Файл: podarki/gifts.php
Строк: 188
<?
include_once '../sys/inc/start.php';
include_once '../sys/inc/compress.php';
include_once '../sys/inc/sess.php';
include_once '../sys/inc/home.php';
include_once '../sys/inc/settings.php';
include_once '../sys/inc/db_connect.php';
include_once '../sys/inc/ipua.php';
include_once '../sys/inc/fnc.php';
include_once '../sys/inc/user.php';
if (!isset($user) && !isset($_GET['id'])){header("Location: /index.php?".SID);exit;}
if (isset($user))$ank['id']=$user['id'];
if (isset($_GET['id']))$ank['id']=intval($_GET['id']);
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `user` WHERE `id` = '$ank[id]' LIMIT 1"),0)==0){header("Location: /index.php?".SID);exit;}
$ank=mysql_fetch_array(mysql_query("SELECT * FROM `user` WHERE `id` = $ank[id] LIMIT 1"));
if ((!isset($_SESSION['refer']) || $_SESSION['refer']==NULL)
&& isset($_SERVER['HTTP_REFERER']) && $_SERVER['HTTP_REFERER']!=NULL &&
!ereg('gifts.php',$_SERVER['HTTP_REFERER']))
$_SESSION['refer']=str_replace('&','&',ereg_replace('^http://[^/]*/','/', $_SERVER['HTTP_REFERER']));
if (isset($user))
{
$p = (isset($_GET['p'])) ? htmlspecialchars($_GET['p']) : null;
switch($p){
case 'send_gifts':
include_once '../sys/inc/thead.php';
$set['title']='Отправить подарок'; // заголовок страницы
title();
aut();
$pid = intval($_GET['pid']);
if (isset($_GET['go'])){
$curr=date("d.m.y / H:i");
$balls = 50;
if (isset($_POST['msg']) && strlen2($_POST['msg'])<=512)
{
if (preg_match('#[^A-zА-я0-9 _-=+()*?.,]#ui',$_POST['msg'])) msg ('В поле "Ваше сообщение" используются запрещенные символы');
else {
$msg=$_POST['msg'];
}
}
else msg ('Ваше сообщение нужно писать меньше :)');
$ank['id'];
if($ank==0){
msg ('Пользователь не найден :(');
}else{if (isset($user) & $user['balls']<=$balls){
msg ('У Вас не достаточно денег :(');}else{
////////////////////
mysql_query("UPDATE `user` SET `balls` = '".($user['balls']-$balls)."' WHERE `id` = '$user[id]' LIMIT 1",$db);
////////////////////
mysql_query("INSERT INTO `fin_oper` (`user`, `oper`, `time`, `cena`) values('$user[id]', 'Отправлен подарок $balls KM для $ank[nick]', '$time', '$balls')",$db);
////////////////////
mysql_query("INSERT INTO `gifts` (`id_user`, `ot_id`, `text`, `time`, `id_gifts`) values('$ank[id]', '$user[id]', '$msg', '$time', '$pid')",$db);
////////////////////
$msgrat="К вам пришёл подарок от $user[nick]!";
mysql_query("INSERT INTO `jurnal` (`id_user`, `id_kont`, `msg`, `time`) values('0', '$ank[id]', '$msgrat', '$time')");
msg ('Отправка подарка успешно завершена');
}}
include_once '../sys/inc/tfoot.php';}
echo"<img src='/gifts/".$pid.".png' alt='' class='icon'/>";
echo "<form method="post" action="gifts.php?p=send_gifts&id=$ank[id]&pid=".htmlentities($_GET['pid'])."&go">";
echo "Получатель:<b> $ank[nick]</b><br/><br />n";
echo "Ваше сообщение:<br/>";
echo "<input type="text" name="msg" value=""/><br />rn";
echo "<input type="submit" value="Подарить" />";
echo "</form>n";
echo'<small>С вашего счета будет снято 50 баллов</small>';
include_once '../sys/inc/tfoot.php';
break;
}
$pod = (isset($_GET['pod'])) ? htmlspecialchars($_GET['pod']) : null;
$set['title']='Подарки';
include_once '../sys/inc/thead.php';
title();
aut();
////////////
switch($pod) {
case '1':
echo "<img src='/gifts/1.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=1">Кошка</a><br/>";
echo "<img src='/gifts/2.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=2">Призрак</a><br/>";
echo "<img src='/gifts/3.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=3">Емкость</a><br/>";
echo "<img src='/gifts/4.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=4">Череп</a><br/>";
echo "<img src='/gifts/5.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=5">Зонтик</a><br/>";
echo "<img src='/gifts/6.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=6">Лист</a><br/>";
echo "<img src='/gifts/7.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=7">Соль</a><br/>";
echo "<img src='/gifts/8.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=8">Пальма</a><br/>";
echo "<img src='/gifts/9.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=9">Акула</a><br/>";
echo "<img src='/gifts/10.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=10">Мотерброд</a><br/>";
echo "<img src='/gifts/11.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=11">Кукуруза</a><br/>";
echo "<br /><a href="gifts.php?id=$ank[id]&pod=2">Дальше</a>n";
break;
case '2':
echo "<img src='/gifts/12.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=12">Черт</a><br/>";
echo "<img src='/gifts/13.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=13">Жук</a><br/>";
echo "<img src='/gifts/14.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=14">Зайка</a><br/>";
echo "<img src='/gifts/15.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=15">Туфля</a><br/>";
echo "<img src='/gifts/16.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=16">Сигорета</a><br/>";
echo "<img src='/gifts/17.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=17">Пехаль</a><br/>";
echo "<img src='/gifts/18.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=18">Кепка</a><br/>";
echo "<img src='/gifts/19.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=19">Компас</a><br/>";
echo "<img src='/gifts/20.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=20">Дева</a><br/>";
echo "<img src='/gifts/21.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=21">Черепаха</a><br/>";
echo "<br /><a href="gifts.php?id=$ank[id]&pod=1">Назад |</a>n";
echo "<a href="gifts.php?id=$ank[id]&pod=3"> Дальше</a><br/>n";
break;
case '3':
echo "<img src='/gifts/22.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=22">Орех</a><br/>";
echo "<img src='/gifts/23.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=23">Супер</a><br/>";
echo "<img src='/gifts/24.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=24">Койка</a><br/>";
echo "<img src='/gifts/25.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=25">Автомат</a><br/>";
echo "<img src='/gifts/26.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=26">Цветы</a><br/>";
echo "<img src='/gifts/27.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=27">Шампанское</a><br/>";
echo "<img src='/gifts/28.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=28">Помада</a><br/>";
echo "<img src='/gifts/29.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gift&id=$ank[id]&p&id=29">Орден</a><br/>";
echo "<img src='/gifts/30.png' width='45' height='45' alt=''/> <a href="gifts.php?p=send_gifts&id=$ank[id]&pid=30">Изба</a><br/>";
echo "<br /><a href="gifts.php?id=$ank[id]&pod=2">Назад</a>n";
break;
}
}else{
include_once '../sys/inc/thead.php';
$set['title']='Отправить подарок'; // заголовок страницы
title();
aut();
echo'А тебе это и не нужно :) Зарегайся для начала!';}
include_once '../sys/inc/tfoot.php';
?>