profile extra fields, profile deletion

This commit is contained in:
Mike Macgirvin 2010-07-10 16:47:10 -07:00
parent e3b86cc583
commit 79725b28cf
4 changed files with 104 additions and 22 deletions

View File

@ -190,7 +190,9 @@ function notags($string) {
// The PHP built-in tag escape function has traditionally been buggy // The PHP built-in tag escape function has traditionally been buggy
if(! function_exists('escape_tags')) { if(! function_exists('escape_tags')) {
function escape_tags($string) { function escape_tags($string) {
return(str_replace(array("<",">","&"), array('&lt;','&gt;','&amp;'), $string)); return(str_replace(
array('&', '"', "'", '<', '>'),
array('&amp;', '&quot;', '&apos;', '&lt;', '&gt;'), $string));
}} }}
if(! function_exists('login')) { if(! function_exists('login')) {

View File

@ -7,9 +7,6 @@ function profiles_post(&$a) {
$_SESSION['sysmsg'] .= "Unauthorised." . EOL; $_SESSION['sysmsg'] .= "Unauthorised." . EOL;
return; return;
} }
// todo - delete... ensure that all contacts using the to-be-deleted profile are moved to the default.
if(($a->argc > 1) && ($a->argv[1] != "new") && intval($a->argv[1])) { if(($a->argc > 1) && ($a->argv[1] != "new") && intval($a->argv[1])) {
$r = q("SELECT * FROM `profile` WHERE `id` = %d AND `uid` = %d LIMIT 1", $r = q("SELECT * FROM `profile` WHERE `id` = %d AND `uid` = %d LIMIT 1",
intval($a->argv[1]), intval($a->argv[1]),
@ -27,6 +24,20 @@ function profiles_post(&$a) {
return; return;
} }
$year = intval($_POST['year']);
if($year < 1900 || $year > 2100 || $year < 0)
$year = 0;
$month = intval($_POST['month']);
if(($month > 12) || ($month < 0))
$month = 0;
$mtab = array(0,31,29,31,30,31,30,31,31,30,31,30,31);
$day = intval($_POST['day']);
if(($day > $mtab[$month]) || ($day < 0))
$day = 0;
$dob = '0000-00-00';
$dob = sprintf('%04d-%02d-%02d',$year,$month,$day);
$name = notags(trim($_POST['name'])); $name = notags(trim($_POST['name']));
$gender = notags(trim($_POST['gender'])); $gender = notags(trim($_POST['gender']));
$address = notags(trim($_POST['address'])); $address = notags(trim($_POST['address']));
@ -35,8 +46,21 @@ function profiles_post(&$a) {
$postal_code = notags(trim($_POST['postal_code'])); $postal_code = notags(trim($_POST['postal_code']));
$country_name = notags(trim($_POST['country_name'])); $country_name = notags(trim($_POST['country_name']));
$marital = notags(trim(implode(', ',$_POST['marital']))); $marital = notags(trim(implode(', ',$_POST['marital'])));
$sexual = notags(trim($_POST['sexual']));
$homepage = notags(trim($_POST['homepage'])); $homepage = notags(trim($_POST['homepage']));
$about = str_replace(array('<','>','&'),array('&lt;','&gt;','&amp;'),trim($_POST['about'])); $politic = notags(trim($_POST['politic']));
$religion = notags(trim($_POST['religion']));
$about = escape_tags(trim($_POST['about']));
$interest = escape_tags(trim($_POST['interest']));
$contact = escape_tags(trim($_POST['contact']));
$music = escape_tags(trim($_POST['music']));
$book = escape_tags(trim($_POST['book']));
$tv = escape_tags(trim($_POST['tv']));
$film = escape_tags(trim($_POST['film']));
$romance = escape_tags(trim($_POST['romance']));
$work = escape_tags(trim($_POST['work']));
$education = escape_tags(trim($_POST['education']));
if(x($_POST,'profile_in_directory')) if(x($_POST,'profile_in_directory'))
$publish = (($_POST['profile_in_directory'] == 1) ? 1: 0); $publish = (($_POST['profile_in_directory'] == 1) ? 1: 0);
