]> git.wh0rd.org - tt-rss.git/blame - backend.php
remove unneeded escaping in label/add
[tt-rss.git] / backend.php
CommitLineData
1cd17194 1<?
4356293a 2 session_start();
090e250b 3
262bd8ea
AD
4 $op = $_REQUEST["op"];
5
6 if (($op == "rpc" || $op == "updateAllFeeds" ||
7 $op == "forceUpdateAllFeeds") && !$_REQUEST["noxml"]) {
8 header("Content-Type: application/xml");
9 }
10
11 if (!$_SESSION["uid"]) {
12
13 if (($op == "rpc" || $op == "updateAllFeeds" ||
14 $op == "forceUpdateAllFeeds")) {
15 print "<error error-code=\"6\"/>";
16 }
17 exit;
18 }
1c7f75ed 19
4356293a 20 define(SCHEMA_VERSION, 2);
1cd17194 21
82baad4a 22 require_once "config.php";
648472a7 23 require_once "db.php";
3bac89ad 24 require_once "db-prefs.php";
82baad4a
AD
25 require_once "functions.php";
26 require_once "magpierss/rss_fetch.inc";
1cd17194 27
406d9489
AD
28 $script_started = getmicrotime();
29
648472a7 30 $link = db_connect(DB_HOST, DB_USER, DB_PASS, DB_NAME);
d76a3b03 31
5136011e
AD
32 if (!$link) {
33 if (DB_TYPE == "mysql") {
34 print mysql_error();
35 }
36 // PG seems to display its own errors just fine by default.
37 return;
38 }
39
648472a7
AD
40 if (DB_TYPE == "pgsql") {
41 pg_query("set client_encoding = 'utf-8'");
42 }
7ec2a838 43
295f9b42 44/*
7ec2a838
AD
45 $result = db_query($link, "SELECT schema_version FROM ttrss_version");
46
47 $schema_version = db_fetch_result($result, 0, "schema_version");
48
49 if ($schema_version != SCHEMA_VERSION) {
50 print "Error: database schema is invalid
51 (got version $schema_version; expected ".SCHEMA_VERSION.")";
52 return;
53 }
295f9b42
AD
54*/
55
331900c6 56 $fetch = $_GET["fetch"];
175847de 57
8143ae1f
AD
58 /* FIXME this needs reworking */
59
fc69e641 60 function getGlobalCounters($link) {
4c193675
AD
61 $result = db_query($link, "SELECT count(id) as c_id FROM ttrss_entries,ttrss_user_entries
62 WHERE unread = true AND
63 ttrss_user_entries.ref_id = ttrss_entries.id AND
64 owner_uid = " . $_SESSION["uid"]);
fc69e641
AD
65 $c_id = db_fetch_result($result, 0, "c_id");
66 print "<counter id='global-unread' counter='$c_id'/>";
67 }
68
8143ae1f 69 function getTagCounters($link) {
05732aa0 70
8143ae1f 71 $result = db_query($link, "SELECT tag_name,count(ttrss_entries.id) AS count
4c193675
AD
72 FROM ttrss_tags,ttrss_entries,ttrss_user_entries WHERE
73 ttrss_user_entries.ref_id = ttrss_entries.id AND
4356293a 74 ttrss_tags.owner_uid = ".$_SESSION["uid"]." AND
05732aa0 75 post_int_id = ttrss_user_entries.int_id AND unread = true GROUP BY tag_name
8143ae1f 76 UNION
4356293a
AD
77 select tag_name,0 as count FROM ttrss_tags
78 WHERE ttrss_tags.owner_uid = ".$_SESSION["uid"]);
8143ae1f
AD
79
80 $tags = array();
81
82 while ($line = db_fetch_assoc($result)) {
83 $tags[$line["tag_name"]] += $line["count"];
84 }
85
86 foreach (array_keys($tags) as $tag) {
87 $unread = $tags[$tag];
88
89 $tag = htmlspecialchars($tag);
90 print "<tag id=\"$tag\" counter=\"$unread\"/>";
91 }
92 }
93
090e250b
AD
94 function getLabelCounters($link) {
95
4c193675
AD
96 $result = db_query($link, "SELECT count(id) as count FROM ttrss_entries,ttrss_user_entries
97 WHERE marked = true AND ttrss_user_entries.ref_id = ttrss_entries.id AND
98 unread = true AND owner_uid = ".$_SESSION["uid"]);
090e250b 99
d61fd764 100 $count = db_fetch_result($result, 0, "count");
090e250b
AD
101
102 print "<label id=\"-1\" counter=\"$count\"/>";
103
4356293a
AD
104 $result = db_query($link, "SELECT owner_uid,id,sql_exp,description FROM
105 ttrss_labels WHERE owner_uid = ".$_SESSION["uid"]." ORDER by description");
090e250b
AD
106
107 while ($line = db_fetch_assoc($result)) {
108
109 $id = -$line["id"] - 11;
110
111 error_reporting (0);
d61fd764 112
4c193675 113 $tmp_result = db_query($link, "SELECT count(id) as count FROM ttrss_user_entries,ttrss_entries
655be073 114 WHERE (" . $line["sql_exp"] . ") AND unread = true AND
4c193675 115 ttrss_user_entries.ref_id = ttrss_entries.id AND
655be073 116 owner_uid = ".$_SESSION["uid"]);
090e250b 117
d61fd764 118 $count = db_fetch_result($tmp_result, 0, "count");
090e250b 119
ab3f3f72 120 print "<label id=\"$id\" counter=\"$count\"/>";
090e250b
AD
121
122 error_reporting (E_ERROR | E_WARNING | E_PARSE);
123
124 }
125 }
126
8073cce7
AD
127 function getFeedCounter($link, $id) {
128
129 $result = db_query($link, "SELECT
4c193675
AD
130 count(id) as count FROM ttrss_entries,ttrss_user_entries
131 WHERE feed_id = '$id' AND unread = true
132 AND ttrss_user_entries.ref_id = ttrss_entries.id");
8073cce7
AD
133
134 $count = db_fetch_result($result, 0, "count");
135
136 print "<feed id=\"$id\" counter=\"$count\"/>";
137 }
090e250b 138
8073cce7
AD
139 function getFeedCounters($link) {
140
090e250b 141 $result = db_query($link, "SELECT id,
4c193675
AD
142 (SELECT count(id)
143 FROM ttrss_entries,ttrss_user_entries
144 WHERE feed_id = ttrss_feeds.id AND ttrss_user_entries.ref_id = ttrss_entries.id
b88917af 145 AND unread = true AND owner_uid = ".$_SESSION["uid"].") as count
4356293a 146 FROM ttrss_feeds WHERE owner_uid = ".$_SESSION["uid"]);
090e250b
AD
147
148 while ($line = db_fetch_assoc($result)) {
149
150 $id = $line["id"];
151 $count = $line["count"];
152
153 print "<feed id=\"$id\" counter=\"$count\"/>";
154 }
155 }
156
8143ae1f 157 function outputFeedList($link, $tags = false) {
175847de 158
1a66d16e
AD
159 print "<html><head>
160 <title>Tiny Tiny RSS : Feedlist</title>
430bf183
AD
161 <link rel=\"stylesheet\" href=\"tt-rss.css\" type=\"text/css\">";
162
4769ddaf 163 if (get_pref($link, 'USE_COMPACT_STYLESHEET')) {
430bf183
AD
164 print "<link rel=\"stylesheet\" type=\"text/css\"
165 href=\"tt-rss_compact.css\"/>";
166 } else {
167 print "<link title=\"Compact Stylesheet\" rel=\"alternate stylesheet\"
168 type=\"text/css\" href=\"tt-rss_compact.css\"/>";
169 }
170
171 print "<script type=\"text/javascript\" src=\"functions.js\"></script>
1a66d16e
AD
172 <script type=\"text/javascript\" src=\"feedlist.js\"></script>
173 <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\">
3745788e 174 </head><body onload=\"init()\">";
254e0e4b
AD
175
176 print "<ul class=\"feedList\" id=\"feedList\">";
177
4356293a
AD
178 $owner_uid = $_SESSION["uid"];
179
8143ae1f 180 if (!$tags) {
254e0e4b 181
8143ae1f 182 /* virtual feeds */
254e0e4b 183
8143ae1f 184 $result = db_query($link, "SELECT count(id) as num_starred
4c193675
AD
185 FROM ttrss_entries,ttrss_user_entries
186 WHERE marked = true AND
187 ttrss_user_entries.ref_id = ttrss_entries.id AND
188 unread = true AND owner_uid = '$owner_uid'");
8143ae1f 189 $num_starred = db_fetch_result($result, 0, "num_starred");
254e0e4b 190
3745788e 191 $class = "virt";
8add756a
AD
192
193 if ($num_starred > 0) $class .= "Unread";
194
195 printFeedEntry(-1, $class, "Starred articles", $num_starred,
4668523d 196 "images/mark_set.png", $link);
48f0adb0 197
4769ddaf 198 if (get_pref($link, 'ENABLE_LABELS')) {
8143ae1f
AD
199
200 $result = db_query($link, "SELECT id,sql_exp,description FROM
4356293a 201 ttrss_labels WHERE owner_uid = '$owner_uid' ORDER by description");
8143ae1f
AD
202
203 if (db_num_rows($result) > 0) {
204 print "<li><hr></li>";
205 }
206
207 while ($line = db_fetch_assoc($result)) {
48f0adb0 208
8143ae1f
AD
209 error_reporting (0);
210
4c193675
AD
211 $tmp_result = db_query($link, "SELECT count(id) as count FROM ttrss_entries,ttrss_user_entries
212 WHERE (" . $line["sql_exp"] . ") AND unread = true AND
213 ttrss_user_entries.ref_id = ttrss_entries.id
655be073 214 AND owner_uid = '$owner_uid'");
8143ae1f
AD
215
216 $count = db_fetch_result($tmp_result, 0, "count");
217
3745788e 218 $class = "label";
8143ae1f
AD
219
220 if ($count > 0) {
221 $class .= "Unread";
222 }
223
224 error_reporting (E_ERROR | E_WARNING | E_PARSE);
225
226 printFeedEntry(-$line["id"]-11,
4668523d 227 $class, $line["description"], $count, "images/label.png", $link);
8143ae1f
AD
228
229 }
48f0adb0
AD
230 }
231
8143ae1f
AD
232 print "<li><hr></li>";
233
234 $result = db_query($link, "SELECT *,
4c193675
AD
235 (SELECT count(id) FROM ttrss_entries,ttrss_user_entries
236 WHERE feed_id = ttrss_feeds.id AND
237 ttrss_user_entries.ref_id = ttrss_entries.id AND
238 owner_uid = '$owner_uid') AS total,
239 (SELECT count(id) FROM ttrss_entries,ttrss_user_entries
b88917af 240 WHERE feed_id = ttrss_feeds.id AND unread = true
4c193675 241 AND ttrss_user_entries.ref_id = ttrss_entries.id
b88917af 242 AND owner_uid = '$owner_uid') as unread
4356293a 243 FROM ttrss_feeds WHERE owner_uid = '$owner_uid' ORDER BY title");
8143ae1f
AD
244
245 $actid = $_GET["actid"];
246
247 /* real feeds */
248
249 $lnum = 0;
250
251 $total_unread = 0;
252
48f0adb0 253 while ($line = db_fetch_assoc($result)) {
8143ae1f
AD
254
255 $feed = $line["title"];
256 $feed_id = $line["id"];
257
258 $subop = $_GET["subop"];
259
260 $total = $line["total"];
261 $unread = $line["unread"];
262
263 // $class = ($lnum % 2) ? "even" : "odd";
