Skip to content
Snippets Groups Projects
diary.module 12.9 KiB
Newer Older
Dries Buytaert's avatar
 
Dries Buytaert committed
<?php
Dries Buytaert's avatar
Dries Buytaert committed

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_perm() {
Dries Buytaert's avatar
 
Dries Buytaert committed
  return array("administer diary entries", "access diary entries", "post diary entries");
Dries Buytaert's avatar
 
Dries Buytaert committed
}

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_search($keys) {
Dries Buytaert's avatar
 
Dries Buytaert committed
  $result = db_query("SELECT d.*, u.userid FROM diaries d LEFT JOIN users u ON d.author = u.id WHERE d.text LIKE '%$keys%' ORDER BY d.timestamp DESC LIMIT 20");
Dries Buytaert's avatar
 
Dries Buytaert committed
  while ($diary = db_fetch_object($result)) {
Dries Buytaert's avatar
 
Dries Buytaert committed
    $find[$i++] = array("title" => "$diary->userid's diary", "link" => (user_access("administer diary entries") ? "admin.php?mod=diary&op=edit&id=$diary->id" : "module.php?mod=diary&op=view&name=$diary->userid"), "user" => $diary->userid, "date" => $diary->timestamp);
Dries Buytaert's avatar
 
Dries Buytaert committed
  }
  return $find;

}

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_page_overview($num = 20) {
  global $theme, $user;

Dries Buytaert's avatar
 
Dries Buytaert committed
  if (user_access("access diary entries")) {
Dries Buytaert's avatar
 
Dries Buytaert committed
    $result = db_query("SELECT d.*, u.userid FROM diaries d LEFT JOIN users u ON d.author = u.id ORDER BY d.timestamp DESC LIMIT $num");

    while ($diary = db_fetch_object($result)) {
      if ($time != date("F jS", $diary->timestamp)) {
        $output .= "<B>". $date = t(date("l", $diary->timestamp)) .", ". t(date("F", $diary->timestamp)) ." ". date("j", $diary->timestamp) ."</B>\n";
        $time = date("F jS", $diary->timestamp);
      }
      $output .= "<DL>\n";
      $output .= " <DD><P><B>$diary->userid ". t("wrote") .":</B></P></DD>\n";
      $output .= " <DL>\n";
      $output .= "  <DD><P>". check_output($diary->text, 1) ."</P><P>[ <A HREF=\"module.php?mod=diary&op=view&name=$diary->userid\">". t("more") ."</A> ]</P></DD>\n";
      $output .= " </DL>\n";
      $output .= "</DL>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
    }

Dries Buytaert's avatar
 
Dries Buytaert committed
    $theme->header();
    $theme->box(t("Online diary"), $output);
    $theme->footer();
  }
  else {
    $theme->header();
    $theme->box(t("Access denied"), message_access());
    $theme->footer();
  }
Dries Buytaert's avatar
 
Dries Buytaert committed
}

function diary_page_entry($timestamp, $text, $id = 0) {
  if ($id) {
    $output .= "<DL>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
    $output .= " <DT><B>". format_date($timestamp, "large") .":</B></DT>\n";
    $output .= " <DD><P>[ <A HREF=\"module.php?mod=diary&op=edit&id=$id\">". t("edit") ."</A> | <A HREF=\"module.php?mod=diary&op=delete&id=$id\">". t("delete") ."</A> ]</P><P>". check_output($text, 1) ."</P></DD>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
    $output .= "</DL>\n";
  }
  else {
    $output .= "<DL>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
    $output .= " <DT><B>". format_date($timestamp, "large") .":</B></DT>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
    $output .= " <DD><P>". check_output($text, 1) ."</P></DD>\n";
    $output .= "</DL>\n";
  }
  return $output;
}

function diary_page_display($username) {
  global $theme, $user;

Dries Buytaert's avatar
 
Dries Buytaert committed
  $username = empty($username) ? $user->userid : $username;
Dries Buytaert's avatar
 
