Файл: world-faces.ru/world-faces.ru/frend_new.php
Строк: 156
<?php
include_once 'sys/inc/start.php';
include_once 'sys/inc/compress.php';
include_once 'sys/inc/sess.php';
include_once 'sys/inc/home.php';
include_once 'sys/inc/settings.php';
include_once 'sys/inc/db_connect.php';
include_once 'sys/inc/ipua.php';
include_once 'sys/inc/fnc.php';
include_once 'sys/inc/user.php';
only_reg();
$ank['id'] = $user['id'];
$ok = (isset($_GET['ok'])) ? $_GET['ok'] : NULL;
if(isset($ok)){
$ok = intval($ok);
if(mysql_result(mysql_query("SELECT COUNT(*) FROM `user` WHERE `id` = '".$ok."' LIMIT 1"),0)==0){
header("Location: /index.php");
exit;
}
mysql_query("INSERT INTO `frends` (`user`, `frend`, `time`, `i`) values('".$ank['id']."', '".$ok."', '".$time."', '1')");
mysql_query("INSERT INTO `frends` (`user`, `frend`, `time`, `i`) values('".$ok."', '".$ank['id']."', '".$time."', '1')");
$ot=$user[id];
$to=$ank[id];
$emsg='теперь друг с id ';
$lool=drug;
mysql_query("INSERT INTO `lenta_saita` (`user`, `to_user`, `action`, `time`,`type`) values('$user[nick]', '".$ok."', '$emsg', '$time','$lool')");
mysql_query("DELETE FROM `frends_new` WHERE `user` = '".$ok."' AND `to` = '".$user['id']."' LIMIT 1");
mysql_query("DELETE FROM `frends_new` WHERE `user` = '".$user['id']."' AND `to` = '".$ok."' LIMIT 1");
$msgok = 'Поздравляем! обитатель [b]'.$user['nick'].'[/b] принял ваше предложение дружбы';
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values('0', '".$ok."', '".$msgok."', '".$time."')");
mysql_query("OPTIMIZE TABLE `frends`, `frends_new`, `jurnal`");
header("Location: /frend.php");
exit;
}
$no = (isset($_GET['no'])) ? $_GET['no'] : NULL;
if(isset($no)){
$no = intval($no);
if(mysql_result(mysql_query("SELECT COUNT(*) FROM `user` WHERE `id` = '".$no."' LIMIT 1"),0)==0){
header("Location: /index.php");
exit;
}
mysql_query("DELETE FROM `frends` WHERE `user` = '".$user['id']."' AND `frend` = '".$no."' LIMIT 1");
mysql_query("DELETE FROM `frends` WHERE `user` = '".$no."' AND `frend` = '".$user['id']."' LIMIT 1");
mysql_query("DELETE FROM `frends_new` WHERE `user` = '".$no."' AND `to` = '".$user['id']."' LIMIT 1");
mysql_query("DELETE FROM `frends_new` WHERE `user` = '".$user['id']."' AND `to` = '".$no."' LIMIT 1");
$msgno = 'К сожалению, обитатель [b]'.$user['nick'].'[/b] отказал вам в предложение дружбы!';
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values('0', '".$no."', '".$msgno."', '".$time."')");
mysql_query("OPTIMIZE TABLE `frends`, `frends_new`, `jurnal`");
header("Location: /frend_new.php");
exit;
}
$del = (isset($_GET['del'])) ? $_GET['del'] : NULL;
if(isset($del)){
$no = intval($del);
if(mysql_result(mysql_query("SELECT COUNT(*) FROM `user` WHERE `id` = '".$no."' LIMIT 1"),0)==0){
header("Location: /index.php");
exit;
}
mysql_query("DELETE FROM `frends` WHERE `user` = '".$user['id']."' AND `frend` = '".$no."' LIMIT 1");
mysql_query("DELETE FROM `frends` WHERE `user` = '".$no."' AND `frend` = '".$user['id']."' LIMIT 1");
$lol=rand(1,10000000);
$ot=$user[id];
$to=$ank[id];
$emsg='больше не друг с id ';
$lool=drug;
mysql_query("INSERT INTO `lenta_saita` (`id`, `user`, `to_user`, `action`, `time`,`type`) values('$lol', '$user[nick]', '".$no."', '$emsg', '$time','$lool')");
mysql_query("DELETE FROM `frends_new` WHERE `user` = '".$no."' AND `to` = '".$user['id']."' LIMIT 1");
mysql_query("DELETE FROM `frends_new` WHERE `user` = '".$user['id']."' AND `to` = '".$no."' LIMIT 1");
$msgno = 'К сожалению, обитатель [b]'.$user['nick'].'[/b] удалил вас из списка друзей!';
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values('0', '".$no."', '".$msgno."', '".$time."')");
mysql_query("OPTIMIZE TABLE `frends`, `frends_new`, `jurnal`");
header("Location: /frend.php");
exit;
}
$set['title'] = 'Список предложений дружбы & '.$_SERVER['HTTP_HOST'];
include_once 'sys/inc/thead.php';
title();
aut();
echo '<table class="post">';
if($ank['id']==$user['id']){
echo "<div class='gend'>";
echo '<img src="/img/tabor/add_frends.gif" alt=""/> <a href="/frend.php">Мои друзья</a></div>';
echo "</div>";
}
$m = date('m',$time);
if(substr($m,0,1)==0){
$m = str_replace('0','',$m);
}
$d = date('d',$time);
$k_f = mysql_result(mysql_query("SELECT COUNT(id) FROM `frends_new` WHERE `to` = '".$user['id']."' LIMIT 1"),0);
if($k_f==0){
echo '<div class="p_m">Нет предложений на дружбу</div>';
}
$q = mysql_query("SELECT * FROM `frends_new` WHERE `to` = '".$user['id']."' ORDER BY time DESC");
while($f = mysql_fetch_array($q)){
$a = mysql_fetch_array(mysql_query("SELECT * FROM `user` WHERE `id` = '".$f['user']."' LIMIT 1"));
echo '<tr><td class="icon48" >';
echo avatar2($a['id']);
echo '</td><td class="p_m"> '.online($a['id']).' <a href="/info.php?id='.$a['id'].'">'.$a['nick'].'</a> ('.vremja($f['time']).')<br/>';
echo '<a href="/frend_new.php?ok='.$a['id'].'">Принять</a> / <a href="/frend_new.php?no='.$a['id'].'">Отклонить</a></td></tr>';
}
echo '</table>';
echo '</div>';
include_once 'sys/inc/tfoot.php';
?>