Файл: wap-ads.ru/chat.php
Строк: 84
<?php
if(isset($_GET['otvet']) && isset($user))
{
$otvett=mysql_fetch_array(mysql_query("SELECT * FROM `chat` WHERE `id` = '".intval($_GET['otvet'])."'"));
$title='Чат';
include_once 'h.php';
echo "<div class='list_item busis'>Ответ на сообщение ".nc($otvett['id_user']).":<div class='friends_access_list attach_block grey' style='position:relative;'>".output_text($otvett['text'])."</div>";
if(isset($_GET['okk']))
{
if(strlen2($_POST['opis'])<1){$err=1;err_game('Слишком короткий текст.');}
if(strlen2($_POST['opis'])>20000){$err=1;err_game('Текст привышает 50000 символов.');}
}
echo '<form action="?chat&otvet='.$otvett['id'].'&okk" method="post">';
echo '<textarea name="opis"></textarea><br/>';
echo '<br>';
echo '<input type="submit" value="Отправить"/>';
echo '</form>';
echo "</div>";
if(isset($_GET['okk']) && !isset($err)){
$opis=htmlspecialchars(mysql_real_escape_string(trim($_POST['opis'])));
mysql_query("INSERT INTO `chat` (`text`,`id_user`,`time`,`see`,`otvet`)VALUES('$opis','$user[id]','$time','0','$otvett[id]')");
header("Location:?chat");
}
include_once 'foot.php';
}
if(isset($_GET['del']) && isset($user) && $user['status']>=0 && $user['status']!=2 && mysql_result(mysql_query("SELECT COUNT(*) FROM `chat` WHERE `id` = '".intval($_GET['del'])."'"),0)!=0){
mysql_query("DELETE FROM `chat` WHERE `id` = '".intval($_GET['del'])."'");
header("Location:?chat".(isset($_GET['page'])?"&page=$_GET[page]":null)."");
}
if(isset($_GET['see']) && isset($user) && $user['status']>=0 && $user['status']!=2 && mysql_result(mysql_query("SELECT COUNT(*) FROM `chat` WHERE `id` = '".intval($_GET['see'])."'"),0)!=0){
$see=mysql_fetch_array(mysql_query("SELECT * FROM `chat` WHERE `id` = '".intval($_GET['see'])."'"));
mysql_query("UPDATE `chat` SET `see` = '".($see['see']==1?"0":"$user[id]")."' WHERE `id` = '".intval($_GET['see'])."'");
header("Location:?chat".(isset($_GET['page'])?"&page=$_GET[page]":null)."");
}
$num=0;
$title='Чат';
include_once 'h.php';
echo "<div class='linkes'><a href='?chat&refresh=".rand(100000,500000)."'><img src='/images/view-refresh_1973.png'> Обновить</a></div>";
if(isset($_GET['save1']) && isset($user))
{
if(strlen2($_POST['opis'])<1){$err=1;err_game('Слишком короткий текст.');}
if(strlen2($_POST['opis'])>20000){$err=1;err_game('Текст привышает 50000 символов.');}
}
if(isset($user))
{
echo "<div class='list_item busis'>";
echo '<form action="?chat&save1" method="post">';
echo '<textarea name="opis"></textarea><br/>';
echo '<br>';
echo '<input type="submit" value="Отправить"/>';
echo '</form>';
echo "</div>";
}
if(isset($_GET['save1']) && !isset($err) && isset($user)){
$opis=htmlspecialchars(mysql_real_escape_string(trim($_POST['opis'])));
mysql_query("INSERT INTO `chat` (`text`,`id_user`,`time`,`see`)VALUES('$opis','$user[id]','$time','0')");
header("Location:?chat");
}
$k_post = mysql_result(mysql_query("SELECT COUNT(*) FROM `chat`".($user['status']==0?" WHERE `see` = '0'":null).""),0);
$k_page=k_page($k_post,$set['p_str']);
$page=page($k_page);
$start=$set['p_str']*$page-$set['p_str'];
$q=mysql_query("SELECT * FROM `chat`".($user['status']==0?" WHERE `see` = '0'":null)." ORDER BY id desc LIMIT $start, $set[p_str]");
while($post=mysql_fetch_array($q))
{
$num++;
$otvet=mysql_fetch_array(mysql_query("SELECT * FROM `chat` WHERE `id` = '$post[otvet]'"));
$usotv=mysql_fetch_array(mysql_query("SELECT * FROM `users` WHERE `id` = '$otvet[id_user]'"));
echo "".($post['see']!=0?"<div class='list_item comment_block overfl_hid' style='background:#E8E3E3;'>":"<div id='298999220' class='list_item comment_block overfl_hid'>")."<div class='left font0 avatar_wrap' style='padding-right: 7px;'><img src='".(file_exists('images/ava/'.$post['id_user'].'.png')?"/images/ava/$post[id_user].png":"/images/noavatar.png")."' width='41' height='40'></div> <div class='overfl_hid'>".iconka($post['id_user'])." <a href='?user=$post[id_user]'>".nc($post['id_user'])."</a>".($otvet!=0 && $otvet['see']==0?" <span class='grey'>ответил".($usotv['pol']==0?"а":null)."</span> <a href='' class='spoiler_links'> ".$usotv['nick']."</a>":null)."<span class='comment_date middle'>".vremja($post['time'])."</span><div style='display: none;' class='spoiler_body attach_block grey friends_access_list'>".output_text($otvet['text'])."</div>".($post['see']!=0?"<div class='red_item pad_t_a'>Комментарий скрыт ".nc($post['see'])."</div>":null)."<div class='pad_t_a'>".output_text($post['text'])."</div>".(isset($user)?"<div class='pad_t_a'><a href='?chat&otvet=$post[id]".(isset($_GET['page'])?"&page=$_GET[page]":null)."'>Ответить</a>":null)."".($user['status']>=0 && $user['status']!=2?"<span style='float:right;'><a class='grey' href='?chat&see=$post[id]".(isset($_GET['page'])?"&page=$_GET[page]":null)."'>".($post['see']!=0?"Показать":"Скрыть")."</a>".($user['status']>=0 && $user['status']!=2?" | <a class='grey' href='?chat&del=$post[id]".(isset($_GET['page'])?"&page=$_GET[page]":null)."'>Удалить</a>":null)."</span>":null)."</div></div></div>";
}
if ($k_page>1)str("?chat&",$k_page,$page); // Вывод страниц
if(isset($_GET['save']) && isset($user))
{
if(strlen2($_POST['opis'])<1){$err=1;err_game('Слишком короткий текст.');}
if(strlen2($_POST['opis'])>20000){$err=1;err_game('Текст привышает 50000 символов.');}
}
if(isset($user) && $num>5)
{
echo "<div class='list_item busis'>";
echo '<form action="?chat&save" method="post">';
echo '<textarea name="opis"></textarea><br/>';
echo '<br>';
echo '<input type="submit" value="Отправить"/>';
echo '</form>';
echo "</div>";
}
if(isset($_GET['save']) && !isset($err) && isset($user)){
$opis=htmlspecialchars(mysql_real_escape_string(trim($_POST['opis'])));
mysql_query("INSERT INTO `chat` (`text`,`id_user`,`time`,`see`)VALUES('$opis','$user[id]','$time','0')");
header("Location:?chat");
}
echo "</div>";
include_once 'foot.php';
?>