Dries Buytaert committed

Dries Buytaert's avatar
 
Dries Buytaert committed
  $result = db_query("SELECT d.*, u.userid FROM diaries d LEFT JOIN users u ON d.author = u.id WHERE u.userid = '$username' ORDER BY timestamp DESC");

  if ($username == $user->userid) {
Dries Buytaert's avatar
 
Dries Buytaert committed
    $output .= diary_page_entry(time(), "<BIG><A HREF=\"module.php?mod=diary&op=add\">". t("Add new diary entry!") ."</A></BIG><P>");
Dries Buytaert's avatar
 
Dries Buytaert committed
    while ($diary = db_fetch_object($result)) $output .= diary_page_entry($diary->timestamp, $diary->text, $diary->id);
  }
  else {
Dries Buytaert's avatar
 
Dries Buytaert committed
    $output .= "<B>". t("Username") .":</B> ". format_username($username);
Dries Buytaert's avatar
 
Dries Buytaert committed
    while ($diary = db_fetch_object($result)) $output .= diary_page_entry($diary->timestamp, $diary->text);
  }

  $theme->header();
Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->box(t("Online diary"), $output);
Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->footer();
}

function diary_page_add() {
Dries Buytaert's avatar
Dries Buytaert committed
  global $theme, $user;
Dries Buytaert's avatar
 
Dries Buytaert committed

Dries Buytaert's avatar
 
Dries Buytaert committed
  $output .= "<FORM ACTION=\"module.php?mod=diary\" METHOD=\"post\">\n";

Dries Buytaert's avatar
 
Dries Buytaert committed
  $output .= "<P>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
  $output .= " <TEXTAREA WRAP=\"virtual\" COLS=\"50\" ROWS=\"15\" NAME=\"text\"></TEXTAREA><BR>\n";
Dries Buytaert's avatar
Dries Buytaert committed
  $output .= " <SMALL><I>". t("Allowed HTML tags") .": ". htmlspecialchars(variable_get("allowed_html", "")) .".</I></SMALL>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
  $output .= "</P>\n";

  $output .= "<P>\n";
  $output .= " <INPUT TYPE=\"submit\" NAME=\"op\" VALUE=\"Preview diary entry\">\n";
  $output .= "</P>\n";

  $output .= "</FORM>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed

Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->header();
Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->box(t("Edit your diary"), $output);
Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->footer();
}

function diary_page_delete($id) {
  db_query("DELETE FROM diaries WHERE id = '$id'");
  watchdog("message", "diary: diary entry deleted");
}

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_page_edit($id) {
Dries Buytaert's avatar
Dries Buytaert committed
  global $theme, $user;
Dries Buytaert's avatar
 
Dries Buytaert committed

  $result = db_query("SELECT * FROM diaries WHERE id = '$id'");
Dries Buytaert's avatar
 
Dries Buytaert committed
  $diary = db_fetch_object($result);

  $output .= diary_page_entry($diary->timestamp, $diary->text);

  $output .= "<FORM ACTION=\"module.php?mod=diary\" METHOD=\"post\">\n";
  $output .= "<P>\n";
Dries Buytaert's avatar
Dries Buytaert committed
  $output .= " <TEXTAREA WRAP=\"virtual\" COLS=\"50\" ROWS=\"15\" NAME=\"text\">". check_form($diary->text) ."</TEXTAREA><BR>\n";
  $output .= " <SMALL><I>". t("Allowed HTML tags") .": ". htmlspecialchars(variable_get("allowed_html", "")) .".</I></SMALL>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
  $output .= "</P>\n";
  $output .= "<P>\n";
  $output .= " <INPUT TYPE=\"hidden\" NAME=\"id\" VALUE=\"$diary->id\">\n";
  $output .= " <INPUT TYPE=\"hidden\" NAME=\"timestamp\" VALUE=\"$diary->timestamp\">\n";
  $output .= " <INPUT TYPE=\"submit\" NAME=\"op\" VALUE=\"Preview diary entry\"> <INPUT TYPE=\"submit\" NAME=\"op\" VALUE=\"Submit diary entry\">\n";
  $output .= "</P>\n";
  $output .= "</FORM>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed

Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->header();
Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->box(t("Edit your diary"), $output);
Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->footer();
}

function diary_page_preview($text, $timestamp, $id = 0) {
Dries Buytaert's avatar
Dries Buytaert committed
  global $theme, $user;
Dries Buytaert's avatar
 
Dries Buytaert committed

  $output .= diary_page_entry($timestamp, $text);

