. if (!defined('EG')) die('Direct access not allowed!'); class UsersModel extends Model_Map { public static $usersList = array(); public function __construct() { $this->_tables='regusers,reggroups,regusers_groups'; $this->_idFields='id_user,id_group'; $this->_where=array( 'id_group' => 'reggroups', 'id_user' => 'regusers', 'name' => 'reggroups', 'confirmation_token'=> 'regusers', 'has_confirmed' => 'regusers', 'deleted' => 'regusers', 'forgot_token' => 'regusers' ); $this->_popupItemNames = array( 'has_confirmed'=>'has_confirmed', 'deleted'=>'deleted', 'id_group'=>'name', ); $this->_popupLabels = array( 'has_confirmed'=>'HAS CONFIRMED?', 'deleted'=>'DELETED?', 'id_group'=>'GROUP' ); $this->orderBy = 'regusers.id_user desc'; parent::__construct(); $this->deleteNotRegistered(); } public function pUpdate($id) { return parent::update($id); } public function deleteNotRegistered() { $limit = time() - Account::$confirmTime; $this->db->del('regusers','has_confirmed = 1 and deleted = "no" and creation_time < '.$limit); } public function getUser($id_user = 0) { $clean['id_user'] = (int)$id_user; if (array_key_exists($clean['id_user'],self::$usersList)) { return self::$usersList[$clean['id_user']]; } else { $user = $this->db->select('regusers','username,has_confirmed','id_user='.$clean['id_user']); if (count($user) > 0) { $fuser = (strcmp($user[0]['regusers']['has_confirmed'],0) === 0) ? $user[0]['regusers']['username'] : "__".$user[0]['regusers']['username']; self::$usersList[$clean['id_user']] = $fuser; return $fuser; } else { return "__anonymous__"; } } } public function getLinkToUser($user) { if (strstr($user,'__')) { return $user; // return str_replace('__',null,$user); } else { return "$user"; } } public function getLinkToUserFromId($id_user = 0) { $clean['id_user'] = (int)$id_user; return $this->getLinkToUser($this->getUser($clean['id_user'])); } //check if the user exists public function userExists($user) { $clean['user'] = ctype_alnum($user) ? sanitizeAll($user) : ''; if (strcmp($clean['user'],'') !== 0) { $res = $this->where(array("username"=>$clean['user'],"has_confirmed"=>"0","deleted"=>"no"))->send(); // $res = $this->db->select('regusers','has_confirmed','username="'.$clean['user'].'" and has_confirmed=0 and deleted="no"'); if (count($res) > 0) { return true; } } return false; } //get the user id from the username public function getUserId($username = '') { $clean['username'] = ctype_alnum($username) ? sanitizeAll($username) : ''; $users = $this->select('id_user')->where(array('username'=>$clean['username'],'has_confirmed'=>0,'deleted'=>'no'))->send(); if (count($users) > 0) { return $users[0]['regusers']['id_user']; } else { return 0; } } public function isBlocked($idUser) { $clean['id_user'] = (int)$idUser; $res = $this->select('blocked')->where(array('id_user'=>$clean['id_user'],'has_confirmed'=>0,'deleted'=>'no'))->toList('blocked')->send(); if (count($res) > 0) { return strcmp($res[0],'yes') === 0 ? true : false; } return true; } public function insert() { //create the token $confirmation_token = md5(randString(20)); $this->values['confirmation_token'] = $confirmation_token; //has_confirmed flag $this->values['has_confirmed'] = 1; $this->values['creation_time'] = time(); //random ID $randomId = md5(randString(5).uniqid(mt_rand(),true)); $this->values["temp_field"] = $randomId; if (isset($_POST['captcha'])) { if ( strcmp($_SESSION['captchaString'],$_POST['captcha']) === 0 ) { parent::insert(); if ($this->queryResult) { $resId = $this->db->select("regusers","id_user","temp_field='$randomId'"); $clean['id_user'] = $resId[0]['regusers']['id_user']; $this->db->update("regusers",'temp_field',array(''),'id_user='.$clean['id_user']); $result = Account::confirm($this->values['username'],$this->values['e_mail'],$clean['id_user'],$confirmation_token); if ($result) { $_SESSION['status'] = 'sent'; } else { $_SESSION['status'] = 'regerror'; } $hed = new HeaderObj(DOMAIN_NAME); $hed->redirect('users/notice/'.Lang::$current); } } else { $this->result = false; $this->queryResult = false; $this->notice = "