diff -r 0944c9354e9c -r 7c6e2e97aa08 plugins/gallery/browser.php --- a/plugins/gallery/browser.php Sat Aug 21 23:25:41 2010 -0400 +++ b/plugins/gallery/browser.php Sat Aug 21 23:32:06 2010 -0400 @@ -27,446 +27,447 @@ class SnaprFormatter { - - /** - * Main render method, called from pagination function - * @access private - */ - - function render($column_crap, $row, $row_crap = false) - { - global $db, $session, $paths, $template, $plugins; // Common objects - - $out = '
' . print_r(gallery_folder_hierarchy(), true) . ''); - - $sort_column = ( isset($_GET['sort']) && in_array($_GET['sort'], array('img_title', 'img_time_upload', 'img_time_mod')) ) ? $_GET['sort'] : 'img_title'; - $sort_order = ( isset($_GET['order']) && in_array($_GET['order'], array('ASC', 'DESC')) ) ? $_GET['order'] : 'ASC'; - - // Determine number of pictures per page - $template->load_theme(); - - $where = 'WHERE folder_parent IS NULL ' . "\n ORDER BY is_folder DESC, $sort_column $sort_order, img_title ASC"; - $parms = $paths->getAllParams(); - - $sql = "SELECT img_id, img_title, is_folder, 'NULL' AS folder_id FROM ".table_prefix."gallery $where;"; - - // Breadcrumb browser - $breadcrumbs = array(); - $breadcrumbs[] = 'Gallery index'; - - $breadcrumb_urlcache = ''; - - // CSS for gallery browser - // Moved to search.php - //$template->add_header(''); - //$template->add_header(''); - - $header = $template->getHeader(); - - if ( !empty($parms) ) - { - $parms = dirtify_page_id($parms); - if ( strstr($parms, '/') ) - { - $folders = explode('/', $parms); - } - else - { - $folders = array(0 => $parms); - } - foreach ( $folders as $i => $_crap ) - { - $folder =& $folders[$i]; - - $f_url = sanitize_page_id($folder); - $breadcrumb_urlcache .= '/' . $f_url; - $breadcrumb_url = makeUrlNS('Special', 'Gallery' . $breadcrumb_urlcache); - - $folder = str_replace('_', ' ', $folder); - - if ( $i == ( count($folders) - 1 ) ) - { - $breadcrumbs[] = htmlspecialchars($folder); - } - else - { - $breadcrumbs[] = '' . htmlspecialchars($folder) . ''; - } - } - unset($folder); - $folders = array_reverse($folders); - // This is one of the best MySQL tricks on the market. We're going to reverse-travel a folder path using LEFT JOIN and the incredible power of metacoded SQL - $sql = 'SELECT gm.img_id, gm.img_title, gm.is_folder, g0.img_title AS folder_name, g0.img_id AS folder_id FROM '.table_prefix.'gallery AS gm' . "\n " . 'LEFT JOIN '.table_prefix.'gallery AS g0' . "\n " . 'ON ( gm.folder_parent = g0.img_id )'; - $where = "\n " . 'WHERE g0.img_title=\'' . $db->escape($folders[0]) . '\''; - foreach ( $folders as $i => $folder ) - { - if ( $i == 0 ) - continue; - $i_dec = $i - 1; - $folder = $db->escape($folder); - $sql .= "\n LEFT JOIN ".table_prefix."gallery AS g{$i}\n ON ( g{$i}.img_id=g{$i_dec}.folder_parent AND g{$i}.img_title='$folder' )"; - $where .= "\n ".'AND g'.$i.'.img_id IS NOT NULL'; - } - $where .= "\n AND g{$i}.folder_parent IS NULL"; - $sql .= $where . "\n ORDER BY is_folder DESC, gm.$sort_column $sort_order, gm.img_title ASC" . ';'; - } - - $img_query = $db->sql_query($sql); - if ( !$img_query ) - $db->_die('The folder ID could not be selected.'); - - if ( $db->numrows() < 1 ) - { - // Nothing in this folder, for one of two reasons: - // 1) The folder doesn't exist - // 2) The folder exists but doesn't have any images in it - - if ( sizeof($folders) < 1 ) - { - // Nothing in the root folder - - $first_row['folder_id'] = 'NULL'; - if ( $session->user_level >= USER_LEVEL_ADMIN && isset($_POST['create_folder']) && isset($first_row['folder_id']) ) - { - if ( empty($_POST['create_folder']) ) - { - $f_errors[] = 'Please enter a folder name.'; - } - if ( $_POST['create_folder'] == '_id' ) - { - $f_errors[] = 'The name "_id" is reserved for internal functions and cannot be used on any image or folder.'; - } - if ( count($f_errors) < 1 ) - { - $q = $db->sql_query('INSERT INTO '.table_prefix.'gallery(img_title, is_folder, folder_parent) VALUES(\'' . $db->escape($_POST['create_folder']) . '\', 1, ' . $first_row['folder_id'] . ');'); - if ( !$q ) - $db->_die(); - redirect(makeUrl($paths->fullpage), 'Folder created', 'The folder "' . htmlspecialchars($_POST['create_folder']) . '" has been created. Redirecting to last viewed folder...', 2); - } - } - - $html = ''; - if ( $session->user_level >= USER_LEVEL_ADMIN ) - { - $html .= ''; - $html .= '
No images have been uploaded to the gallery yet.