48f0adb0 264
3745788e 265 $class = "feed";
8143ae1f
AD
266
267 if ($unread > 0) $class .= "Unread";
268
269 if ($actid == $feed_id) {
270 $class .= "Selected";
392d4563 271 }
48f0adb0 272
8143ae1f
AD
273 $total_unread += $unread;
274
4668523d 275 printFeedEntry($feed_id, $class, $feed, $unread, "icons/$feed_id.ico", $link);
8143ae1f
AD
276
277 ++$lnum;
48f0adb0 278 }
8143ae1f 279 } else {
a1a8a2be 280
8143ae1f 281 // tags
a1a8a2be 282
8143ae1f 283 $result = db_query($link, "SELECT tag_name,count(ttrss_entries.id) AS count
05732aa0
AD
284 FROM ttrss_tags,ttrss_entries,ttrss_user_entries WHERE
285 post_int_id = ttrss_user_entries.int_id AND
286 unread = true AND ref_id = ttrss_entries.id
3b0948c4 287 AND ttrss_tags.owner_uid = '$owner_uid' GROUP BY tag_name
8143ae1f 288 UNION
3b0948c4
AD
289 select tag_name,0 as count FROM ttrss_tags WHERE owner_uid = '$owner_uid'
290 ORDER BY tag_name");
8143ae1f
AD
291
292 $tags = array();
293
294 while ($line = db_fetch_assoc($result)) {
295 $tags[$line["tag_name"]] += $line["count"];
1a66d16e 296 }
8143ae1f
AD
297
298 foreach (array_keys($tags) as $tag) {
299
300 $unread = $tags[$tag];
301
302 $class = "odd";
303
304 if ($unread > 0) {
305 $class .= "Unread";
306 }
307
4668523d 308 printFeedEntry($tag, $class, $tag, $unread, "images/tag.png", $link);
8143ae1f
AD
309
310 }
1a66d16e 311
e828e31e 312 }
82baad4a 313
dc33ec95 314 if (db_num_rows($result) == 0) {
4356293a 315 print "<li>No tags/feeds to display.</li>";
dc33ec95
AD
316 }
317
8143ae1f 318 print "</ul>";
1cd17194 319
caa4e57f
AD
320 print "<div class=\"invisible\" id=\"FEEDTU\">$total_unread</div>";
321
c3b81db0
AD
322 }
323
324
325 if ($op == "rpc") {
326
327 $subop = $_GET["subop"];
328
090e250b 329 if ($subop == "getLabelCounters") {
8073cce7 330 $aid = $_GET["aid"];
090e250b
AD
331 print "<rpc-reply>";
332 getLabelCounters($link);
8073cce7
AD
333 if ($aid) {
334 getFeedCounter($link, $aid);
335 }
090e250b
AD
336 print "</rpc-reply>";
337 }
338
339 if ($subop == "getFeedCounters") {
340 print "<rpc-reply>";
341 getFeedCounters($link);
342 print "</rpc-reply>";
343 }
344
345 if ($subop == "getAllCounters") {
346 print "<rpc-reply>";
347 getLabelCounters($link);
348 getFeedCounters($link);
8143ae1f 349 getTagCounters($link);
fc69e641 350 getGlobalCounters($link);
090e250b 351 print "</rpc-reply>";
090e250b
AD
352 }
353
f4c10d44
AD
354 if ($subop == "mark") {
355 $mark = $_GET["mark"];
648472a7 356 $id = db_escape_string($_GET["id"]);
f4c10d44
AD
357
358 if ($mark == "1") {
359 $mark = "true";
360 } else {
361 $mark = "false";
362 }
363
b5137506
AD
364 // FIXME this needs collision testing
365
366 $result = db_query($link, "UPDATE ttrss_user_entries SET marked = $mark
367 WHERE ref_id = '$id' AND owner_uid = " . $_SESSION["uid"]);
f4c10d44
AD
368 }
369
caa4e57f 370 if ($subop == "updateFeed") {
648472a7 371 $feed_id = db_escape_string($_GET["feed"]);
9cfc649a 372
648472a7 373 $result = db_query($link,
a5873b2e
AD
374 "SELECT feed_url FROM ttrss_feeds WHERE id = '$feed_id'
375 AND owner_uid = " . $_SESSION["uid"]);
9cfc649a 376
648472a7
AD
377 if (db_num_rows($result) > 0) {
378 $feed_url = db_fetch_result($result, 0, "feed_url");
a5873b2e 379 update_rss_feed($link, $feed_url, $feed_id);
caa4e57f 380 }
9cfc649a 381
a5873b2e
AD
382 print "<rpc-reply>";
383 getFeedCounter($link, $feed_id);
384 print "</rpc-reply>";
385
caa4e57f 386 return;
9cfc649a
AD
387 }
388
090e250b 389 if ($subop == "forceUpdateAllFeeds" || $subop == "updateAllFeeds") {
c5142cca 390
05732aa0 391 update_all_feeds($link, $subop == "forceUpdateAllFeeds");
c3b81db0 392
ab3f3f72
AD
393 $omode = $_GET["omode"];
394
395 if (!$omode) $omode = "tfl";
396
090e250b 397 print "<rpc-reply>";
ab3f3f72
AD
398 if (strchr($omode, "l")) getLabelCounters($link);
399 if (strchr($omode, "f")) getFeedCounters($link);
400 if (strchr($omode, "t")) getTagCounters($link);
fc69e641 401 getGlobalCounters($link);
090e250b 402 print "</rpc-reply>";
c3b81db0
AD
403 }
404
b018b49b 405 if ($subop == "catchupSelected") {
c3b81db0
AD
406
407 $ids = split(",", $_GET["ids"]);
408
409 foreach ($ids as $id) {
410
b018b49b
AD
411 db_query($link, "UPDATE ttrss_user_entries SET unread=false,last_read = NOW()
412 WHERE id = '$id' AND owner_uid = " . $_SESSION["uid"]);
c3b81db0
AD
413
414 }
415
416 print "Marked active page as read.";
417 }
295f9b42
AD
418
419 if ($subop == "sanityCheck") {
420
421 $error_code = 0;
422
423 $result = db_query($link, "SELECT schema_version FROM ttrss_version");
424
425 $schema_version = db_fetch_result($result, 0, "schema_version");
426
427 if ($schema_version != SCHEMA_VERSION) {
428 $error_code = 5;
429 }
430
262bd8ea 431 print "<error error-code='$error_code'/>";
295f9b42 432 }
fefa6ca3
AD
433
434 if ($subop == "globalPurge") {
435
436 print "<rpc-reply>";
437 global_purge_old_posts($link, true);
438 print "</rpc-reply>";
439
440 }
441
c3b81db0
AD
442 }
443
444 if ($op == "feeds") {
445
8143ae1f
AD
446 $tags = $_GET["tags"];
447
c3b81db0
AD
448 $subop = $_GET["subop"];
449
450 if ($subop == "catchupAll") {
b018b49b 451 db_query($link, "UPDATE ttrss_user_entries SET
6d15e1ef 452 last_read = NOW(),unread = false WHERE owner_uid = " . $_SESSION["uid"]);
c3b81db0
AD
453 }
454
8143ae1f 455 outputFeedList($link, $tags);
c3b81db0 456
1cd17194
AD
457 }
458
459 if ($op == "view") {
460
d76a3b03 461 $id = $_GET["id"];
8073cce7 462 $feed_id = $_GET["feed"];
d76a3b03 463
4c193675
AD
464 $result = db_query($link, "UPDATE ttrss_user_entries
465 SET unread = false,last_read = NOW()
466 WHERE ref_id = '$id' AND feed_id = '$feed_id' AND owner_uid = " . $_SESSION["uid"]);
a1a8a2be 467
70830c87
AD
468 $addheader = $_GET["addheader"];
469
648472a7 470 $result = db_query($link, "SELECT title,link,content,feed_id,comments,
b7f4bda2 471 (SELECT icon_url FROM ttrss_feeds WHERE id = feed_id) as icon_url
4c193675
AD
472 FROM ttrss_entries,ttrss_user_entries
473 WHERE id = '$id' AND ref_id = id");
1cd17194 474
70830c87 475 if ($addheader) {
f0601b87 476 print "<html><head>
70830c87
AD
477 <title>Tiny Tiny RSS : Article $id</title>
478 <link rel=\"stylesheet\" href=\"tt-rss.css\" type=\"text/css\">
c05608c2 479 <script type=\"text/javascript\" src=\"functions.js\"></script>
70830c87 480 <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\">
f0601b87 481 </head><body>";
70830c87
AD
482 }
483
d76a3b03 484 if ($result) {
1cd17194 485
648472a7 486 $line = db_fetch_assoc($result);
1cd17194 487
b7f4bda2
AD
488 if ($line["icon_url"]) {
489 $feed_icon = "<img class=\"feedIcon\" src=\"" . $line["icon_url"] . "\">";
490 } else {
491 $feed_icon = "&nbsp;";
492 }
d76a3b03 493
f7181e9b
AD
494 if ($line["comments"] && $line["link"] != $line["comments"]) {
495 $entry_comments = "(<a href=\"".$line["comments"]."\">Comments</a>)";
496 } else {
497 $entry_comments = "";
498 }
499
e828e31e
AD
500 print "<div class=\"postReply\">";
501
502 print "<div class=\"postHeader\"><table>";
503
504 print "<tr><td><b>Title:</b></td>
505 <td width='100%'>" . $line["title"] . "</td></tr>";
f7181e9b 506
e828e31e 507 print "<tr><td><b>Link:</b></td>
f7181e9b
AD
508 <td width='100%'>
509 <a href=\"" . $line["link"] . "\">".$line["link"]."</a>
510 $entry_comments</td></tr>";
e828e31e
AD
511
512 print "</table></div>";
513
514 print "<div class=\"postIcon\">" . $feed_icon . "</div>";
515 print "<div class=\"postContent\">" . $line["content"] . "</div>";
516
517 print "</div>";
518
090e250b 519 print "<script type=\"text/javascript\">
8143ae1f 520 update_label_counters('$feed_id');
090e250b 521 </script>";
d76a3b03 522 }
70830c87
AD
523
524 if ($addheader) {
525 print "</body></html>";
526 }
1cd17194
AD
527 }
528
529 if ($op == "viewfeed") {
530
531 $feed = $_GET["feed"];
d76a3b03 532 $skip = $_GET["skip"];
476cac42 533 $subop = $_GET["subop"];
f175937c 534 $view_mode = $_GET["view"];
f0601b87 535 $addheader = $_GET["addheader"];
cb1083a1 536 $limit = $_GET["limit"];
a1a8a2be 537
8d7008c7
AD
538 if (!$feed) {
539 print "Error: no feed to display.";
540 return;
541 }
542
ac53063a
AD
543 if (!$skip) $skip = 0;
544
476cac42 545 if ($subop == "undefined") $subop = "";
1cd17194 546
f0601b87
AD
547 if ($addheader) {
548 print "<html><head>
ac43eba1 549 <title>Tiny Tiny RSS : Feed $feed</title>
430bf183
AD
550 <link rel=\"stylesheet\" href=\"tt-rss.css\" type=\"text/css\">";
551
4769ddaf 552 if (get_pref($link, 'USE_COMPACT_STYLESHEET')) {
430bf183
AD
553 print "<link rel=\"stylesheet\"
554 type=\"text/css\" href=\"tt-rss_compact.css\"/>";
555
556 } else {
557 print "<link title=\"Compact Stylesheet\" rel=\"alternate stylesheet\"
558 type=\"text/css\" href=\"tt-rss_compact.css\"/>";
559 }
560 print "<meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\">
f0601b87
AD
561 <script type=\"text/javascript\" src=\"functions.js\"></script>
562 <script type=\"text/javascript\" src=\"viewfeed.js\"></script>
