l<=$r; $l++){
if ($l>$maxpage)break;
if ($l == $page){
echo " <b>$page</b> ";
}else{
echo " <a href="".$PHP_SELF."?mod=input&page=$l&".session_name()."=".session_id()."">$l</a> ";}
}
if ($maxpage>$r) { $ll=$r+1;
echo " <a href="".$PHP_SELF."?mod=input&page=$ll&".session_name()."=".session_id()."">»</a> ";}
if ($page<$maxpage-2) {
echo "... <a href="".$PHP_SELF."?mod=input&page=$maxpage&".session_name()."=".session_id()."">$maxpage</a><br/> ";}
}
}
echo $div["ten"];
echo "<a href="mail.php?mod=index&".session_name()."=".session_id()."">Внутреняя почта</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">Панель</a><br/>";
echo $div["end"];
PRINT_NUM_PAGE();
break;
///////////////////////////////////////////////////////////////////////////////
case "output":
$page=@$_GET['page'];
if (!isset($page) || $page=='' || $page<1 ) {
$page=1;}
$max_lines_on_page=$autorize['letmsg'];
$maxpages=5;
$t=2;
$limit=($page-1)* $max_lines_on_page;
$q= mysql_query("select * from `letters` where ((`komu`='$login')and(`inout`='out'));");
$all=mysql_num_rows($q);
$query = mysql_query("select * from `letters` where ((`komu`='$login')and(`inout`='out')) order by `id`;");
if ($_SESSION['wap']!="xml") {print "-<br/>";}
if (mysql_affected_rows()==0)
{
echo $div["ten"];
echo "Сообщений нет!<br/>";
echo $div["end"];
}
else
{
while ($field=mysql_fetch_array($query))
{
$id=$field['id'];
$who=$field['who'];
$data_msg=$field['data'];
$read=$field['read'];
echo $div["ten"];
echo "От: ".($font)."$who".($fend)." [<a href="mail.php?mod=readout&msgid=$id&".session_name()."=".session_id()."">Читать</a>]<br/>
Дата: ".($font)."$data_msg".($fend)."<br/>";
echo $div["end"];
}}
function PRINT_NUM_PAGE(){##функция навигации
//global $page,$all, $max_lines_on_page, $max_pages_on_page, $maxpages, $t, $p;
//$maxpage=ceil($all/$max_lines_on_page);
if ($maxpage>0&&$maxpage!=1){
if ($page>1) echo "<a href="".$PHP_SELF."?mod=output&?page=".($page-1)."&".session_name()."=".session_id()."">«-</a>";
else echo "«-";
echo " | </small><input name="page" maxlength="3" value="1" size="3"/><small>";
echo "<a href="".$PHP_SELF."?mod=output&page=$(page)&".session_name()."=".session_id()."">»</a> | ";
if ($page<$maxpage) print " <a href="".$PHP_SELF."?mod=output&page=".($page+1)."&".session_name()."=".session_id()."">-»</a> <br/>";
else print " -» <br/>";
if ($page>4) {echo "<a href="".$PHP_SELF."?mod=output&page=1">1</a> ... "; }
if ($t=='2'){
$l=$page - floor($maxpages/2);
$r=$page + floor($maxpages/2);
if ($l<1){$l='1'; $r=$maxpages;}
if ($r>$maxpage){$r=$r+$r/2;}
if (($page-1)>$maxpages-3/2){ $ll=$l+1;
echo "<a href="".$PHP_SELF."?mod=output&page=$ll&".session_name()."=".session_id()."">«</a> ";
}
}else{
$l = ceil($page/$maxpages)*$maxpages+1- $maxpages;
$r = ceil($page/$maxpages)*$maxpages;
}
$l=$l;
for ($l; $l<=$r; $l++){
if ($l>$maxpage)break;
if ($l == $page){
print " <b>$page</b> ";
}else{
echo " <a href="".$PHP_SELF."?mod=output&page=$l&".session_name()."=".session_id()."">$l</a> ";}
}
if ($maxpage>$r) { $ll=$r+1;
echo "<a href="".$PHP_SELF."?mod=output&page=$ll&".session_name()."=".session_id()."">»</a> ";}
if ($page<$maxpage-2) {
echo "... <a href="".$PHP_SELF."?mod=output&page=$maxpage&".session_name()."=".session_id()."">$maxpage</a> ";}
print "<br/>";
}
}
echo $div["ten"];
echo "<a href="mail.php?mod=index&".session_name()."=".session_id()."">Внутреняя почта</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">Панель</a><br/>";
echo $div["end"];
PRINT_NUM_PAGE();
break;
///////////////////////////////////////////////////////////////////////////////
case "read":
$q_msg = mysql_query("select * from `letters` where ((`komu`='$login')and(`id`='$msgid')and(`inout`='in'));");
echo $div["ten"];
if (mysql_affected_rows()==0)
{
echo "Нет такого сообщения!<br/>";
}
else
{
$row_msg=mysql_fetch_array($q_msg);
$who=$row_msg['who'];
$db_data=$row_msg['data'];
$msg=$row_msg['msg'];
echo "Сообщение от:".($font)." $who ".($fend)."<br/>";
echo "Дата:".($font)." $db_data ".($fend)."<br/>";
echo "Текст:".($font)." $msg ".($fend)."<br/>";
@mysql_query("UPDATE `letters` SET `read`='1' WHERE `id`='$msgid';");
}
echo "[<a href="mail.php?mod=sent&user=$who&".session_name()."=".session_id()."">Ответить</a>] ";
echo "[<a href="mail.php?mod=delin&delid=$msgid&".session_name()."=".session_id()."">Удалить</a>]<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=input&".session_name()."=".session_id()."">Входящие</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">Панель</a><br/>";
echo $div["end"];
break;
///////////////////////////////////////////////////////////////////////////////
case "readout":
$q_msa = mysql_query("select * from `letters` where ((`komu`='$login')and(`id`='$msgid')and(`inout`='out'));");
echo $div["ten"];
if (mysql_affected_rows()==0)
{
echo "Нет такого сообщения!<br/>";
}
else
{
$row_msg=mysql_fetch_array($q_msa);