' . $html); - } - - /* - $folders_old = $folders; - $folders = array( - 0 => $folders_old[0] - ); - $x = $folders_old; - unset($x[0]); - $folders = array_merge($folders, $x); - unset($x); - */ - // die('' . print_r($folders, true) . ''); - - // This next query will try to determine if the folder itself exists - $sql = 'SELECT g0.img_id, g0.img_title FROM '.table_prefix.'gallery AS g0'; - $where = "\n " . 'WHERE g0.img_title=\'' . $db->escape($folders[0]) . '\''; - foreach ( $folders as $i => $folder ) - { - if ( $i == 0 ) - continue; - $i_dec = $i - 1; - $folder = $db->escape($folder); - $sql .= "\n LEFT JOIN ".table_prefix."gallery AS g{$i}\n ON ( g{$i}.img_id=g{$i_dec}.folder_parent AND g{$i}.img_title='$folder' )"; - $where .= "\n ".'AND g'.$i.'.img_id IS NOT NULL'; - } - $where .= "\n AND g{$i}.folder_parent IS NULL"; - $where .= "\n AND g0.is_folder=1"; - $sql .= $where . ';'; - - $nameq = $db->sql_query($sql); - if ( !$nameq ) - $db->_die(); - - if ( $db->numrows($nameq) < 1 ) - { - die_friendly('Folder not found', '
The folder you requested doesn\'t exist. Please check the URL and try again, or return to the gallery index.
'); - } - - $row = $db->fetchrow($nameq); - - // Generate title - $title = dirtify_page_id($row['img_title']); - $title = str_replace('_', ' ', $title); - $title = htmlspecialchars($title); - - $template->tpl_strings['PAGE_NAME'] = $title; - - $first_row = $row; - - if ( $db->numrows($img_query) > 0 ) - $db->sql_data_seek(0, $img_query); - - /* $folders = $folders_old; */ - } - else if ( !empty($parms) ) - { - $row = $db->fetchrow($img_query); - $first_row = $row; - - // Generate title - $title = htmlspecialchars($row['folder_name']); - - $template->tpl_strings['PAGE_NAME'] = $title; - - $db->sql_data_seek(0, $img_query); - } - else - { - $row = $db->fetchrow($img_query); - $first_row = $row; - - $template->tpl_strings['PAGE_NAME'] = 'Image Gallery'; - $breadcrumbs = array('Gallery index'); - - $db->sql_data_seek(0, $img_query); - } - - $f_errors = array(); - - if ( $session->user_level >= USER_LEVEL_ADMIN && isset($_POST['create_folder']) ) - { - if ( !isset($first_row['folder_id']) ) - { - //die('FALLING' . print_r($first_row, true) . ''); - $first_row['folder_id'] =& $first_row['img_id']; - } - if ( !isset($first_row['folder_id']) ) - { - $f_errors[] = 'Internal error getting parent folder ID'; - } - if ( empty($_POST['create_folder']) ) - { - $f_errors[] = 'Please enter a folder name.'; - } - if ( $_POST['create_folder'] == '_id' ) - { - $f_errors[] = 'The name "_id" is reserved for internal functions and cannot be used on any image or folder.'; - } - if ( count($f_errors) < 1 ) - { - $q = $db->sql_query('INSERT INTO '.table_prefix.'gallery(img_title, is_folder, folder_parent) VALUES(\'' . $db->escape($_POST['create_folder']) . '\', 1, ' . $first_row['folder_id'] . ');'); - if ( !$q ) - $db->_die(); - redirect(makeUrl($paths->fullpage), 'Folder created', 'The folder "' . htmlspecialchars($_POST['create_folder']) . '" has been created. Redirecting to last viewed folder...', 2); - } - } - - echo $header; - - if ( count($f_errors) > 0 ) - { - echo '
' . var_dump($row) . $db->sql_backtrace() . ''); - if ( !$row['img_id'] ) - break; - $all_list[] = $row['img_id']; - if ( $row['is_folder'] == 1 ) - $fol_list[] = $row['img_id']; - else - $img_list[] = $row['img_id']; - } - while ( $row = $db->fetchrow($img_query) ); - - $all_list = implode(',', $all_list); - $fol_list = implode(',', $fol_list); - $img_list = implode(',', $img_list); - - if ( !empty($all_list) ) - { - echo '