b623b3ed 563 </head><body onload='init()'>";
f0601b87
AD
564 }
565
dcee8f61
AD
566 if ($subop == "ForceUpdate" && sprintf("%d", $feed) > 0) {
567
568 $tmp_result = db_query($link, "SELECT feed_url FROM ttrss_feeds
569 WHERE id = '$feed'");
570
571 $feed_url = db_fetch_result($tmp_result, 0, "feed_url");
572
573 update_rss_feed($link, $feed_url, $feed);
574
575 }
576
0e32076b 577 if ($subop == "MarkAllRead") {
d76a3b03 578
0e32076b
AD
579 if (sprintf("%d", $feed) != 0) {
580
581 if ($feed > 0) {
f23a2177 582 db_query($link, "UPDATE ttrss_user_entries
0e32076b 583 SET unread = false,last_read = NOW()
f23a2177 584 WHERE feed_id = '$feed' AND owner_uid = " . $_SESSION["uid"]);
0e32076b
AD
585
586 } else if ($feed < 0 && $feed > -10) { // special, like starred
587
588 if ($feed == -1) {
f23a2177 589 db_query($link, "UPDATE ttrss_user_entries
0e32076b 590 SET unread = false,last_read = NOW()
5859be02 591 WHERE marked = true AND owner_uid = ".$_SESSION["uid"]);
0e32076b
AD
592 }
593
594 } else if ($feed < -10) { // label
595
f23a2177
AD
596 // TODO make this more efficient
597
7db95187 598 $label_id = -$feed - 11;
0e32076b 599
7db95187 600 $tmp_result = db_query($link, "SELECT sql_exp FROM ttrss_labels
f23a2177 601 WHERE id = '$label_id'");
7db95187
AD
602
603 if ($tmp_result) {
604 $sql_exp = db_fetch_result($tmp_result, 0, "sql_exp");
605
f23a2177
AD
606 db_query($link, "BEGIN");
607
608 $tmp2_result = db_query($link,
609 "SELECT
610 int_id
611 FROM
612 ttrss_user_entries,ttrss_entries
613 WHERE
614 ref_id = id AND
615 $sql_exp AND
616 owner_uid = " . $_SESSION["uid"]);
617
618 while ($tmp_line = db_fetch_assoc($tmp2_result)) {
619 db_query($link, "UPDATE
620 ttrss_user_entries
621 SET
622 unread = false, last_read = NOW()
623 WHERE
624 int_id = " . $tmp_line["int_id"]);
625 }
626
627 db_query($link, "COMMIT");
628
629/* db_query($link, "UPDATE ttrss_user_entries,ttrss_entries
7db95187 630 SET unread = false,last_read = NOW()
f23a2177
AD
631 WHERE $sql_exp
632 AND ref_id = id
633 AND owner_uid = ".$_SESSION["uid"]); */
7db95187 634 }
254e0e4b 635 }
0e32076b
AD
636 } else { // tag
637 // FIXME, implement catchup for tags
a1a8a2be 638 }
0e32076b 639
a1a8a2be 640 }
d76a3b03 641
175847de 642 print "<table class=\"headlinesList\" id=\"headlinesList\" width=\"100%\">";
ac53063a 643
c374a3fe
AD
644 $search = $_GET["search"];
645
52b51244
AD
646 $search_mode = $_GET["smode"];
647
f175937c 648 if ($search) {
ac53063a
AD
649 $search_query_part = "(upper(title) LIKE upper('%$search%')
650 OR content LIKE '%$search%') AND";
f175937c
AD
651 } else {
652 $search_query_part = "";
653 }
654
655 $view_query_part = "";
656
657 if ($view_mode == "Starred") {
658 $view_query_part = " marked = true AND ";
ac53063a
AD
659 }
660
ac43eba1
AD
661 if ($view_mode == "Unread") {
662 $view_query_part = " unread = true AND ";
663 }
664
b5aa95e7
AD
665 if ($view_mode == "Unread or Starred") {
666 $view_query_part = " (unread = true OR marked = true) AND ";
667 }
668
bdd01d3f
AD
669 if ($view_mode == "Unread or Updated") {
670 $view_query_part = " (unread = true OR last_read is NULL) AND ";
671 }
672
254e0e4b 673/* $result = db_query($link, "SELECT count(id) AS total_entries
36bf7496
AD
674 FROM ttrss_entries WHERE
675 $search_query_part
676 feed_id = '$feed'");
e6d1c0a0 677
254e0e4b 678 $total_entries = db_fetch_result($result, 0, "total_entries"); */
e6d1c0a0 679
648472a7 680/* $result = db_query("SELECT count(id) AS unread_entries
ac43eba1
AD
681 FROM ttrss_entries WHERE
682 $search_query_part
683 unread = true AND
684 feed_id = '$feed'");
685
648472a7 686 $unread_entries = db_fetch_result($result, 0, "unread_entries"); */
ac43eba1 687
8d7008c7 688 if ($limit && $limit != "All") {
82c9223c 689 $limit_query_part = "LIMIT " . $limit;
ad3cb710 690 }
f0601b87 691
254e0e4b
AD
692 $vfeed_query_part = "";
693
52b51244 694 // override query strategy and enable feed display when searching globally
d3416913 695 if ($search && $search_mode == "All feeds") {
52b51244
AD
696 $query_strategy_part = "id > 0";
697 $vfeed_query_part = "(SELECT title FROM ttrss_feeds WHERE
698 id = feed_id) as feed_title,";
699 } else if (sprintf("%d", $feed) == 0) {
8143ae1f
AD
700 $query_strategy_part = "ttrss_entries.id > 0";
701 $vfeed_query_part = "(SELECT title FROM ttrss_feeds WHERE
702 id = feed_id) as feed_title,";
703 } else if ($feed >= 0) {
254e0e4b 704 $query_strategy_part = "feed_id = '$feed'";
48f0adb0 705 } else if ($feed == -1) { // starred virtual feed
254e0e4b 706 $query_strategy_part = "marked = true";
48f0adb0
AD
707 $vfeed_query_part = "(SELECT title FROM ttrss_feeds WHERE
708 id = feed_id) as feed_title,";
709 } else if ($feed <= -10) { // labels
710 $label_id = -$feed - 11;
711
712 $tmp_result = db_query($link, "SELECT sql_exp FROM ttrss_labels
713 WHERE id = '$label_id'");
714
715 $query_strategy_part = db_fetch_result($tmp_result, 0, "sql_exp");
716
254e0e4b
AD
717 $vfeed_query_part = "(SELECT title FROM ttrss_feeds WHERE
718 id = feed_id) as feed_title,";
719 } else {
48f0adb0 720 $query_strategy_part = "id > 0"; // dumb
254e0e4b
AD
721 }
722
52b51244 723
f99321a3
AD
724 $order_by = "updated DESC";
725
726// if ($feed < -10) {
727// $order_by = "feed_id,updated DESC";
728// }
729
48f0adb0
AD
730 if ($feed < -10) error_reporting (0);
731
8143ae1f
AD
732 if (sprintf("%d", $feed) != 0) {
733
734 $result = db_query($link, "SELECT
735 id,title,updated,unread,feed_id,marked,link,last_read,
736 SUBSTRING(last_read,1,19) as last_read_noms,
737 $vfeed_query_part
738 SUBSTRING(updated,1,19) as updated_noms
739 FROM
4c193675 740 ttrss_entries,ttrss_user_entries
8143ae1f 741 WHERE
4c193675 742 ttrss_user_entries.ref_id = ttrss_entries.id AND
aee86c2e 743 owner_uid = '".$_SESSION["uid"]."' AND
8143ae1f
AD
744 $search_query_part
745 $view_query_part
746 $query_strategy_part ORDER BY $order_by
747 $limit_query_part");
748
749 } else {
750 // browsing by tag
751
752 $result = db_query($link, "SELECT
753 ttrss_entries.id as id,title,updated,unread,feed_id,
754 marked,link,last_read,
c05a19f3 755 SUBSTRING(last_read,1,19) as last_read_noms,
254e0e4b 756 $vfeed_query_part
c05a19f3 757 SUBSTRING(updated,1,19) as updated_noms
8143ae1f 758 FROM
05732aa0 759 ttrss_entries,ttrss_user_entries,ttrss_tags
8143ae1f 760 WHERE
05732aa0
AD
761 ref_id = ttrss_entries.id AND
762 ttrss_user_entries.owner_uid = '".$_SESSION["uid"]."' AND
763 post_int_id = int_id AND tag_name = '$feed' AND
8143ae1f
AD
764 $view_query_part
765 $search_query_part
766 $query_strategy_part ORDER BY $order_by
767 $limit_query_part");
768 }
d76a3b03 769
48f0adb0
AD
770 if (!$result) {
771 print "<tr><td colspan='4' align='center'>
772 Could not display feed (query failed). Please check match syntax or local configuration.</td></tr>";
773 return;
774 }
775
a1a8a2be 776 $lnum = 0;
48f0adb0
AD
777
778 error_reporting (E_ERROR | E_WARNING | E_PARSE);
779
e1123aee 780 $num_unread = 0;
d76a3b03 781
648472a7 782 while ($line = db_fetch_assoc($result)) {
d76a3b03 783
a1a8a2be 784 $class = ($lnum % 2) ? "even" : "odd";
d76a3b03 785
ad99045e
AD
786 $id = $line["id"];
787 $feed_id = $line["feed_id"];
788
c43f77f5 789// printf("L %d (%s) &gt; U %d (%s) = %d<br>",
c05a19f3 790// strtotime($line["last_read_noms"]), $line["last_read_noms"],
c43f77f5
AD
791// strtotime($line["updated"]), $line["updated"],
792// strtotime($line["last_read"]) >= strtotime($line["updated"]));
793
ecb14114 794/* if ($line["last_read"] != "" && $line["updated"] != "" &&
c05a19f3 795 strtotime($line["last_read_noms"]) < strtotime($line["updated_noms"])) {
c43f77f5
AD
796
797 $update_pic = "<img id='FUPDPIC-$id' src=\"images/updated.png\"
798 alt=\"Updated\">";
799
800 } else {
801
5bfef089 802 $update_pic = "<img id='FUPDPIC-$id' src=\"images/blank_icon.gif\"
c43f77f5
AD
803 alt=\"Updated\">";
804
ecb14114
AD
805 } */
806
4cc6ea5e
AD
807 if ($line["last_read"] == "" &&
808 ($line["unread"] != "t" && $line["unread"] != "1")) {
809
ecb14114
AD
810 $update_pic = "<img id='FUPDPIC-$id' src=\"images/updated.png\"
811 alt=\"Updated\">";
812 } else {
813 $update_pic = "<img id='FUPDPIC-$id' src=\"images/blank_icon.gif\"
814 alt=\"Updated\">";
c43f77f5 815 }
b197f117 816
8158c57a 817 if ($line["unread"] == "t" || $line["unread"] == "1") {
a1a8a2be 818 $class .= "Unread";
e1123aee
AD
819 ++$num_unread;
820 }
d76a3b03 821
8158c57a 822 if ($line["marked"] == "t" || $line["marked"] == "1") {
f4c10d44
AD
823 $marked_pic = "<img id=\"FMARKPIC-$id\" src=\"images/mark_set.png\"
824 alt=\"Reset mark\" onclick='javascript:toggleMark($id, false)'>";
825 } else {
826 $marked_pic = "<img id=\"FMARKPIC-$id\" src=\"images/mark_unset.png\"
827 alt=\"Set mark\" onclick='javascript:toggleMark($id, true)'>";
828 }
829
ac43eba1 830 $content_link = "<a id=\"FTITLE-$id\" href=\"javascript:view($id,$feed_id);\">" .