$who=$row_msg['who'];
$db_data=$row_msg['data'];
$msg=$row_msg['msg'];
echo "Сообщение от:".($font)." $who ".($fend)."<br/>";
echo "Дата:".($font)." $db_data ".($fend)."<br/>";
echo "Сообщение:".($font)." $msg ".($fend)."<br/>";
@mysql_query("UPDATE `letters` SET `read`='1' WHERE `id`='$msgid';");
}
echo "[<a href="mail.php?mod=sent&user=$who&".session_name()."=".session_id()."">Ответить</a>] ";
echo "[<a href="mail.php?mod=delout&delid=$msgid&".session_name()."=".session_id()."">Удалить</a>]<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=output&".session_name()."=".session_id()."">Отправленные</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">Панель</a><br/>";
echo $div["end"];
break;
///////////////////////////////////////////////////////////////////////////////
case "sent":
$uname = $_GET['uname'];
if (empty($go)){
if ($_SESSION['wap']=="xml")
{
$_SESSION['pswd']=rand(10000,99999);
echo $div["ten"];
echo "<form action="mail.php?mod=sent&go=add&".session_name()."=".session_id()."" method="post">";
echo "Кому (введите Логин) <br/><input class="ibutton" name="komu" value="$user" title="Text"/><br/>";
echo "Сообщение: <br/><input class="ibutton" name="msg" title="Text"/><br/>";
echo "Введите число: <img src="pic.php?".session_name()."=".session_id()."" alt="..."/><br/>";
echo "<input class="ibutton" name="psw" maxlength="5"/><br/>";
echo "<input class="ibutton" type="submit" value="Отправить"/>";
echo "</form>";
echo $div["end"];
}
else
{
print "Кому: <br/>";
print "</small><input name="komu".$ref."" maxlength="20" value="$user" title="Text"/><br/><small>";
print "Сообщение: <br/>";
print "</small><input name="msg".$ref."" maxlength="200" title="Text"/><br/><small>";
print "<anchor title="send">Отправить<go href="mail.php?mod=sent&go=add&".session_name()."=".session_id()."" method="post">";
print "<postfield name="komu" value="$(komu".$ref.")"/>";
print "<postfield name="msg" value="$(msg".$ref.")"/>";
print "</go></anchor><br/>";
}
echo $div["ten"];
echo "<a href="mail.php?mod=index&".session_name()."=".session_id()."">Сообщения</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">Панель</a><br/>";
echo $div["end"];
}
else
{
$q = mysql_query("select * from `uzvers` where `log`='$komu';");
if (mysql_affected_rows()==0)
{
echo $div["ten"];
echo "Нет такого пользователя!<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=index&".session_name()."=".session_id()."">Сообщения</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">Панель</a><br/>";
echo $div["end"];
}
elseif ($_SESSION['pswd']!=$psw) {
echo $div["ten"];
echo 'Число на картинке и ваше не совпадают!';
echo $div["end"];
$_SESSION['pswd']=rand(10000,99999); }
else
{
if (!empty($msg))
{
$datamsg=date("d.m.Y H:i");
$k=$autorize['log'];
@mysql_query("insert into `letters` values(0,'$k','$komu','$msg','$datamsg','0','in');")or die ("FUCK");
@mysql_query("insert into `letters` values(0,'$komu','$k','$msg','$datamsg','0','out');")or die ("FUCK");
echo $div["ten"];
echo "Сообщение отправленно!<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=index&".session_name()."=".session_id()."">Сообщения</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">Панель</a><br/>";
echo $div["end"];
}
else
{
echo $div["ten"];
echo "Сообщение не может быть пустым!<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=index&".session_name()."=".session_id()."">Сообщения</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">Панель</a><br/>";
echo $div["end"];
}
}}
break;
////////////////////////////////////////////////////////////////////////////////
case "delall":
mysql_query("delete from `letters` where ((`komu`='$login')and(`inout`='in'))");
mysql_query("delete from `letters` where ((`who`='$login')and(`inout`='out'))");
echo $div["ten"];
echo "Сообщения удалены!<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=index&".session_name()."=".session_id()."">Сообщения</a><br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="enter.php?".session_name()."=".session_id()."">Панель</a><br/>";
echo $div["end"];
break;
case "delin":
mysql_query("delete from `letters` where ((`komu`='$login')and(`inout`='in')and(`id`='$delid'))");
echo $div["ten"];
echo "Сообщение удалено!<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=input&".session_name()."=".session_id()."">Входящие</a><br/>";
echo $div["end"];
break;
case "delout":
mysql_query("delete from `letters` where ((`who`='$login')and(`inout`='out')and(`id`='$delid'))");
echo $div["ten"];
echo "Сообщение удалено!<br/>";
echo $div["end"];
echo $div["ten"];
echo "<a href="mail.php?mod=output&".session_name()."=".session_id()."">Исходящие</a><br/>";
echo $div["end"];
break;
////////////////////////////////////////////////////////////////////////////////
}
if ($_SESSION['wap']!="xml") {print "-<br/>";}
include ("footergl.php");
?>