' . print_r(gallery_folder_hierarchy(), true) . ''); + + $sort_column = ( isset($_GET['sort']) && in_array($_GET['sort'], array('img_title', 'img_time_upload', 'img_time_mod')) ) ? $_GET['sort'] : 'img_title'; + $sort_order = ( isset($_GET['order']) && in_array($_GET['order'], array('ASC', 'DESC')) ) ? $_GET['order'] : 'ASC'; + + // Determine number of pictures per page + $template->load_theme(); + + $where = 'WHERE folder_parent IS NULL ' . "\n ORDER BY is_folder DESC, $sort_column $sort_order, img_title ASC"; + $parms = $paths->getAllParams(); + + $sql = "SELECT img_id, img_title, is_folder, 'NULL' AS folder_id FROM ".table_prefix."gallery $where;"; + + // Breadcrumb browser + $breadcrumbs = array(); + $breadcrumbs[] = 'Gallery index'; + + $breadcrumb_urlcache = ''; + + // CSS for gallery browser + // Moved to search.php + //$template->add_header(''); + //$template->add_header(''); + + $header = $template->getHeader(); + + $folders = $f_errors = array(); + if ( !empty($parms) ) + { + $parms = dirtify_page_id($parms); + if ( strstr($parms, '/') ) + { + $folders = explode('/', $parms); + } + else + { + $folders = array(0 => $parms); + } + foreach ( $folders as $i => $_crap ) + { + $folder =& $folders[$i]; + + $f_url = sanitize_page_id($folder); + $breadcrumb_urlcache .= '/' . $f_url; + $breadcrumb_url = makeUrlNS('Special', 'Gallery' . $breadcrumb_urlcache); + + $folder = str_replace('_', ' ', $folder); + + if ( $i == ( count($folders) - 1 ) ) + { + $breadcrumbs[] = htmlspecialchars($folder); + } + else + { + $breadcrumbs[] = '' . htmlspecialchars($folder) . ''; + } + } + unset($folder); + $folders = array_reverse($folders); + // This is one of the best MySQL tricks on the market. We're going to reverse-travel a folder path using LEFT JOIN and the incredible power of metacoded SQL + $sql = 'SELECT gm.img_id, gm.img_title, gm.is_folder, g0.img_title AS folder_name, g0.img_id AS folder_id FROM '.table_prefix.'gallery AS gm' . "\n " . 'LEFT JOIN '.table_prefix.'gallery AS g0' . "\n " . 'ON ( gm.folder_parent = g0.img_id )'; + $where = "\n " . 'WHERE g0.img_title=\'' . $db->escape($folders[0]) . '\''; + foreach ( $folders as $i => $folder ) + { + if ( $i == 0 ) + continue; + $i_dec = $i - 1; + $folder = $db->escape($folder); + $sql .= "\n LEFT JOIN ".table_prefix."gallery AS g{$i}\n ON ( g{$i}.img_id=g{$i_dec}.folder_parent AND g{$i}.img_title='$folder' )"; + $where .= "\n ".'AND g'.$i.'.img_id IS NOT NULL'; + } + $where .= "\n AND g{$i}.folder_parent IS NULL"; + $sql .= $where . "\n ORDER BY is_folder DESC, gm.$sort_column $sort_order, gm.img_title ASC" . ';'; + } + + $img_query = $db->sql_query($sql); + if ( !$img_query ) + $db->_die('The folder ID could not be selected.'); + + if ( $db->numrows() < 1 ) + { + // Nothing in this folder, for one of two reasons: + // 1) The folder doesn't exist + // 2) The folder exists but doesn't have any images in it + + if ( count($folders) < 1 ) + { + // Nothing in the root folder + + $first_row['folder_id'] = 'NULL'; + if ( $session->user_level >= USER_LEVEL_ADMIN && isset($_POST['create_folder']) && isset($first_row['folder_id']) ) + { + if ( empty($_POST['create_folder']) ) + { + $f_errors[] = 'Please enter a folder name.'; + } + if ( $_POST['create_folder'] == '_id' ) + { + $f_errors[] = 'The name "_id" is reserved for internal functions and cannot be used on any image or folder.'; + } + if ( count($f_errors) < 1 ) + { + $q = $db->sql_query('INSERT INTO '.table_prefix.'gallery(img_title, is_folder, folder_parent, img_author) VALUES(\'' . $db->escape($_POST['create_folder']) . '\', 1, ' . $first_row['folder_id'] . ', ' . $session->user_id . ');'); + if ( !$q ) + $db->_die(); + redirect(makeUrl($paths->fullpage), 'Folder created', 'The folder "' . htmlspecialchars($_POST['create_folder']) . '" has been created. Redirecting to last viewed folder...', 2); + } + } + + $html = ''; + if ( $session->user_level >= USER_LEVEL_ADMIN ) + { + $html .= ''; + $html .= '
No images have been uploaded to the gallery yet.