b197f117
AD
831 $line["title"] . "</a>";
832
d5224f0d 833 print "<tr class='$class' id='RROW-$id'>";
5f89f780 834 // onclick=\"javascript:view($id,$feed_id)\">
b197f117 835
8d7008c7
AD
836 print "<td valign='center' align='center'>$update_pic</td>";
837 print "<td valign='center' align='center'>$marked_pic</td>";
b197f117 838
8d7008c7 839 print "<td width='25%'>
a3ee2a38 840 <a href=\"javascript:view($id,$feed_id);\">".$line["updated"]."</a></td>";
254e0e4b
AD
841
842 if ($line["feed_title"]) {
843 print "<td width='50%'>$content_link</td>";
2db4190c
AD
844 print "<td width='20%'>
845 <a href='javascript:viewfeed($feed_id)'>".$line["feed_title"]."</a></td>";
254e0e4b
AD
846 } else {
847 print "<td width='70%'>$content_link</td>";
848 }
d76a3b03 849
a1a8a2be 850 print "</tr>";
d76a3b03 851
a1a8a2be
AD
852 ++$lnum;
853 }
d76a3b03 854
ac53063a 855 if ($lnum == 0) {
a82065a1 856 print "<tr><td align='center'>No articles found.</td></tr>";
047bae73 857 }
a2015351 858
a1a8a2be 859 print "</table>";
6113ef7d
AD
860
861 print "<script type=\"text/javascript\">
bb7cface 862 document.onkeydown = hotkey_handler;
8143ae1f 863 update_label_counters('$feed');
6113ef7d 864 </script>";
d76a3b03 865
f0601b87
AD
866 if ($addheader) {
867 print "</body></html>";
868 }
869
1cd17194
AD
870 }
871
0e091d38 872 if ($op == "pref-rpc") {
331900c6 873
0e091d38 874 $subop = $_GET["subop"];
331900c6 875
83fe4d6d
AD
876 if ($subop == "unread") {
877 $ids = split(",", $_GET["ids"]);
878 foreach ($ids as $id) {
a5873b2e
AD
879 db_query($link, "UPDATE ttrss_user_entries SET unread = true
880 WHERE feed_id = '$id' AND owner_uid = ".$_SESSION["uid"]);
83fe4d6d 881 }
0e091d38 882
a5873b2e 883 print "Marked selected feeds as unread.";
83fe4d6d
AD
884 }
885
886 if ($subop == "read") {
887 $ids = split(",", $_GET["ids"]);
888 foreach ($ids as $id) {
a5873b2e
AD
889 db_query($link, "UPDATE ttrss_user_entries
890 SET unread = false,last_read = NOW() WHERE
891 feed_id = '$id' AND owner_uid = ".$_SESSION["uid"]);
83fe4d6d 892 }
0e091d38 893
a5873b2e 894 print "Marked selected feeds as read.";
0e091d38
AD
895
896 }
897
898 }
899
900 if ($op == "pref-feeds") {
901
902 $subop = $_GET["subop"];
903
508a81e1 904 if ($subop == "editSave") {
648472a7
AD
905 $feed_title = db_escape_string($_GET["t"]);
906 $feed_link = db_escape_string($_GET["l"]);
d148926e 907 $upd_intl = db_escape_string($_GET["ui"]);
5d73494a 908 $purge_intl = db_escape_string($_GET["pi"]);
508a81e1
AD
909 $feed_id = $_GET["id"];
910
d148926e
AD
911 if (strtoupper($upd_intl) == "DEFAULT")
912 $upd_intl = 0;
913
5d73494a
AD
914 if (strtoupper($purge_intl) == "DEFAULT")
915 $purge_intl = 0;
916
140aae81
AD
917 if (strtoupper($purge_intl) == "DISABLED")
918 $purge_intl = -1;
919
648472a7 920 $result = db_query($link, "UPDATE ttrss_feeds SET
d148926e 921 title = '$feed_title', feed_url = '$feed_link',
5d73494a
AD
922 update_interval = '$upd_intl',
923 purge_interval = '$purge_intl'
f72dbbde 924 WHERE id = '$feed_id' AND owner_uid = " . $_SESSION["uid"]);
508a81e1 925
83fe4d6d
AD
926 }
927
331900c6 928 if ($subop == "remove") {
331900c6 929
b0b4abcf 930 if (!WEB_DEMO_MODE) {
331900c6 931
b0b4abcf
AD
932 $ids = split(",", $_GET["ids"]);
933
934 foreach ($ids as $id) {
f72dbbde
AD
935 db_query($link, "DELETE FROM ttrss_feeds
936 WHERE id = '$id' AND owner_uid = " . $_SESSION["uid"]);
4769ddaf 937
273a2f6b 938 $icons_dir = ICONS_DIR;
d5caaae5 939
4769ddaf
AD
940 if (file_exists($icons_dir . "/$id.ico")) {
941 unlink($icons_dir . "/$id.ico");
d5caaae5 942 }
b0b4abcf 943 }
331900c6
AD
944 }
945 }
946
947 if ($subop == "add") {
b0b4abcf
AD
948
949 if (!WEB_DEMO_MODE) {
331900c6 950
b6b535ca 951 $feed_link = db_escape_string(trim($_GET["link"]));
331900c6 952
648472a7 953 $result = db_query($link,
7e9a3986
AD
954 "SELECT id FROM ttrss_feeds
955 WHERE feed_url = '$feed_link' AND owner_uid = ".$_SESSION["uid"]);
956
957 if (db_num_rows($result) == 0) {
958
959 $result = db_query($link,
960 "INSERT INTO ttrss_feeds (owner_uid,feed_url,title)
961 VALUES ('".$_SESSION["uid"]."', '$feed_link', '')");
331900c6 962
7e9a3986
AD
963 $result = db_query($link,
964 "SELECT id FROM ttrss_feeds WHERE feed_url = '$feed_link'
965 AND owner_uid = " . $_SESSION["uid"]);
966
967 $feed_id = db_fetch_result($result, 0, "id");
968
969 if ($feed_id) {
970 update_rss_feed($link, $feed_link, $feed_id);
971 }
972 } else {
331900c6 973
7e9a3986
AD
974 print "<div class=\"warning\">
975 Feed <b>$feed_link</b> already exists in the database.
976 </div>";
b0b4abcf
AD
977 }
978 }
331900c6 979 }
a0d53889 980
ab3d0b99 981 $result = db_query($link, "SELECT id,title,feed_url,last_error
131f94e4 982 FROM ttrss_feeds WHERE last_error != '' AND owner_uid = ".$_SESSION["uid"]);
ab3d0b99
AD
983
984 if (db_num_rows($result) > 0) {
985
986 print "<div class=\"warning\">";
987
988 print "<b>Feeds with update errors:</b>";
989
990 print "<ul class=\"nomarks\">";
991
992 while ($line = db_fetch_assoc($result)) {
993 print "<li>" . $line["title"] . " (" . $line["feed_url"] . "): " .
994 $line["last_error"];
995 }
996
997 print "</ul>";
998 print "</div>";
999
1000 }
1001
a0d53889
AD
1002 print "<table class=\"prefAddFeed\"><tr>
1003 <td><input id=\"fadd_link\"></td>
1004 <td colspan=\"4\" align=\"right\">
1005 <a class=\"button\" href=\"javascript:addFeed()\">Add feed</a></td></tr>
1006 </table>";
1007
648472a7 1008 $result = db_query($link, "SELECT
d148926e 1009 id,title,feed_url,substring(last_updated,1,16) as last_updated,
5d73494a 1010 update_interval,purge_interval
c0e5a40e 1011 FROM
4356293a 1012 ttrss_feeds WHERE owner_uid = '".$_SESSION["uid"]."' ORDER by title");
1cd17194 1013
c6c3a07f
AD
1014 print "<div id=\"infoBox\">PLACEHOLDER</div>";
1015
331900c6 1016 print "<p><table width=\"100%\" class=\"prefFeedList\" id=\"prefFeedList\">";
007bda35 1017 print "<tr class=\"title\">
5d73494a
AD
1018 <td>&nbsp;</td><td>Select</td><td width=\"30%\">Title</td>
1019 <td width=\"30%\">Link</td>
1020 <td width=\"10%\">Update Interval</td>
1021 <td width=\"10%\">Purge Days</td>
d148926e 1022 <td>Last updated</td></tr>";
007bda35
AD
1023
1024 $lnum = 0;
1025
648472a7 1026 while ($line = db_fetch_assoc($result)) {
007bda35
AD
1027
1028 $class = ($lnum % 2) ? "even" : "odd";
9b307248 1029
331900c6 1030 $feed_id = $line["id"];
603c27f8
AD
1031
1032 $edit_feed_id = $_GET["id"];
1033
9b307248
AD
1034 if ($subop == "edit" && $feed_id != $edit_feed_id) {
1035 $class .= "Grayed";
1036 }
1037
331900c6 1038 print "<tr class=\"$class\" id=\"FEEDR-$feed_id\">";
007bda35 1039
273a2f6b 1040 $icon_file = ICONS_DIR . "/$feed_id.ico";
c0e5a40e
AD
1041
1042 if (file_exists($icon_file) && filesize($icon_file) > 0) {
1043 $feed_icon = "<img width=\"16\" height=\"16\"
273a2f6b 1044 src=\"" . ICONS_URL . "/$feed_id.ico\">";
c0e5a40e
AD
1045 } else {
1046 $feed_icon = "&nbsp;";
1047 }
1048 print "<td align='center'>$feed_icon</td>";
1049
6e0584e9
AD
1050 $edit_title = htmlspecialchars(db_unescape_string($line["title"]));
1051 $edit_link = htmlspecialchars(db_unescape_string($line["feed_url"]));
1052
9b307248 1053 if (!$edit_feed_id || $subop != "edit") {
603c27f8
AD
1054
1055 print "<td><input onclick='toggleSelectRow(this);'
331900c6 1056 type=\"checkbox\" id=\"FRCHK-".$line["id"]."\"></td>";
603c27f8
AD
1057
1058 print "<td><a href=\"javascript:editFeed($feed_id);\">" .
5d73494a 1059 $edit_title . "</a></td>";
603c27f8 1060 print "<td><a href=\"javascript:editFeed($feed_id);\">" .
5d73494a 1061 $edit_link . "</a></td>";
d148926e
AD
1062
1063 if ($line["update_interval"] == "0")
1064 $line["update_interval"] = "Default";
1065
5d73494a
AD
1066 print "<td><a href=\"javascript:editFeed($feed_id);\">" .
1067 $line["update_interval"] . "</a></td>";
d148926e 1068
5d73494a
AD
1069 if ($line["purge_interval"] == "0")
1070 $line["purge_interval"] = "Default";
1071
140aae81
AD
1072 if ($line["purge_interval"] < 0)
1073 $line["purge_interval"] = "Disabled";
1074
5d73494a
AD
1075 print "<td><a href=\"javascript:editFeed($feed_id);\">" .