if(! in_array($gender,array('','Male','Female','Other'))) if(! in_array($gender,array('','Male','Female','Other')))
@ -46,26 +70,52 @@ function profiles_post(&$a) {
SET `profile-name` = '%s', SET `profile-name` = '%s',
`name` = '%s', `name` = '%s',
`gender` = '%s', `gender` = '%s',
`dob` = '%s',
`address` = '%s', `address` = '%s',
`locality` = '%s', `locality` = '%s',
`region` = '%s', `region` = '%s',
`postal-code` = '%s', `postal-code` = '%s',
`country-name` = '%s', `country-name` = '%s',
`marital` = '%s', `marital` = '%s',
`sexual` = '%s',
`homepage` = '%s', `homepage` = '%s',
`about` = '%s' `politic` = '%s',
`religion` = '%s',
`about` = '%s',
`interest` = '%s',
`contact` = '%s',
`music` = '%s',
`book` = '%s',
`tv` = '%s',
`film` = '%s',
`romance` = '%s',
`work` = '%s',
`education` = '%s'
WHERE `id` = %d AND `uid` = %d LIMIT 1", WHERE `id` = %d AND `uid` = %d LIMIT 1",
dbesc($profile_name), dbesc($profile_name),
dbesc($name), dbesc($name),
dbesc($gender), dbesc($gender),
dbesc($dob),
dbesc($address), dbesc($address),
dbesc($locality), dbesc($locality),
dbesc($region), dbesc($region),
dbesc($postal_code), dbesc($postal_code),
dbesc($country_name), dbesc($country_name),
dbesc($marital), dbesc($marital),
dbesc($sexual),
dbesc($homepage), dbesc($homepage),
dbesc($politic),
dbesc($religion),
dbesc($about), dbesc($about),
dbesc($interest),
dbesc($contact),
dbesc($music),
dbesc($book),
dbesc($tv),
dbesc($film),
dbesc($romance),
dbesc($work),
dbesc($education),
intval($a->argv[1]), intval($a->argv[1]),
intval($_SESSION['uid']) intval($_SESSION['uid'])
); );
@ -101,6 +151,38 @@ function profiles_content(&$a) {
return; return;
} }
if(($a->argc > 2) && ($a->argv[1] == "drop") && intval($a->argv[2])) {
$r = q("SELECT * FROM `profile` WHERE `id` = %d AND `uid` = %d AND `is-default` = 0 LIMIT 1",
intval($a->argv[2]),
intval($_SESSION['uid'])
);
if(! count($r)) {
$_SESSION['sysmsg'] .= "Profile not found." . EOL;
goaway($a->get_baseurl() . '/profiles');
return; // NOTREACHED
}
// move every contact using this profile as their default to the user default
$r = q("UPDATE `contact` SET `profile-id` = (SELECT `profile`.`id` AS `profile-id` FROM `profile` WHERE `profile`.`is-default` = 1 AND `profile`.`uid` = %d LIMIT 1) WHERE `profile-id` = %d AND `uid` = %d ",
intval($_SESSION['uid']),
intval($a->argv[2]),
intval($_SESSION['uid'])
);
$r = q("DELETE FROM `profile` WHERE `id` = %d LIMIT 1",
intval($a->argv[2])
);
if($r)
notice("Profile deleted." . EOL);
goaway($a->get_baseurl() . '/profiles');
return; // NOTREACHED
}
if(($a->argc > 1) && ($a->argv[1] == 'new')) { if(($a->argc > 1) && ($a->argv[1] == 'new')) {
$r0 = q("SELECT `id` FROM `profile` WHERE `uid` = %d", $r0 = q("SELECT `id` FROM `profile` WHERE `uid` = %d",
@ -219,7 +301,7 @@ function profiles_content(&$a) {
'$region' => $r[0]['region'], '$region' => $r[0]['region'],
'$postal_code' => $r[0]['postal-code'], '$postal_code' => $r[0]['postal-code'],
'$country_name' => $r[0]['country-name'], '$country_name' => $r[0]['country-name'],
'$age' => $r[0]['age'], '$age' => ((intval($r[0]['dob'])) ? '(Age: '. age($r[0]['dob'],$a->user['timezone'],$a->user['timezone']) . ')' : ''),
'$gender' => gender_selector($r[0]['gender']), '$gender' => gender_selector($r[0]['gender']),
'$marital' => marital_selector($r[0]['marital']), '$marital' => marital_selector($r[0]['marital']),
'$sexual' => sexpref_selector($r[0]['sexual']), '$sexual' => sexpref_selector($r[0]['sexual']),

