Файл: modules/earn/check/vkfriend.php
Строк: 33
<?
mysql_query("INSERT INTO `done` (`social` ,`type` ,`uid` ,`tid`, `mode`) VALUES ('".$Task['social']."', '".$Task['type']."', '$uid', '$tid', 'done');");
$path = $aa['path'];
preg_match_all('#id([0-9]+)#',$path,$bb);
if($bb[1][0]){
$userid = $bb[1][0];
} else {
$userid = substr($path,1);
}
if(preg_match('#^[w-]+$#i',$userid)){
$res = Core::url_get_contents('https://api.vk.com/method/users.get?uids='.$userid.'&fields=uid');
$resp = json_decode($res, true);
$userid = $resp['response'][0]['uid'];
$res = Core::url_get_contents('https://api.vk.com/method/subscriptions.get?uid='.$CONFIG['Globals']['social:vk'].'&count=5&access_token='.$token);
$resp = json_decode($res, true);
$res2 = Core::url_get_contents('https://api.vk.com/method/friends.get?uid='.$CONFIG['Globals']['social:vk'].'&access_token='.$token.'×tamp='.time().'&random='.rand(0,10000));
$resp2 = json_decode($res2, true);
}
if(in_array($userid,$resp['response']['users']) || in_array($userid,$resp2['response'])){
echo Ajax::Responce(array('ok'));
$tid = $Task['id'];
$uid = $CONFIG['uid'];
Tasks::ChangeBal($tid,$Task['bal']-$Task['pay']);
mysql_query("UPDATE `users` SET `balance` = balance+".$Task['pay']." WHERE `id` =$uid;");
} else {
echo Ajax::Responce(array('err'));
mysql_query("DELETE FROM `done` WHERE `uid`='$uid' AND `tid`='$tid' AND `mode`='done';");
}