1076 $line["purge_interval"] . "</a></td>";
9b307248
AD
1077
1078 } else if ($feed_id != $edit_feed_id) {
1079
e9c54861
AD
1080 print "<td><input disabled=\"true\" type=\"checkbox\"
1081 id=\"FRCHK-".$line["id"]."\"></td>";
9b307248 1082
6e0584e9
AD
1083 print "<td>$edit_title</td>";
1084 print "<td>$edit_link</td>";
9b307248 1085
d148926e
AD
1086 if ($line["update_interval"] == "0")
1087 $line["update_interval"] = "Default";
1088
1089 print "<td>" . $line["update_interval"] . "</td>";
1090
5d73494a
AD
1091 if ($line["purge_interval"] == "0")
1092 $line["purge_interval"] = "Default";
1093
140aae81
AD
1094 if ($line["purge_interval"] < 0)
1095 $line["purge_interval"] = "Disabled";
1096
5d73494a
AD
1097 print "<td>" . $line["purge_interval"] . "</td>";
1098
603c27f8
AD
1099 } else {
1100
e6cb77a0 1101 print "<td><input disabled=\"true\" type=\"checkbox\" checked></td>";
603c27f8 1102
6e0584e9
AD
1103 print "<td><input id=\"iedit_title\" value=\"$edit_title\"></td>";
1104 print "<td><input id=\"iedit_link\" value=\"$edit_link\"></td>";
d148926e 1105 print "<td><input id=\"iedit_updintl\" value=\"".$line["update_interval"]."\"></td>";
5d73494a 1106 print "<td><input id=\"iedit_purgintl\" value=\"".$line["purge_interval"]."\"></td>";
d148926e 1107
603c27f8 1108 }
0afbd851
AD
1109
1110 if (!$line["last_updated"]) $line["last_updated"] = "Never";
1111
007bda35 1112 print "<td>" . $line["last_updated"] . "</td>";
603c27f8 1113
007bda35
AD
1114 print "</tr>";
1115
1116 ++$lnum;
1117 }
1118
0afbd851
AD
1119 if ($lnum == 0) {
1120 print "<tr><td colspan=\"5\" align=\"center\">No feeds defined.</td></tr>";
1121 }
1122
007bda35
AD
1123 print "</table>";
1124
603c27f8
AD
1125 print "<p>";
1126
1127 if ($subop == "edit") {
1128 print "Edit feed:&nbsp;
e828e31e
AD
1129 <input type=\"submit\" class=\"button\"
1130 onclick=\"javascript:feedEditCancel()\" value=\"Cancel\">
1131 <input type=\"submit\" class=\"button\"
8158c57a 1132 onclick=\"javascript:feedEditSave()\" value=\"Save\">";
603c27f8
AD
1133 } else {
1134
603c27f8
AD
1135 print "
1136 Selection:&nbsp;
c6c3a07f
AD
1137 <input type=\"submit\" class=\"button\"
1138 onclick=\"javascript:selectedFeedDetails()\" value=\"Details\">
e828e31e
AD
1139 <input type=\"submit\" class=\"button\"
1140 onclick=\"javascript:editSelectedFeed()\" value=\"Edit\">
1141 <input type=\"submit\" class=\"button\"
1142 onclick=\"javascript:removeSelectedFeeds()\" value=\"Remove\">";
1143
4769ddaf 1144 if (get_pref($link, 'ENABLE_PREFS_CATCHUP_UNCATCHUP')) {
f92db4f5 1145 print "
e828e31e
AD
1146 <input type=\"submit\" class=\"button\"
1147 onclick=\"javascript:readSelectedFeeds()\" value=\"Mark as read\">
1148 <input type=\"submit\" class=\"button\"
1149 onclick=\"javascript:unreadSelectedFeeds()\" value=\"Mark as unread\">&nbsp;";
f92db4f5
AD
1150 }
1151 print "
e828e31e
AD
1152 All feeds:
1153 <input type=\"submit\"
8158c57a 1154 class=\"button\" onclick=\"gotoExportOpml()\" value=\"Export OPML\">";
10c5820d 1155
603c27f8
AD
1156 }
1157
f5a50b25
AD
1158 print "<h3>OPML Import</h3>
1159 <form enctype=\"multipart/form-data\" method=\"POST\" action=\"opml.php\">
1160 File: <input id=\"opml_file\" name=\"opml_file\" type=\"file\">&nbsp;
1161 <input class=\"button\" name=\"op\" onclick=\"return validateOpmlImport();\"
1162 type=\"submit\" value=\"Import\">
1163 </form>";
1164
007bda35
AD
1165 }
1166
a0d53889
AD
1167 if ($op == "pref-filters") {
1168
1169 $subop = $_GET["subop"];
1170
1171 if ($subop == "editSave") {
a0d53889 1172
648472a7
AD
1173 $regexp = db_escape_string($_GET["r"]);
1174 $descr = db_escape_string($_GET["d"]);
1175 $match = db_escape_string($_GET["m"]);
1176 $filter_id = db_escape_string($_GET["id"]);
0afbd851 1177
648472a7 1178 $result = db_query($link, "UPDATE ttrss_filters SET
4b3dff6e 1179 reg_exp = '$regexp',
0afbd851
AD
1180 description = '$descr',
1181 filter_type = (SELECT id FROM ttrss_filter_types WHERE
1182 description = '$match')
1183 WHERE id = '$filter_id'");
a0d53889
AD
1184 }
1185
1186 if ($subop == "remove") {
1187
1188 if (!WEB_DEMO_MODE) {
1189
1190 $ids = split(",", $_GET["ids"]);
1191
1192 foreach ($ids as $id) {
648472a7 1193 db_query($link, "DELETE FROM ttrss_filters WHERE id = '$id'");
a0d53889
AD
1194
1195 }
1196 }
1197 }
1198
1199 if ($subop == "add") {
1200
de435974 1201 if (!WEB_DEMO_MODE) {
a0d53889 1202
b6b535ca
AD
1203 $regexp = db_escape_string(trim($_GET["regexp"]));
1204 $match = db_escape_string(trim($_GET["match"]));
4401bf04 1205
648472a7 1206 $result = db_query($link,
4356293a 1207 "INSERT INTO ttrss_filters (reg_exp,filter_type,owner_uid) VALUES
de435974 1208 ('$regexp', (SELECT id FROM ttrss_filter_types WHERE
4356293a 1209 description = '$match'),'".$_SESSION["uid"]."')");
de435974 1210 }
a0d53889
AD
1211 }
1212
648472a7 1213 $result = db_query($link, "SELECT description
a0d53889
AD
1214 FROM ttrss_filter_types ORDER BY description");
1215
1216 $filter_types = array();
1217
648472a7 1218 while ($line = db_fetch_assoc($result)) {
a0d53889
AD
1219 array_push($filter_types, $line["description"]);
1220 }
1221
1222 print "<table class=\"prefAddFeed\"><tr>
ea6774cf 1223 <td><input id=\"fadd_regexp\"></td>
a0d53889 1224 <td>";
bdc00fe0 1225 print_select("fadd_match", "Title", $filter_types);
a0d53889
AD
1226
1227 print"</td><td colspan=\"4\" align=\"right\">
1228 <a class=\"button\" href=\"javascript:addFilter()\">Add filter</a></td></tr>
1229 </table>";
1230
648472a7 1231 $result = db_query($link, "SELECT
4b3dff6e 1232 id,reg_exp,description,
a0d53889
AD
1233 (SELECT name FROM ttrss_filter_types WHERE
1234 id = filter_type) as filter_type_name,
1235 (SELECT description FROM ttrss_filter_types
1236 WHERE id = filter_type) as filter_type_descr
1237 FROM
4356293a
AD
1238 ttrss_filters
1239 WHERE
1240 owner_uid = ".$_SESSION["uid"]."
1241 ORDER by reg_exp");
a0d53889
AD
1242
1243 print "<p><table width=\"100%\" class=\"prefFilterList\" id=\"prefFilterList\">";
1244
1245 print "<tr class=\"title\">
0afbd851
AD
1246 <td width=\"5%\">Select</td><td width=\"40%\">Filter expression</td>
1247 <td width=\"40%\">Description</td><td width=\"10%\">Match</td></tr>";
a0d53889
AD
1248
1249 $lnum = 0;
1250
648472a7 1251 while ($line = db_fetch_assoc($result)) {
a0d53889
AD
1252
1253 $class = ($lnum % 2) ? "even" : "odd";
1254
1255 $filter_id = $line["id"];
1256 $edit_filter_id = $_GET["id"];
1257
1258 if ($subop == "edit" && $filter_id != $edit_filter_id) {
1259 $class .= "Grayed";
1260 }
1261
1262 print "<tr class=\"$class\" id=\"FILRR-$filter_id\">";
1263
4b3dff6e 1264 $line["regexp"] = htmlspecialchars($line["reg_exp"]);
ea6774cf
AD
1265 $line["description"] = htmlspecialchars($line["description"]);
1266
a0d53889
AD
1267 if (!$edit_filter_id || $subop != "edit") {
1268
0afbd851
AD
1269 if (!$line["description"]) $line["description"] = "[No description]";
1270
a0d53889
AD
1271 print "<td><input onclick='toggleSelectRow(this);'
1272 type=\"checkbox\" id=\"FICHK-".$line["id"]."\"></td>";
1273
1274 print "<td><a href=\"javascript:editFilter($filter_id);\">" .
4b3dff6e 1275 $line["reg_exp"] . "</td>";
a0d53889
AD
1276
1277 print "<td><a href=\"javascript:editFilter($filter_id);\">" .
1278 $line["description"] . "</td>";
1279
1280 print "<td>".$line["filter_type_descr"]."</td>";
1281
1282 } else if ($filter_id != $edit_filter_id) {
1283
0afbd851
AD
1284 if (!$line["description"]) $line["description"] = "[No description]";
1285
a0d53889
AD
1286 print "<td><input disabled=\"true\" type=\"checkbox\"
1287 id=\"FICHK-".$line["id"]."\"></td>";
1288
4b3dff6e 1289 print "<td>".$line["reg_exp"]."</td>";
a0d53889
AD
1290 print "<td>".$line["description"]."</td>";
1291 print "<td>".$line["filter_type_descr"]."</td>";
1292
1293 } else {
1294
e6cb77a0 1295 print "<td><input disabled=\"true\" type=\"checkbox\" checked></td>";
a0d53889 1296
4b3dff6e 1297 print "<td><input id=\"iedit_regexp\" value=\"".$line["reg_exp"].
a0d53889
AD
1298 "\"></td>";
1299
1300 print "<td><input id=\"iedit_descr\" value=\"".$line["description"].