  $output .= "<FORM ACTION=\"module.php?mod=diary\" METHOD=\"post\">\n";
  $output .= "<P>\n";
Dries Buytaert's avatar
Dries Buytaert committed
  $output .= " <TEXTAREA WRAP=\"virtual\" COLS=\"50\" ROWS=\"15\" NAME=\"text\">". check_form($text) ."</TEXTAREA><BR>\n";
  $output .= " <SMALL><I>". t("Allowed HTML tags") .": ". htmlspecialchars(variable_get("allowed_html", "")) .".</I></SMALL>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
  $output .= "</P>\n";
  $output .= "<P>\n";
  $output .= " <INPUT TYPE=\"hidden\" NAME=\"id\" VALUE=\"$id\">\n";
  $output .= " <INPUT TYPE=\"submit\" NAME=\"op\" VALUE=\"Preview diary entry\">\n";
  $output .= " <INPUT TYPE=\"submit\" NAME=\"op\" VALUE=\"Submit diary entry\">\n";
  $output .= "</P>\n";

  $output .= "</FORM>\n";

  $theme->header();
Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->box(t("Edit your diary"), $output);
Dries Buytaert's avatar
 
Dries Buytaert committed
  $theme->footer();
}

function diary_page_submit($text, $id = 0) {
  global $user, $theme;

  if ($id) {
    watchdog("message", "diary: old diary entry updated");
Dries Buytaert's avatar
 
Dries Buytaert committed
    db_query("UPDATE diaries SET text = '$text' WHERE id = '$id'");
Dries Buytaert's avatar
 
Dries Buytaert committed
  }
  else {
Dries Buytaert's avatar
 
Dries Buytaert committed
    watchdog("special", "diary: new diary entry added");
Dries Buytaert's avatar
 
Dries Buytaert committed
    db_query("INSERT INTO diaries (author, text, timestamp) VALUES ('$user->id', '$text', '". time() ."')");
Dries Buytaert's avatar
 
Dries Buytaert committed
  }

  header("Location: module.php?mod=diary&op=view&name=$user->userid");
}

function diary_page() {
  global $op, $id, $name, $text, $timestamp;

  // Security check:
  if (strstr($id, " ") || strstr($name, " ")) {
    watchdog("error", "diary: attempt to provide malicious input through URI");
    exit();
  }

  switch($op) {
    case "add":
      diary_page_add();
      break;
Dries Buytaert's avatar
 
Dries Buytaert committed
      diary_page_delete(check_input($id));
      diary_page_display(check_input($name));
Dries Buytaert's avatar
 
Dries Buytaert committed
    case "edit":
Dries Buytaert's avatar
 
Dries Buytaert committed
      diary_page_edit(check_input($id));
Dries Buytaert's avatar
 
Dries Buytaert committed
      break;
    case "view":
Dries Buytaert's avatar
 
Dries Buytaert committed
      diary_page_display(check_input($name));
Dries Buytaert's avatar
 
Dries Buytaert committed
      break;
    case "Preview diary entry":
Dries Buytaert's avatar
 
Dries Buytaert committed
      if ($id) diary_page_preview(($text ? check_output($text) : ""), check_input($timestamp), check_input($id));
      else diary_page_preview(($text ? check_output($text) : ""), time());
Dries Buytaert's avatar
 
Dries Buytaert committed
      break;
    case "Submit diary entry":
Dries Buytaert's avatar
 
Dries Buytaert committed
      if ($id) diary_page_submit(check_input($text), check_input($id));
      else diary_page_submit(check_input($text));
Dries Buytaert's avatar
 
Dries Buytaert committed
      break;
    default:
      diary_page_overview();
  }
}

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_help() {
 ?>
Dries Buytaert's avatar
 
Dries Buytaert committed
  <P>Drupal's diary module allows registered users to maintain an online diary.  It provides easy-to-write and easy-to-read online diaries or journals that can be filled with daily thoughts, poetry, boneless blabber, spiritual theories, intimate details, valuable experiences, cynical rants, semi-coherent comments, writing experiments, artistic babblings, critics on current facts, fresh insights, diverse dreams, chronicles and mumbling madness available for public consumption.</P>
Dries Buytaert's avatar
 