' . $html); + } + + /* + $folders_old = $folders; + $folders = array( + 0 => $folders_old[0] + ); + $x = $folders_old; + unset($x[0]); + $folders = array_merge($folders, $x); + unset($x); + */ + // die('' . print_r($folders, true) . ''); + + // This next query will try to determine if the folder itself exists + $sql = 'SELECT g0.img_id, g0.img_title FROM '.table_prefix.'gallery AS g0'; + $where = "\n " . 'WHERE g0.img_title=\'' . $db->escape($folders[0]) . '\''; + foreach ( $folders as $i => $folder ) + { + if ( $i == 0 ) + continue; + $i_dec = $i - 1; + $folder = $db->escape($folder); + $sql .= "\n LEFT JOIN ".table_prefix."gallery AS g{$i}\n ON ( g{$i}.img_id=g{$i_dec}.folder_parent AND g{$i}.img_title='$folder' )"; + $where .= "\n ".'AND g'.$i.'.img_id IS NOT NULL'; + } + $where .= "\n AND g{$i}.folder_parent IS NULL"; + $where .= "\n AND g0.is_folder=1"; + $sql .= $where . ';'; + + $nameq = $db->sql_query($sql); + if ( !$nameq ) + $db->_die(); + + if ( $db->numrows($nameq) < 1 ) + { + die_friendly('Folder not found', '
The folder you requested doesn\'t exist. Please check the URL and try again, or return to the gallery index.
'); + } + + $row = $db->fetchrow($nameq); + + // Generate title + $title = dirtify_page_id($row['img_title']); + $title = str_replace('_', ' ', $title); + $title = htmlspecialchars($title); + + $template->tpl_strings['PAGE_NAME'] = $title; + + $first_row = $row; + + if ( $db->numrows($img_query) > 0 ) + $db->sql_data_seek(0, $img_query); + + /* $folders = $folders_old; */ + } + else if ( !empty($parms) ) + { + $row = $db->fetchrow($img_query); + $first_row = $row; + + // Generate title + $title = htmlspecialchars($row['folder_name']); + + $template->tpl_strings['PAGE_NAME'] = $title; + + $db->sql_data_seek(0, $img_query); + } + else + { + $row = $db->fetchrow($img_query); + $first_row = $row; + + $template->tpl_strings['PAGE_NAME'] = 'Image Gallery'; + $breadcrumbs = array('Gallery index'); + + $db->sql_data_seek(0, $img_query); + } + + $f_errors = array(); + + if ( $session->user_level >= USER_LEVEL_ADMIN && isset($_POST['create_folder']) ) + { + if ( !isset($first_row['folder_id']) ) + { + //die('FALLING' . print_r($first_row, true) . ''); + $first_row['folder_id'] =& $first_row['img_id']; + } + if ( !isset($first_row['folder_id']) ) + { + $f_errors[] = 'Internal error getting parent folder ID'; + } + if ( empty($_POST['create_folder']) ) + { + $f_errors[] = 'Please enter a folder name.'; + } + if ( $_POST['create_folder'] == '_id' ) + { + $f_errors[] = 'The name "_id" is reserved for internal functions and cannot be used on any image or folder.'; + } + if ( count($f_errors) < 1 ) + { + $q = $db->sql_query('INSERT INTO '.table_prefix.'gallery(img_title, is_folder, folder_parent, img_author) VALUES(\'' . $db->escape($_POST['create_folder']) . '\', 1, ' . $first_row['folder_id'] . ', ' . $session->user_id . ');'); + if ( !$q ) + $db->_die(); + redirect(makeUrl($paths->fullpage), 'Folder created', 'The folder "' . htmlspecialchars($_POST['create_folder']) . '" has been created. Redirecting to last viewed folder...', 2); + } + } + + echo $header; + + if ( count($f_errors) > 0 ) + { + echo '
' . var_dump($row) . $db->sql_backtrace() . ''); + if ( !$row['img_id'] ) + break; + $all_list[] = $row['img_id']; + if ( $row['is_folder'] == 1 ) + $fol_list[] = $row['img_id']; + else + $img_list[] = $row['img_id']; + } + while ( $row = $db->fetchrow($img_query) ); + + $all_list = implode(',', $all_list); + $fol_list = implode(',', $fol_list); + $img_list = implode(',', $img_list); + + if ( !empty($all_list) ) + { + echo '