1301 "\"></td>";
1302
1303 print "<td>";
1304 print_select("iedit_match", $line["filter_type_descr"], $filter_types);
1305 print "</td>";
1306
1307 }
1308
1309
1310 print "</tr>";
1311
1312 ++$lnum;
1313 }
1314
0afbd851
AD
1315 if ($lnum == 0) {
1316 print "<tr><td colspan=\"4\" align=\"center\">No filters defined.</td></tr>";
1317 }
1318
a0d53889
AD
1319 print "</table>";
1320
1321 print "<p>";
1322
1323 if ($subop == "edit") {
e828e31e
AD
1324 print "Edit feed:
1325 <input type=\"submit\" class=\"button\"
1326 onclick=\"javascript:filterEditCancel()\" value=\"Cancel\">
1327 <input type=\"submit\" class=\"button\"
1328 onclick=\"javascript:filterEditSave()\" value=\"Save\">";
a0d53889
AD
1329
1330 } else {
1331
1332 print "
e828e31e
AD
1333 Selection:
1334 <input type=\"submit\" class=\"button\"
1335 onclick=\"javascript:editSelectedFilter()\" value=\"Edit\">
1336 <input type=\"submit\" class=\"button\"
1337 onclick=\"javascript:removeSelectedFilters()\" value=\"Remove\">";
a0d53889
AD
1338 }
1339 }
1340
48f0adb0
AD
1341 if ($op == "pref-labels") {
1342
1343 $subop = $_GET["subop"];
1344
1345 if ($subop == "editSave") {
1346
1347 $sql_exp = $_GET["s"];
1348 $descr = $_GET["d"];
1349 $label_id = db_escape_string($_GET["id"]);
1350
1351// print "$sql_exp : $descr : $label_id";
1352
1353 $result = db_query($link, "UPDATE ttrss_labels SET
1354 sql_exp = '$sql_exp',
1355 description = '$descr'
1356 WHERE id = '$label_id'");
1357 }
1358
1359 if ($subop == "remove") {
1360
1361 if (!WEB_DEMO_MODE) {
1362
1363 $ids = split(",", $_GET["ids"]);
1364
1365 foreach ($ids as $id) {
1366 db_query($link, "DELETE FROM ttrss_labels WHERE id = '$id'");
1367
1368 }
1369 }
1370 }
1371
1372 if ($subop == "add") {
1373
1374 if (!WEB_DEMO_MODE) {
1375
4401bf04
AD
1376 // no escaping is done here on purpose
1377 $exp = trim($_GET["exp"]);
48f0adb0
AD
1378
1379 $result = db_query($link,
4356293a
AD
1380 "INSERT INTO ttrss_labels (sql_exp,description,owner_uid)
1381 VALUES ('$exp', '$exp', '".$_SESSION["uid"]."')");
48f0adb0
AD
1382 }
1383 }
1384
1385 print "<table class=\"prefAddFeed\"><tr>
1386 <td><input id=\"ladd_expr\"></td>";
1387
1388 print"<td colspan=\"4\" align=\"right\">
1389 <a class=\"button\" href=\"javascript:addLabel()\">Add label</a></td></tr>
1390 </table>";
1391
1392 $result = db_query($link, "SELECT
1393 id,sql_exp,description
1394 FROM
4356293a
AD
1395 ttrss_labels
1396 WHERE
1397 owner_uid = ".$_SESSION["uid"]."
1398 ORDER by description");
48f0adb0
AD
1399
1400 print "<p><table width=\"100%\" class=\"prefLabelList\" id=\"prefLabelList\">";
1401
1402 print "<tr class=\"title\">
7dc66a61
AD
1403 <td width=\"5%\">Select</td><td width=\"40%\">SQL expression
1404 <a class=\"helpLink\" href=\"javascript:popupHelp(1)\">(?)</a>
1405 </td>
48f0adb0
AD
1406 <td width=\"40%\">Caption</td></tr>";
1407
1408 $lnum = 0;
1409
1410 while ($line = db_fetch_assoc($result)) {
1411
1412 $class = ($lnum % 2) ? "even" : "odd";
1413
1414 $label_id = $line["id"];
1415 $edit_label_id = $_GET["id"];
1416
1417 if ($subop == "edit" && $label_id != $edit_label_id) {
1418 $class .= "Grayed";
1419 }
1420
1421 print "<tr class=\"$class\" id=\"LILRR-$label_id\">";
1422
1423 $line["sql_exp"] = htmlspecialchars($line["sql_exp"]);
1424 $line["description"] = htmlspecialchars($line["description"]);
1425
1426 if (!$edit_label_id || $subop != "edit") {
1427
1428 if (!$line["description"]) $line["description"] = "[No caption]";
1429
1430 print "<td><input onclick='toggleSelectRow(this);'
1431 type=\"checkbox\" id=\"LICHK-".$line["id"]."\"></td>";
1432
1433 print "<td><a href=\"javascript:editLabel($label_id);\">" .
1434 $line["sql_exp"] . "</td>";
1435
1436 print "<td><a href=\"javascript:editLabel($label_id);\">" .
1437 $line["description"] . "</td>";
1438
1439 } else if ($label_id != $edit_label_id) {
1440
1441 if (!$line["description"]) $line["description"] = "[No description]";
1442
1443 print "<td><input disabled=\"true\" type=\"checkbox\"
1444 id=\"LICHK-".$line["id"]."\"></td>";
1445
1446 print "<td>".$line["sql_exp"]."</td>";
1447 print "<td>".$line["description"]."</td>";
1448
1449 } else {
1450
e6cb77a0 1451 print "<td><input disabled=\"true\" type=\"checkbox\" checked></td>";
48f0adb0
AD
1452
1453 print "<td><input id=\"iedit_expr\" value=\"".$line["sql_exp"].
1454 "\"></td>";
1455
1456 print "<td><input id=\"iedit_descr\" value=\"".$line["description"].
1457 "\"></td>";
1458
1459 }
1460
1461
1462 print "</tr>";
1463
1464 ++$lnum;
1465 }
1466
1467 if ($lnum == 0) {
1468 print "<tr><td colspan=\"4\" align=\"center\">No labels defined.</td></tr>";
1469 }
1470
1471 print "</table>";
1472
1473 print "<p>";
1474
1475 if ($subop == "edit") {
1476 print "Edit label:
1477 <input type=\"submit\" class=\"button\"
1478 onclick=\"javascript:labelEditCancel()\" value=\"Cancel\">
1479 <input type=\"submit\" class=\"button\"
1480 onclick=\"javascript:labelEditSave()\" value=\"Save\">";
1481
1482 } else {
1483
1484 print "
1485 Selection:
1486 <input type=\"submit\" class=\"button\"
1487 onclick=\"javascript:editSelectedLabel()\" value=\"Edit\">
1488 <input type=\"submit\" class=\"button\"
1489 onclick=\"javascript:removeSelectedLabels()\" value=\"Remove\">";
1490 }
1491 }
1492
e828e31e
AD
1493 if ($op == "error") {
1494 print "<div width=\"100%\" align='center'>";
1495 $msg = $_GET["msg"];
1496 print $msg;
1497 print "</div>";
1498 }
1499
7dc66a61
AD
1500 if ($op == "help") {
1501 print "<html><head>
1502 <title>Tiny Tiny RSS : Help</title>
1503 <link rel=\"stylesheet\" href=\"tt-rss.css\" type=\"text/css\">
1504 <script type=\"text/javascript\" src=\"functions.js\"></script>
7dc66a61
AD
1505 <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\">
1506 </head><body>";
1507
1508 $tid = sprintf("%d", $_GET["tid"]);
1509
1510 /* FIXME this badly needs real implementation */
1511
1512 print "<div class='helpResponse'>";
1513
1514 ?>
1515
1516 <h1>Help for SQL expressions</h1>
1517
1518 <h2>Description</h2>
1519
1520 <p>The &laquo;SQL expression&raquo; is added to WHERE clause of
d1f948d1 1521 view feed query. You can match on ttrss_entries table fields
7dc66a61
AD
1522 and even use subselect to query additional information. This
1523 functionality is considered to be advanced and requires basic
1524 understanding of SQL.</p>
1525
1526 <h2>Examples</h2>
1527
1528 <pre>unread = true</pre>
1529
1530 Matches all unread articles
1531
1532 <pre>title like '%Linux%'</pre>
1533
1534 Matches all articles which mention Linux in the title. You get the idea.
1535
1536 <p>See the database schema included in the distribution package for gruesome
1537 details.</p>
1538
1539 <?
1540
1541 print "<div align='center'>
1542 <a class=\"helpLink\"
1543 href=\"javascript:window.close()\">(Close this window)</a></div>";
1544
1545 print "</div>";
1546
1547 print "</body></html>";
1548
1549 }
1550
f84a97a3
AD
1551 if ($op == "dlg") {
1552 $id = $_GET["id"];
6de5d056 1553 $param = $_GET["param"];
f84a97a3
AD
1554
1555 if ($id == "quickAddFeed") {
033e47e0
AD
1556 print "Feed URL: <input
1557 onblur=\"javascript:enableHotkeys()\" onfocus=\"javascript:disableHotkeys()\"
1558 id=\"qafInput\">
f84a97a3
AD
1559 <input class=\"button\"
1560 type=\"submit\" onclick=\"javascript:qafAdd()\" value=\"Add feed\">
1561 <input class=\"button\"
1562 type=\"submit\" onclick=\"javascript:closeDlg()\"
1563 value=\"Cancel\">";
1564 }
6de5d056
AD
1565
1566 if ($id == "quickDelFeed") {
1567
1568 $param = db_escape_string($param);
1569
1570 $result = db_query($link, "SELECT title FROM ttrss_feeds WHERE id = '$param'");
1571
1572 if ($result) {
1573
1574 $f_title = db_fetch_result($result, 0, "title");
1575
1576 print "Remove current feed ($f_title)?&nbsp;
1577 <input class=\"button\"
1578 type=\"submit\" onclick=\"javascript:qfdDelete($param)\" value=\"Remove\">
1579 <input class=\"button\"
1580 type=\"submit\" onclick=\"javascript:closeDlg()\"
1581 value=\"Cancel\">";
1582 } else {
1583 print "Error: Feed $param not found.&nbsp;
1584 <input class=\"button\"
1585 type=\"submit\" onclick=\"javascript:closeDlg()\"
1586 value=\"Cancel\">";
1587 }
1588 }
1589
033e47e0
AD
1590 if ($id == "search") {
1591
1592 print "<input id=\"searchbox\" class=\"extSearch\"
1593 onblur=\"javascript:enableHotkeys()\" onfocus=\"javascript:disableHotkeys()\"
1594 onchange=\"javascript:search()\">
1595 <select id=\"searchmodebox\">
1596 <option selected>All feeds</option>
1597 <option>This feed</option>
1598 </select>
1599 <input type=\"submit\"
1600 class=\"button\" onclick=\"javascript:search()\" value=\"Search\">
1601 <input class=\"button\"
1602 type=\"submit\" onclick=\"javascript:closeDlg()\"
1603 value=\"Close\">";
1604
1605 }
1606
f84a97a3
AD
1607 }
1608
e65af9c1
AD
1609 if ($op == "updateAllFeeds") {
1610 update_all_feeds($link, true);
1611
1612 print "<rpc-reply>";
1613 getLabelCounters($link);
1614 getFeedCounters($link);
1615 getTagCounters($link);
1616 getGlobalCounters($link);
1617 print "</rpc-reply>";
1618
1619 }
1620
77e96719
AD
1621 if ($op == "pref-prefs") {
1622
b1895692 1623 $subop = $_REQUEST["subop"];
77e96719
AD
1624
1625 if ($subop == "Save configuration") {
1626
01d68cf9
AD
1627 if (WEB_DEMO_MODE) return;
1628
93cb4442
AD
1629 $_SESSION["prefs_op_result"] = "save-config";
1630
77e96719
AD