Dries Buytaert committed
 <?php
Dries Buytaert's avatar
 
Dries Buytaert committed
}

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_link($type) {

  if ($type == "admin" && user_access("administer diary entries")) {
Dries Buytaert's avatar
 
Dries Buytaert committed
    $links[] = "<a href=\"admin.php?mod=diary\">online diaries</a>";
  }

  if ($type == "page" && user_access("access diary entries")) {
    $links[] = "<a href=\"module.php?mod=diary\">". t("online diaries") ."</a>";
  }

  if ($type == "menu" && user_access("post diary entries")) {
    $links[] = "<a href=\"module.php?mod=diary&op=add\">". t("edit your diary") ."</a>";
    $links[] = "<a href=\"module.php?mod=diary&op=view\">". t("view your diary") ."</a>";
  }

  return $links ? $links : array();
Dries Buytaert's avatar
 
Dries Buytaert committed
}

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_block() {
Dries Buytaert's avatar
 
Dries Buytaert committed
  $result = db_query("SELECT u.userid, d.timestamp FROM diaries d LEFT JOIN users u ON d.author = u.id ORDER BY timestamp DESC LIMIT 10");
Dries Buytaert's avatar
 
Dries Buytaert committed

  while ($diary = db_fetch_object($result)) {
    if ($time != date("F jS", $diary->timestamp)) {
Dries Buytaert's avatar
 
Dries Buytaert committed
      $content .= "<P><B>". t(date("l", $diary->timestamp)) ."</B> (". date("m/d/Y", $diary->timestamp) .")</P>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
      $time = date("F jS", $diary->timestamp);
    }
    $content .= "<LI><A HREF=\"module.php?mod=diary&op=view&name=$diary->userid\">$diary->userid</A></LI>\n";
  }

  $block[0]["subject"] = "Recent diary entries";
  $block[0]["content"] = $content;
Dries Buytaert's avatar
 
Dries Buytaert committed
  $block[0]["info"] = "Recent diary entries";
Dries Buytaert's avatar
 
Dries Buytaert committed
  $block[0]["link"] = "module.php?mod=diary";

  return $block;
}

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_admin_edit($id) {
Dries Buytaert's avatar
 
Dries Buytaert committed
  $result = db_query("SELECT d.*, u.userid FROM diaries d LEFT JOIN users u ON d.author = u.id WHERE d.id = '$id'");
Dries Buytaert's avatar
Dries Buytaert committed

  $diary = db_fetch_object($result);

  $output .= "<FORM ACTION=\"admin.php?mod=diary&op=save&id=$id\" METHOD=\"post\">\n";

  $output .= "<P>\n";
  $output .= " <B>Author:</B><BR>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed
  $output .= " ". format_username($diary->userid) ."\n";
Dries Buytaert's avatar
Dries Buytaert committed
  $output .= "</P>\n";

  $output .= "<P>\n";
  $output .= "<B>Diary entry:</B><BR>\n";
Dries Buytaert's avatar
Dries Buytaert committed
  $output .= " <TEXTAREA WRAP=\"virtual\" COLS=\"50\" ROWS=\"10\" NAME=\"text\">". check_form($diary->text) ."</TEXTAREA><BR>\n";
Dries Buytaert's avatar
Dries Buytaert committed
  $output .= "</P>\n";

  $output .= "<P>\n";
  $output .= " <INPUT TYPE=\"submit\" NAME=\"op\" VALUE=\"Save diary entry\">\n";
  $output .= "</P>\n";
  $output .= "</FORM>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed

Dries Buytaert's avatar
Dries Buytaert committed
  print $output;
}

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_admin_save($id, $text) {
Dries Buytaert's avatar
 
Dries Buytaert committed
  db_query("UPDATE diaries SET text = '$text' WHERE id = $id");
Dries Buytaert's avatar
 
Dries Buytaert committed
  watchdog("message", "diary: modified entry #$id.");
Dries Buytaert's avatar
Dries Buytaert committed
}

function diary_admin_delete($id) {
  db_query("DELETE FROM diaries WHERE id = '$id'");
  watchdog("message", "diary: deleted entry #$id.");
}

