· 10 years ago · Mar 19, 2016, 02:24 PM
1<?php
2//functions
3/*
4 Functiion name:
5 Parameters:
6
7 Returns Nothing
8 Written by: John Branca (03/04/2006)
9 Note: SQL Error handling so other people don't see code
10*/
11
12function sql_failure_handler($query, $error, $linkprefix) {
13 $msg = htmlspecialchars("Failed Query: {$query}<br>SQL Error: {$error}");
14 error_log($msg, 3, $linkprefix."sql_error_log");
15 if ((isset($_SESSION["db"]) && $_SESSION["db"] == "fantasy_testing") || USERADMIN) {
16 return $msg;
17 }
18 return "Requested page is temporarily unavailable, please try again later.";
19}
20/*
21 Function name: getGameStats
22 Parameters:
23 $divisiontypeid = the type of division you want to get info about
24 Returns Nothing
25 Written by: John Branca (07/02/2005)
26 Note: Sets variable definitions for all of the game stats
27*/
28
29function getGameStats($divisiontypeid){
30 $othersql = "SELECT a.stat_value, a.stat_name, replace(b.descript,' ', '') as descript ".
31 "FROM game_stats a, tbldivisions_type b ".
32 "WHERE a.division_type_id = $divisiontypeid ".
33 " AND a.division_type_id = b.division_type_id";
34 $otherresult2 = mysql_query($othersql) or die(sql_failure_handler($othersql, mysql_error(), $linkprefix));
35 $otherrow2 = mysql_fetch_array($otherresult2);
36 while($otherrow2 != ""){
37 $stat_name = $otherrow2["stat_name"];
38 $stat_value = $otherrow2["stat_value"];
39 define(strtoupper(trim($otherrow2["descript"].$stat_name," ")), "$stat_value");
40 $otherrow2 = mysql_fetch_array($otherresult2);
41 }
42}
43
44/*
45 Function name: getDirName
46 Parameters:
47 $url = website url
48 Returns the deepest directory that the url is in, or nothing if there isn't any
49 Written by: John Branca (06/25/2005)
50*/
51
52function getDirName($url){
53 $tenturl = substr($url,9,(strlen($url)-9));
54 $countslash = substr_count($tenturl, "/");
55
56 if($countslash > 1){
57 $tenturl = substr($tenturl,1,(strlen($tenturl)-1));
58 $posofslash = strpos($tenturl, "/");
59 $tenturl = substr($tenturl, 0, $posofslash);
60 return $tenturl;
61 }
62 else {
63 return '';
64 }
65}
66
67/*
68 Function name: getPageName
69 Parameters:
70 $url = website url
71 Returns only the pagename of a given url
72 Written by: John Branca (06/24/2005)
73*/
74function getPageName($url){
75 $parsearray = parse_url($url);
76 $path = $parsearray['path'];
77 $path_parts = pathinfo($path);
78
79 return $path_parts['basename'];
80}
81
82/*
83 Function name: getHelpText
84 Parameters:
85 $url = website url
86 Returns helptext if successful, 0 if not
87 Written by: John Branca (06/24/2005)
88*/
89function getHelpText($url){
90 $sql = "SELECT descript FROM site WHERE url='$url'";
91 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
92 $row = mysql_fetch_array($result);
93 return $row["descript"];
94}
95/*
96 Function name: editQuestions
97 Parameters:
98 $type = type of section of questions to edit
99 $section_id = section_id to edit
100 Returns 1 if successful, 0 if not
101 Written by: John Branca (06/24/2005)
102*/
103function editQuestions($type, $section_id){
104 //get the table name by using the type variable
105 $tablename = "$type";
106
107 //get max section_id number so we know how far to go in loop
108 $sql = "SELECT max(".$type."_id) as maxquestion FROM $tablename WHERE section_id = $section_id";
109 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
110 $row = mysql_fetch_array($result);
111 $maxquestion = $row["maxquestion"];
112
113 $returnval = 0;
114
115 //loop through post variables and edit them in database with sql query
116 for($i = 0; $i <= $maxquestion; $i++){
117 //make sure post variable is set
118 if(isset($_POST["question".$section_id."-".$i])){
119 $sql = "UPDATE $tablename SET question = '".$_POST["question".$section_id."-".$i]."'".
120 ", answer='".$_POST["answer".$section_id."-".$i]."' WHERE section_id = $section_id ".