1631 foreach (array_keys($_POST) as $pref_name) {
1632
1633 $pref_name = db_escape_string($pref_name);
1634 $value = db_escape_string($_POST[$pref_name]);
1635
1636 $result = db_query($link, "SELECT type_name
1637 FROM ttrss_prefs,ttrss_prefs_types
1638 WHERE pref_name = '$pref_name' AND type_id = ttrss_prefs_types.id");
1639
1640 if (db_num_rows($result) > 0) {
1641
1642 $type_name = db_fetch_result($result, 0, "type_name");
1643
5da169d9
AD
1644// print "$pref_name : $type_name : $value<br>";
1645
77e96719 1646 if ($type_name == "bool") {
5da169d9 1647 if ($value == "1") {
77e96719
AD
1648 $value = "true";
1649 } else {
1650 $value = "false";
1651 }
1652 } else if ($type_name == "integer") {
1653 $value = sprintf("%d", $value);
1654 }
1655
1656// print "$pref_name : $type_name : $value<br>";
1657
ff485f1d
AD
1658 db_query($link, "UPDATE ttrss_user_prefs SET value = '$value'
1659 WHERE pref_name = '$pref_name' AND owner_uid = ".$_SESSION["uid"]);
77e96719
AD
1660
1661 }
1662
1663 header("Location: prefs.php");
1664
1665 }
1666
b1895692
AD
1667 } else if ($subop == "getHelp") {
1668
1669 $pref_name = db_escape_string($_GET["pn"]);
1670
1671 $result = db_query($link, "SELECT help_text FROM ttrss_prefs
1672 WHERE pref_name = '$pref_name'");
1673
1674 if (db_num_rows($result) > 0) {
1675 $help_text = db_fetch_result($result, 0, "help_text");
1676 print $help_text;
1677 } else {
1678 print "Unknown option: $pref_name";
1679 }
1680
1c7f75ed
AD
1681 } else if ($subop == "Change password") {
1682
1683 if (WEB_DEMO_MODE) return;
1684
1685 $old_pw = $_POST["OLD_PASSWORD"];
1686 $new_pw = $_POST["OLD_PASSWORD"];
1687
1688 $old_pw_hash = 'SHA1:' . sha1($_POST["OLD_PASSWORD"]);
1689 $new_pw_hash = 'SHA1:' . sha1($_POST["NEW_PASSWORD"]);
1690
1691 $active_uid = $_SESSION["uid"];
1692
1693 if ($old_pw && $new_pw) {
1694
1695 $login = db_escape_string($_SERVER['PHP_AUTH_USER']);
1696
1697 $result = db_query($link, "SELECT id FROM ttrss_users WHERE
1698 id = '$active_uid' AND (pwd_hash = '$old_pw' OR
1699 pwd_hash = '$old_pw_hash')");
1700
1701 if (db_num_rows($result) == 1) {
1702 db_query($link, "UPDATE ttrss_users SET pwd_hash = '$new_pw_hash'
1703 WHERE id = '$active_uid'");
b791095d
AD
1704
1705 $_SESSION["pwd_change_result"] = "ok";
1706 } else {
1707 $_SESSION["pwd_change_result"] = "failed";
1c7f75ed
AD
1708 }
1709 }
1710
1711 header("Location: prefs.php");
b791095d 1712
77e96719
AD
1713 } else if ($subop == "Reset to defaults") {
1714
01d68cf9
AD
1715 if (WEB_DEMO_MODE) return;
1716
93cb4442
AD
1717 $_SESSION["prefs_op_result"] = "reset-to-defaults";
1718
e1aa0559
AD
1719 if (DB_TYPE == "pgsql") {
1720 db_query($link,"UPDATE ttrss_user_prefs
1721 SET value = ttrss_prefs.def_value
1722 WHERE owner_uid = '".$_SESSION["uid"]."' AND
1723 ttrss_prefs.pref_name = ttrss_user_prefs.pref_name");
1724 } else {
1725 db_query($link, "DELETE FROM ttrss_user_prefs
1726 WHERE owner_uid = ".$_SESSION["uid"]);
1727 initialize_user_prefs($link, $_SESSION["uid"]);
1728 }
5da169d9 1729
77e96719
AD
1730 header("Location: prefs.php");
1731
1732 } else {
1733
7d4c898a 1734 if (!SINGLE_USER_MODE) {
1c7f75ed 1735
a029d530
AD
1736 $result = db_query($link, "SELECT id FROM ttrss_users
1737 WHERE id = ".$_SESSION["uid"]." AND (pwd_hash = 'password' OR
1738 pwd_hash = 'SHA1:".sha1("password")."')");
1739
1740 if (db_num_rows($result) != 0) {
b791095d 1741 print "<div class=\"warning\">
a029d530
AD
1742 Your password is at default value, please change it.
1743 </div>";
1744 }
1745
b791095d
AD
1746 if ($_SESSION["pwd_change_result"] == "failed") {
1747 print "<div class=\"warning\">
1748 There was an error while changing your password.
1749 </div>";
1750 }
1751
1752 if ($_SESSION["pwd_change_result"] == "ok") {
1753 print "<div class=\"notice\">
1754 Password changed successfully.
1755 </div>";
1756 }
1757
1758 $_SESSION["pwd_change_result"] = "";
1759
93cb4442
AD
1760 if ($_SESSION["prefs_op_result"] == "reset-to-defaults") {
1761 print "<div class=\"notice\">
1762 Your configuration was reset to defaults.
1763 </div>";
1764 }
1765
1766 if ($_SESSION["prefs_op_result"] == "save-config") {
1767 print "<div class=\"notice\">
1768 Your configuration was saved successfully.
1769 </div>";
1770 }
1771
1772 $_SESSION["prefs_op_result"] = "";
1773
7d4c898a
AD
1774 print "<form action=\"backend.php\" method=\"POST\">";
1775
1776 print "<table width=\"100%\" class=\"prefPrefsList\">";
1777 print "<tr><td colspan='3'><h3>Authentication</h3></tr></td>";
1778
1779 print "<tr><td width=\"40%\">Old password</td>";
1780 print "<td><input class=\"editbox\" type=\"password\"
1781 name=\"OLD_PASSWORD\"></td></tr>";
1782
1783 print "<tr><td width=\"40%\">New password</td>";
1784
1785 print "<td><input class=\"editbox\" type=\"password\"
1786 name=\"NEW_PASSWORD\"></td></tr>";
1787
1788 print "</table>";
1789
1790 print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
1791
1792 print "<p><input class=\"button\" type=\"submit\"
1793 value=\"Change password\" name=\"subop\">";
1794
1795 print "</form>";
1c7f75ed 1796
7d4c898a 1797 }
1c7f75ed 1798
77e96719 1799 $result = db_query($link, "SELECT
ff485f1d 1800 ttrss_user_prefs.pref_name,short_desc,help_text,value,type_name,
77e96719 1801 section_name,def_value
ff485f1d 1802 FROM ttrss_prefs,ttrss_prefs_types,ttrss_prefs_sections,ttrss_user_prefs
77e96719 1803 WHERE type_id = ttrss_prefs_types.id AND
ff485f1d 1804 section_id = ttrss_prefs_sections.id AND
a2411bd9
AD
1805 ttrss_user_prefs.pref_name = ttrss_prefs.pref_name AND
1806 owner_uid = ".$_SESSION["uid"]."
650bc435 1807 ORDER BY section_id,short_desc");
77e96719
AD
1808
1809 print "<form action=\"backend.php\" method=\"POST\">";
1810
77e96719
AD
1811 $lnum = 0;
1812
1813 $active_section = "";
1814
1815 while ($line = db_fetch_assoc($result)) {
1816
1817 if ($active_section != $line["section_name"]) {
59a654ba
AD
1818
1819 if ($active_section != "") {
1c7f75ed 1820 print "</table>";
59a654ba 1821 }
1c7f75ed
AD
1822
1823 print "<p><table width=\"100%\" class=\"prefPrefsList\">";
59a654ba
AD
1824
1825 $active_section = $line["section_name"];
1826
77e96719 1827 print "<tr><td colspan=\"3\"><h3>$active_section</h3></td></tr>";
59a654ba
AD
1828// print "<tr class=\"title\">
1829// <td width=\"25%\">Option</td><td>Value</td></tr>";
7268adf7
AD
1830
1831 $lnum = 0;
77e96719
AD
1832 }
1833
650bc435 1834// $class = ($lnum % 2) ? "even" : "odd";
77e96719 1835
650bc435 1836 print "<tr>";
77e96719 1837
77e96719
AD
1838 $type_name = $line["type_name"];
1839 $pref_name = $line["pref_name"];
1840 $value = $line["value"];
1841 $def_value = $line["def_value"];
b1895692
AD
1842 $help_text = $line["help_text"];
1843
1844 print "<td width=\"40%\" id=\"$pref_name\">" . $line["short_desc"];
1845
1846 if ($help_text) print "<div class=\"prefHelp\">$help_text</div>";
1847
1848 print "</td>";
77e96719
AD
1849
1850 print "<td>";
1851
1852 if ($type_name == "bool") {
1853// print_select($pref_name, $value, array("true", "false"));
1854
1855 if ($value == "true") {
1856 $value = "Yes";
1857 } else {
1858 $value = "No";
1859 }
1860
1861 print_radio($pref_name, $value, array("Yes", "No"));
1862
1863 } else {
1864 print "<input class=\"editbox\" name=\"$pref_name\" value=\"$value\">";
1865 }
1866
1867 print "</td>";
1868
1869 print "</tr>";
1870
1871 $lnum++;
1872 }
1873
1874 print "</table>";
1875
1876 print "<input type=\"hidden\" name=\"op\" value=\"pref-prefs\">";
1877
1878 print "<p><input class=\"button\" type=\"submit\"
1879 name=\"subop\" value=\"Save configuration\">";
1880
1881 print "&nbsp;<input class=\"button\" type=\"submit\"
1882 name=\"subop\" value=\"Reset to defaults\"></p>";
1883
1884 print "</form>";
1885
1886 }
1887
1888 }
1889
e6cb77a0
AD
1890 if ($op == "pref-users") {
1891
1892 $subop = $_GET["subop"];
1893
1894 if ($subop == "editSave") {
1895
1896 if (!WEB_DEMO_MODE) {
1897
1898 $login = db_escape_string($_GET["l"]);
1899 $uid = db_escape_string($_GET["id"]);
1900 $access_level = sprintf("%d", $_GET["al"]);
1901
1902 db_query($link, "UPDATE ttrss_users SET login = '$login', access_level = '$access_level' WHERE id = '$uid'");
1903
1904 }
1905 } else if ($subop == "remove") {
1906
1907 if (!WEB_DEMO_MODE && $_SESSION["access_level"] >= 10) {
1908
1909 $ids = split(",", $_GET["ids"]);
1910
1911 foreach ($ids as $id) {
1912 db_query($link, "DELETE FROM ttrss_users WHERE id = '$id' AND id != " . $_SESSION["uid"]);
1913
1914 }
1915 }
1916 } else if ($subop == "add") {
1917
1918 if (!WEB_DEMO_MODE && $_SESSION["access_level"] >= 10) {
1919
b6b535ca 1920 $login = db_escape_string(trim($_GET["login"]));
e6cb77a0
AD
1921 $tmp_user_pwd = make_password(8);
1922 $pwd_hash = 'SHA1:' . sha1($tmp_user_pwd);
1923
1924 db_query($link, "INSERT INTO ttrss_users (login,pwd_hash,access_level)
1925 VALUES ('$login', '$pwd_hash', 0)");
1926
1927
1928 $result = db_query($link, "SELECT id FROM ttrss_users WHERE
1929 login = '$login' AND pwd_hash = '$pwd_hash'");
1930
1931 if (db_num_rows($result) == 1) {
1932
1933 $new_uid = db_fetch_result($result, 0, "id");
1934
1935 print "<div class=\"notice\">Added user <b>".$_GET["login"].
1936 "</b> with password <b>$tmp_user_pwd</b>.</div>";
1937
1938 initialize_user($link, $new_uid);
1939
1940 } else {
1941
1942 print "<div class=\"warning\">Error while adding user <b>".