View File

@ -26,9 +26,9 @@ $gender
<div id="profile-edit-gender-end"></div> <div id="profile-edit-gender-end"></div>
<div id="profile-edit-dob-wrapper" > <div id="profile-edit-dob-wrapper" >
<label id="profile-edit-dob-label" for="dob-select" >Birthday: </label> <label id="profile-edit-dob-label" for="dob-select" >Birthday (y/m/d): </label>
<div id="profile-edit-dob" > <div id="profile-edit-dob" >
$dob $dob $age
</div> </div>
<div id="profile-edit-dob-end"></div> <div id="profile-edit-dob-end"></div>
@ -126,7 +126,7 @@ $profile_in_dir
<div id="about-jot-wrapper" > <div id="about-jot-wrapper" >
<p id="about-jot-desc" > <p id="about-jot-desc" >
Tell us about yourself. Tell us about yourself...
</p> </p>
<textarea rows="10" cols="72" id="profile-jot-text" name="about" >$about</textarea> <textarea rows="10" cols="72" id="profile-jot-text" name="about" >$about</textarea>
@ -138,7 +138,7 @@ Tell us about yourself.
<div id="interest-jot-wrapper" > <div id="interest-jot-wrapper" >
<p id="interest-jot-desc" > <p id="interest-jot-desc" >
Hobbies/Interests. Hobbies/Interests
</p> </p>
<textarea rows="10" cols="72" id="interest-jot-text" name="interest" >$interest</textarea> <textarea rows="10" cols="72" id="interest-jot-text" name="interest" >$interest</textarea>
@ -150,7 +150,7 @@ Hobbies/Interests.
<div id="contact-jot-wrapper" > <div id="contact-jot-wrapper" >
<p id="contact-jot-desc" > <p id="contact-jot-desc" >
Contact information. Contact information and Social Networks
</p> </p>
<textarea rows="10" cols="72" id="contact-jot-text" name="contact" >$contact</textarea> <textarea rows="10" cols="72" id="contact-jot-text" name="contact" >$contact</textarea>
@ -168,7 +168,7 @@ Contact information.
<div id="music-jot-wrapper" > <div id="music-jot-wrapper" >
<p id="music-jot-desc" > <p id="music-jot-desc" >
Musical interests. Musical interests
</p> </p>
<textarea rows="10" cols="72" id="music-jot-text" name="music" >$music</textarea> <textarea rows="10" cols="72" id="music-jot-text" name="music" >$music</textarea>
@ -179,7 +179,7 @@ Musical interests.
<div id="book-jot-wrapper" > <div id="book-jot-wrapper" >
<p id="book-jot-desc" > <p id="book-jot-desc" >
Books, literature. Books, literature
</p> </p>
<textarea rows="10" cols="72" id="book-jot-text" name="book" >$book</textarea> <textarea rows="10" cols="72" id="book-jot-text" name="book" >$book</textarea>
@ -192,7 +192,7 @@ Books, literature.
<div id="tv-jot-wrapper" > <div id="tv-jot-wrapper" >
<p id="tv-jot-desc" > <p id="tv-jot-desc" >
Television. Television
</p> </p>
<textarea rows="10" cols="72" id="tv-jot-text" name="tv" >$tv</textarea> <textarea rows="10" cols="72" id="tv-jot-text" name="tv" >$tv</textarea>
@ -205,7 +205,7 @@ Television.
<div id="film-jot-wrapper" > <div id="film-jot-wrapper" >
<p id="film-jot-desc" > <p id="film-jot-desc" >
Film/dance/culture/entertainment. Film/dance/culture/entertainment
</p> </p>
<textarea rows="10" cols="72" id="film-jot-text" name="film" >$film</textarea> <textarea rows="10" cols="72" id="film-jot-text" name="film" >$film</textarea>
@ -223,7 +223,7 @@ Film/dance/culture/entertainment.
<div id="romance-jot-wrapper" > <div id="romance-jot-wrapper" >
<p id="romance-jot-desc" > <p id="romance-jot-desc" >
Love/romance. Love/romance
</p> </p>
<textarea rows="10" cols="72" id="romance-jot-text" name="romance" >$romance</textarea> <textarea rows="10" cols="72" id="romance-jot-text" name="romance" >$romance</textarea>
@ -236,7 +236,7 @@ Love/romance.
<div id="work-jot-wrapper" > <div id="work-jot-wrapper" >
<p id="work-jot-desc" > <p id="work-jot-desc" >
Work/employment. Work/employment
</p> </p>
<textarea rows="10" cols="72" id="work-jot-text" name="work" >$work</textarea> <textarea rows="10" cols="72" id="work-jot-text" name="work" >$work</textarea>
@ -249,7 +249,7 @@ Work/employment.
<div id="education-jot-wrapper" > <div id="education-jot-wrapper" >
<p id="education-jot-desc" > <p id="education-jot-desc" >
School/education. School/education
</p> </p>
<textarea rows="10" cols="72" id="education-jot-text" name="education" >$education</textarea> <textarea rows="10" cols="72" id="education-jot-text" name="education" >$education</textarea>

View File

@ -17,7 +17,7 @@ contact editor
reputation reputation
profile advanced details submit, display profile advanced details display
publish to external directory publish to external directory
@ -44,8 +44,6 @@ local/remote indicator
side/text side/text
interests/music/tv/etc.
country state select
notififier abstraction notififier abstraction