121 "AND ".$tablename."_id = $i";
122 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
123 $returnval = 1;
124 }
125 }
126 return $returnval;
127}
128
129
130/*
131 Function name: moveUpQuestion
132 Parameters:
133 $type = type of section to delete question in
134 $section_id = type of section type_id is in
135 $type_id = type_id autonumber
136 Returns 1 if successful, -1 if not
137 Written by: John Branca (06/24/2005)
138*/
139
140function moveUpQuestion($type, $section_id, $type_id){
141 //get the table name by using the type variable
142 $tablename = "$type";
143
144 //get display for section
145 $sql = "SELECT display FROM $tablename WHERE section_id = $section_id AND ".$tablename."_id = $type_id";
146 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
147 $row = mysql_fetch_array($result);
148 $display = $row["display"]-0;
149
150 //get display for section above this one
151 $displayfound = 0;
152 $displayUp = $display - 1;
153 while($displayfound == 0 && $displayUp != 0){
154 $sql = "SELECT ".$tablename."_id FROM $tablename WHERE display = $displayUp";
155 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
156 $row2 = mysql_fetch_array($result);
157
158 if($row != ""){
159 $displayfound = 1;
160 $typeUp = $row2[$tablename."_id"];
161 }
162 else {
163 $displayUp--;
164 }
165 }
166 if($displayfound == 0){
167 //an error has occurred, the section above was not found
168 return 0;
169 }
170
171 //switch the displays for these two types
172 $sql = "UPDATE $tablename SET display = $display WHERE ".$tablename."_id = ".$typeUp;
173 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
174
175 $sql = "UPDATE $tablename SET display = $displayUp WHERE ".$tablename."_id = ".$type_id;
176 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
177
178 return 1;
179}
180
181/*
182 Function name: moveDownQuestion
183 Parameters:
184 $type = type of section to delete question in
185 $section_id = type of section type_id is in
186 $type_id = type_id autonumber
187 Returns 1 if successful, -1 if not
188 Written by: John Branca (06/24/2005)
189*/
190
191function moveDownQuestion($type, $section_id, $type_id){
192 //get the table name by using the type variable
193 $tablename = "$type";
194
195 $sql = "DELETE FROM $tablename WHERE ".$type."_id = $delete_id";
196 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
197
198 return $delete_id;
199}
200
201/*
202 Function name: deleteQuestion
203 Parameters:
204 $type = type of section to delete question in
205 $delete_id = id to delete
206 Returns section number if successful, -1 if not
207 Written by: John Branca (06/24/2005)
208*/
209
210function deleteQuestion($type, $delete_id){
211 //get the table name by using the type variable
212 $tablename = "$type";
213
214 $sql = "DELETE FROM $tablename WHERE ".$type."_id = $delete_id";
215 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
216
217 return $delete_id;
218}
219
220/*
221 Function name: addQuestion
222 Parameters:
223 $type = type of section to add question to
224 Returns section number if successful, -1 if not
225 Written by: John Branca (06/24/2005)
226*/
227
228function addQuestion($type, $section_id){
229 //get the table name by using the type variable
230 $tablename = "$type";
231
232 //run sql to get max display number and add one to it
233 $sql = "SELECT max(display) as displaymax FROM $tablename WHERE section_id = $section_id";
234 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
235 $row = mysql_fetch_array($result);
236
237 $maxdisplay = 1;
238
239 if($row != ""){
240 $maxdisplay = $row["displaymax"]+1;
241 }
242
243 //run sql to add section to table
244 $sql = "INSERT INTO $tablename (question, answer, display, section_id) VALUES ('','',$maxdisplay, $section_id)";
245 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
246
247 $help_id = -1;
248
249 //get id returned from table and put it in appropriate variable
250 $help_id = mysql_insert_id();
251
252 return $help_id;
253}
254
255/*
256 Function name: moveUpSection
257 Parameters:
258 $type = type of section to moveup
259 $section_id = section id to moveup
260 Returns 1 if successful, 0 if not
261 Written by: John Branca (06/24/2005)
262*/
263
264function moveUpSection($type, $section_id){
265 //get the table name by using the type variable
266 $tablename = "$type"."_sections";
267
268 //get display for section
269 $sql = "SELECT display FROM $tablename WHERE section_id = $section_id";
270 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
271 $row = mysql_fetch_array($result);
272 $display = $row["display"]-0;
273 //echo($sql);
274
275 //get display for section above this one
276 $displayfound = 0;
277 $displayUp = $display - 1;
278 while($displayfound == 0 && $displayUp != 0){
279 $sql = "SELECT section_id FROM $tablename WHERE display = $displayUp";
280 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
281 $row2 = mysql_fetch_array($result);
282
283 //echo("Display1: $display Display2: $displayUp Section: ".$row2["section_id"]."<br />");
284
285 if($row != ""){
286 $displayfound = 1;
287 $sectionUp = $row2["section_id"];
288 }
289 else {
290 $displayUp--;
291 }