1943 $_GET["login"].".</b></div>";
1944
1945 }
1946 }
1947 } else if ($subop == "resetPass") {
1948
1949 if (!WEB_DEMO_MODE && $_SESSION["access_level"] >= 10) {
1950
1951 $uid = db_escape_string($_GET["id"]);
1952
1953 $result = db_query($link, "SELECT login FROM ttrss_users WHERE id = '$uid'");
1954
1955 $login = db_fetch_result($result, 0, "login");
1956 $tmp_user_pwd = make_password(8);
1957 $pwd_hash = 'SHA1:' . sha1($tmp_user_pwd);
1958
1959 db_query($link, "UPDATE ttrss_users SET pwd_hash = '$pwd_hash'
1960 WHERE id = '$uid'");
1961
1962 print "<div class=\"notice\">Changed password of
1963 user <b>$login</b> to <b>$tmp_user_pwd</b>.</div>";
1964
1965 }
1966 }
1967
1968 print "<table class=\"prefAddFeed\"><tr>
1969 <td><input id=\"uadd_box\"></td>";
1970
1971 print"<td colspan=\"4\" align=\"right\">
1972 <a class=\"button\" href=\"javascript:addUser()\">Add user</a></td></tr>
1973 </table>";
1974
1975 $result = db_query($link, "SELECT
f6f32198 1976 id,login,access_level,last_login
e6cb77a0
AD
1977 FROM
1978 ttrss_users
1979 ORDER by login");
1980
c6c3a07f 1981 print "<div id=\"infoBox\">PLACEHOLDER</div>";
1a7572cb 1982
e6cb77a0
AD
1983 print "<p><table width=\"100%\" class=\"prefUserList\" id=\"prefUserList\">";
1984
1985 print "<tr class=\"title\">
f6f32198
AD
1986 <td width=\"5%\">Select</td>
1987 <td width='30%'>Username</td>
1988 <td width='30%'>Access Level</td>
1989 <td width='30%'>Last login</td></tr>";
e6cb77a0
AD
1990
1991 $lnum = 0;
1992
1993 while ($line = db_fetch_assoc($result)) {
1994
1995 $class = ($lnum % 2) ? "even" : "odd";
1996
1997 $uid = $line["id"];
1998 $edit_uid = $_GET["id"];
1999
2000 if ($uid == $_SESSION["uid"] || ($subop == "edit" && $uid != $edit_uid)) {
2001 $class .= "Grayed";
2002 }
2003
2004 print "<tr class=\"$class\" id=\"UMRR-$uid\">";
2005
2006 $line["login"] = htmlspecialchars($line["login"]);
2007
2008 if ($uid == $_SESSION["uid"]) {
2009
2010 print "<td><input disabled=\"true\" type=\"checkbox\"
2011 id=\"UMCHK-".$line["id"]."\"></td>";
2012
2013 print "<td>".$line["login"]."</td>";
2014 print "<td>".$line["access_level"]."</td>";
e6cb77a0
AD
2015
2016 } else if (!$edit_uid || $subop != "edit") {
2017
2018 print "<td><input onclick='toggleSelectRow(this);'
1a7572cb 2019 type=\"checkbox\" id=\"UMCHK-$uid\"></td>";
e6cb77a0
AD
2020
2021 print "<td><a href=\"javascript:editUser($uid);\">" .
2022 $line["login"] . "</td>";
2023
2024 print "<td><a href=\"javascript:editUser($uid);\">" .
2025 $line["access_level"] . "</td>";
2026
2027 } else if ($uid != $edit_uid) {
2028
2029 print "<td><input disabled=\"true\" type=\"checkbox\"
2030 id=\"UMCHK-".$line["id"]."\"></td>";
2031
2032 print "<td>".$line["login"]."</td>";
2033 print "<td>".$line["access_level"]."</td>";
2034
2035 } else {
2036
2037 print "<td><input disabled=\"true\" type=\"checkbox\" checked></td>";
2038
2039 print "<td><input id=\"iedit_ulogin\" value=\"".$line["login"].
2040 "\"></td>";
2041
2042 print "<td><input id=\"iedit_ulevel\" value=\"".$line["access_level"].
2043 "\"></td>";
2044
2045 }
2046
f6f32198
AD
2047 print "<td>".$line["last_login"]."</td>";
2048
e6cb77a0
AD
2049 print "</tr>";
2050
2051 ++$lnum;
2052 }
2053
2054 print "</table>";
2055
2056 print "<p>";
2057
2058 if ($subop == "edit") {
2059 print "Edit label:
2060 <input type=\"submit\" class=\"button\"
2061 onclick=\"javascript:userEditCancel()\" value=\"Cancel\">
2062 <input type=\"submit\" class=\"button\"
2063 onclick=\"javascript:userEditSave()\" value=\"Save\">";
2064
2065 } else {
2066
2067 print "
2068 Selection:
2069 <input type=\"submit\" class=\"button\"
717f5e64 2070 onclick=\"javascript:selectedUserDetails()\" value=\"User details\">
e6cb77a0
AD
2071 <input type=\"submit\" class=\"button\"
2072 onclick=\"javascript:editSelectedUser()\" value=\"Edit\">
2073 <input type=\"submit\" class=\"button\"
717f5e64
AD
2074 onclick=\"javascript:removeSelectedUsers()\" value=\"Remove\">
2075 <input type=\"submit\" class=\"button\"
2076 onclick=\"javascript:resetSelectedUserPass()\" value=\"Reset password\">";
2077
2078 }
2079 }
2080
2081 if ($op == "user-details") {
2082
2083 if (WEB_DEMO_MODE || $_SESSION["access_level"] < 10) {
2084 return;
2085 }
2086
1a7572cb 2087/* print "<html><head>
717f5e64
AD
2088 <title>Tiny Tiny RSS : User Details</title>
2089 <link rel=\"stylesheet\" href=\"tt-rss.css\" type=\"text/css\">
2090 <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\">
1a7572cb 2091 </head><body>"; */
717f5e64
AD
2092
2093 $uid = sprintf("%d", $_GET["id"]);
2094
c6c3a07f 2095 print "<div class='infoBoxContents'>";
717f5e64 2096
c6c3a07f
AD
2097 $result = db_query($link, "SELECT login,last_login,access_level,
2098 (SELECT COUNT(int_id) FROM ttrss_user_entries
2099 WHERE owner_uid = id) AS stored_articles
717f5e64
AD
2100 FROM ttrss_users
2101 WHERE id = '$uid'");
2102
2103 if (db_num_rows($result) == 0) {
2104 print "<h1>User not found</h1>";
2105 return;
2106 }
2107
2108 print "<h1>User Details</h1>";
2109
2110 print "<table width='100%'>";
2111
2112 $login = db_fetch_result($result, 0, "login");
2113 $last_login = db_fetch_result($result, 0, "last_login");
2114 $access_level = db_fetch_result($result, 0, "access_level");
c6c3a07f 2115 $stored_articles = db_fetch_result($result, 0, "stored_articles");
717f5e64
AD
2116
2117 print "<tr><td>Username</td><td>$login</td></tr>";
2118 print "<tr><td>Access level</td><td>$access_level</td></tr>";
2119 print "<tr><td>Last logged in</td><td>$last_login</td></tr>";
c6c3a07f 2120 print "<tr><td>Stored articles</td><td>$stored_articles</td></tr>";
717f5e64
AD
2121
2122 $result = db_query($link, "SELECT COUNT(id) as num_feeds FROM ttrss_feeds
2123 WHERE owner_uid = '$uid'");
2124
2125 $num_feeds = db_fetch_result($result, 0, "num_feeds");
2126
2127 print "<tr><td>Subscribed feeds count</td><td>$num_feeds</td></tr>";
2128
5d15d3ea 2129/* $result = db_query($link, "SELECT
717f5e64 2130 SUM(LENGTH(content)+LENGTH(title)+LENGTH(link)+LENGTH(guid)) AS db_size
c6c3a07f
AD
2131 FROM ttrss_user_entries,ttrss_entries
2132 WHERE owner_uid = '$uid' AND ref_id = id");
717f5e64 2133
d9f115c3 2134 $db_size = round(db_fetch_result($result, 0, "db_size") / 1024);
717f5e64 2135
c6c3a07f 2136 print "<tr><td>Approx. used DB size</td><td>$db_size KBytes</td></tr>"; */
717f5e64
AD
2137
2138 print "</table>";
2139
2140 print "<h1>Subscribed feeds</h1>";
2141
2142 $result = db_query($link, "SELECT id,title,feed_url FROM ttrss_feeds
d9f115c3 2143 WHERE owner_uid = '$uid' ORDER BY title");
717f5e64
AD
2144
2145 print "<ul class=\"nomarks\">";
2146
2147 while ($line = db_fetch_assoc($result)) {
2148
2149 $icon_file = ICONS_URL."/".$line["id"].".ico";
2150
2151 if (file_exists($icon_file) && filesize($icon_file) > 0) {
6c56687e 2152 $feed_icon = "<img class=\"tinyFeedIcon\" src=\"$icon_file\">";
717f5e64
AD
2153 } else {
2154 $feed_icon = "<img class=\"feedIcon\" src=\"images/blank_icon.gif\">";
2155 }
2156
2157 print "<li>$feed_icon&nbsp;<a href=\"".$line["feed_url"]."\">".$line["title"]."</a></li>";
e6cb77a0 2158 }
717f5e64
AD
2159
2160 print "</ul>";
2161
717f5e64
AD
2162 print "</div>";
2163
1a7572cb
AD
2164 print "<div align='center'>
2165 <input type='submit' class='button'
c6c3a07f 2166 onclick=\"closeInfoBox()\" value=\"Close this window\"></div>";
1a7572cb
AD
2167
2168// print "</body></html>";
717f5e64 2169
e6cb77a0
AD
2170 }
2171
c6c3a07f
AD
2172 if ($op == "feed-details") {
2173
2174 $feed_id = $_GET["id"];
2175
2176 $result = db_query($link,
2177 "SELECT
2178 title,feed_url,last_updated,
2179 (SELECT COUNT(int_id) FROM ttrss_user_entries
2180 WHERE feed_id = id) AS total,
2181 (SELECT COUNT(int_id) FROM ttrss_user_entries
2182 WHERE feed_id = id AND unread = true) AS unread,
2183 (SELECT COUNT(int_id) FROM ttrss_user_entries
2184 WHERE feed_id = id AND marked = true) AS marked
2185 FROM ttrss_feeds
2186 WHERE id = '$feed_id' AND owner_uid = ".$_SESSION["uid"]);
2187
2188 if (db_num_rows($result) == 0) return;
2189
2190 $title = db_fetch_result($result, 0, "title");
2191 $last_updated = db_fetch_result($result, 0, "last_updated");
2192 $feed_url = db_fetch_result($result, 0, "feed_url");
2193 $total = db_fetch_result($result, 0, "total");
2194 $unread = db_fetch_result($result, 0, "unread");
2195 $marked = db_fetch_result($result, 0, "marked");
2196
2197 print "<div class=\"infoBoxContents\"><h1>$title</h1>";
2198
2199 print "<table width='100%'>";
2200
2201 print "<tr><td>Feed URL</td><td><a href=\"$feed_url\">$feed_url</a></td></tr>";
2202 print "<tr><td>Last updated</td><td>$last_updated</td></tr>";
2203 print "<tr><td>Total articles</td><td>$total</td></tr>";
2204 print "<tr><td>Unread articles</td><td>$unread</td></tr>";
2205 print "<tr><td>Starred articles</td><td>$marked</td></tr>";
2206
2207 print "</table>";
2208
2209 print "</div>";
2210
2211 print "<div align='center'>
2212 <input type='submit' class='button'
2213 onclick=\"closeInfoBox()\" value=\"Close this window\"></div>";
2214
2215 }
2216
4b3dff6e 2217 db_close($link);
1cd17194 2218?>
406d9489
AD
2219
2220<!-- <?= sprintf("Backend execution time: %.4f seconds", getmicrotime() - $script_started) ?> -->
2221