Dries Buytaert's avatar
 
Dries Buytaert committed
function diary_admin_display($order = "date") {
Dries Buytaert's avatar
Dries Buytaert committed
  // Initialize variables:
  $fields = array("author" => "author", "date" => "timestamp DESC");

  // Perform SQL query:
  $result = db_query("SELECT d.*, u.userid FROM diaries d LEFT JOIN users u ON u.id = d.author ORDER BY d.$fields[$order] LIMIT 50");
Dries Buytaert's avatar
 
Dries Buytaert committed

Dries Buytaert's avatar
Dries Buytaert committed
  // Display stories:
Dries Buytaert's avatar
 
Dries Buytaert committed
  $output .= "<TABLE BORDER=\"1\" CELLPADDING=\"2\" CELLSPACING=\"2\">\n";
Dries Buytaert's avatar
Dries Buytaert committed
  $output .= " <TR>\n";
  $output .= "  <TH ALIGN=\"right\" COLSPAN=\"4\">\n";
Dries Buytaert's avatar
Dries Buytaert committed
  $output .= "   <FORM ACTION=\"admin.php?mod=diary\" METHOD=\"post\">\n";
  $output .= "    <SELECT NAME=\"order\">\n";
  foreach ($fields as $key=>$value) {
    $output .= "     <OPTION VALUE=\"$key\"". ($key == $order ? " SELECTED" : "") .">Sort by $key</OPTION>\n";
  }
  $output .= "    </SELECT>\n";
  $output .= "    <INPUT TYPE=\"submit\" NAME=\"op\" VALUE=\"Update\">\n";
  $output .= "   </FORM>\n";
  $output .= "  </TH>\n";
  $output .= " </TR>\n";

  $output .= " <TR>\n";
  $output .= "  <TH>subject</TH>\n";
  $output .= "  <TH>author</TH>\n";
  $output .= "  <TH COLSPAN=\"2\">operations</TH>\n";
Dries Buytaert's avatar
Dries Buytaert committed
  $output .= " </TR>\n";

  while ($diary = db_fetch_object($result)) {
    $output .= " <TR><TD><A HREF=\"module.php?mod=diary&op=view&name=$diary->userid\">$diary->userid on ". format_date($diary->timestamp, "small") ."</A></TD><TD>". format_username($diary->userid) ."</TD><TD ALIGN=\"center\"><A HREF=\"admin.php?mod=diary&op=edit&id=$diary->id\">edit</A></TD><TD ALIGN=\"center\"><A HREF=\"admin.php?mod=diary&op=delete&id=$diary->id\">delete</A></TD></TR>\n";
Dries Buytaert's avatar
Dries Buytaert committed
  }

  $output .= "</TABLE>\n";
Dries Buytaert's avatar
 
Dries Buytaert committed

Dries Buytaert's avatar
Dries Buytaert committed
  print $output;
}


function diary_admin() {
Dries Buytaert's avatar
 
Dries Buytaert committed
  global $op, $id, $mod, $keys, $text, $order;
Dries Buytaert's avatar
 
Dries Buytaert committed

Dries Buytaert's avatar
 
Dries Buytaert committed
  if (user_access("administer diary entries")) {
Dries Buytaert's avatar
 
Dries Buytaert committed

    print "<SMALL><A HREF=\"admin.php?mod=diary\">overview</A> | <A HREF=\"admin.php?mod=diary&op=search\">search diary</A> | <A HREF=\"admin.php?mod=diary&op=help\">help</A></SMALL><HR>\n";

    switch ($op) {
      case "delete":
        diary_admin_delete(check_input($id));
        diary_admin_display();
        break;
      case "edit":
        diary_admin_edit(check_input($id));
        break;
      case "help":
        diary_help();
        break;
      case "search":
        print search_form($keys);
        print search_data($keys, $mod);
        break;
      case "Save diary entry":
        diary_admin_save(check_input($id), check_input($text));
        diary_admin_display();
        break;
      case "Update":
        diary_admin_display(check_input($order));
        break;
      default:
        diary_admin_display();
    }
Dries Buytaert's avatar
Dries Buytaert committed
  }
Dries Buytaert's avatar
 
Dries Buytaert committed
  else {
    print message_access();
Dries Buytaert's avatar
 
Dries Buytaert committed
  }
}