292 }
293 if($displayfound == 0){
294 //an error has occurred, the section above was not found
295 return 0;
296 }
297
298 //switch the displays for these two sections
299 $sql = "UPDATE $tablename SET display = $display WHERE section_id = $sectionUp";
300 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
301
302 $sql = "UPDATE $tablename SET display = $displayUp WHERE section_id = $section_id";
303 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
304
305 return 1;
306}
307
308/*
309 Function name: moveDownSection
310 Parameters:
311 $type = type of section to moveDown
312 $section_id = section id to moveDown
313 Returns 1 if successful, 0 if not
314 Written by: John Branca (06/24/2005)
315*/
316
317function moveDownSection($type, $section_id){
318 //get the table name by using the type variable
319 $tablename = "$type"."_sections";
320
321 //get display for section
322 $sql = "SELECT display FROM $tablename WHERE section_id = $section_id";
323 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
324 $row = mysql_fetch_array($result);
325 $display = $row["display"];
326
327 //get display for section below this one
328 $displayfound = 0;
329 $displayDown = $display + 1;
330 while($displayfound == 0 && $displayDown <= 99){
331 $sql = "SELECT section_id FROM $tablename WHERE display = $displayDown";
332 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
333 $row = mysql_fetch_array($result);
334
335 if($row != ""){
336 $displayfound = 1;
337 $sectionDown = $row["section_id"];
338 }
339 else {
340 $displayDown++;
341 }
342 }
343 if($displayfound == 0){
344 //an error has occurred, the section above was not found
345 return 0;
346 }
347
348 //switch the displays for this two sections
349 $sql = "UPDATE $tablename SET display = $display WHERE section_id = $sectionDown";
350 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
351
352 $sql = "UPDATE $tablename SET display = $displayDown WHERE section_id = $section_id";
353 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
354
355 return 1;
356}
357
358/*
359 Function name: deleteSection
360 Parameters:
361 $type = type of section to delete
362 $section_id = section id to delete
363 Returns 1 if successful, 0 if not
364 Written by: John Branca (06/24/2005)
365*/
366
367function deleteSection($type, $section_id){
368 //get the table name by using the type variable
369 $tablename = "$type"."_sections";
370
371 //run sql to delete section
372 $sql = "DELETE FROM $tablename WHERE section_id = $section_id";
373 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
374
375 return 1;
376}
377
378/*
379 Function name: editSections
380 Parameters:
381 $type = type of section to edit
382 Returns 1 if successful, 0 if not
383 Written by: John Branca (06/24/2005)
384*/
385
386function editSections($type){
387 //get the table name by using the type variable
388 $tablename = "$type"."_sections";
389
390 //get max section_id number so we know how far to go in loop
391 $sql = "SELECT max(section_id) as maxsection FROM $tablename";
392 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
393 $row = mysql_fetch_array($result);
394 $maxsection = $row["maxsection"];
395
396 $returnval = 0;
397
398 //loop through post variables and edit them in database with sql query
399 for($i = 0; $i <= $maxsection; $i++){
400 //make sure post variable is set
401 if(isset($_POST["section$i"])){
402 //echo($_POST["section$i"]."<br />");
403 $sql = "UPDATE $tablename SET descript = '".$_POST["section$i"]."'".
404 " WHERE section_id = $i";
405 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
406 $returnval = 1;
407 }
408 }
409 return $returnval;
410}
411
412/*
413 Function name: addSection
414 Parameters:
415 $type = type of section to add
416 Returns section number if successful, -1 if not
417 Written by: John Branca (06/24/2005)
418*/
419
420function addSection($type){
421 //get the table name by using the type variable
422 $tablename = "$type"."_sections";
423
424 //run sql to get max display number and add one to it
425 $sql = "SELECT max(display) as displaymax FROM $tablename";
426 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
427 $row = mysql_fetch_array($result);
428
429 $maxdisplay = 1;
430
431 if($row != ""){
432 $maxdisplay = $row["displaymax"]+1;
433 }
434
435 //run sql to add section to table
436 $sql = "INSERT INTO $tablename (descript, display) VALUES ('',$maxdisplay)";
437 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
438
439 $section_id = -1;
440
441 //get id returned from table and put it in appropriate variable
442 $section_id = mysql_insert_id();
443
444 return $section_id;
445}
446
447/*
448 Function name: activateWeb
449 Parameters: none
450 Returns 1 if successful, 0 if user or random not found
451 Written by: John Branca (06/23/2005)
452*/
453
454function activateWeb(){
455 //sql to detect if right information is gathered
456 $check = $_POST["user"] != "" && isset($_POST["user"]) &&
457 $_POST["email_addy"] != "" && isset($_POST["email_addy"]) &&
458 strlen($_POST["user"]) > 5 && strlen($_POST["email_addy"]) > 8;
459
460 $errormsg = "";
461
462 if(!$check){
463 //they have not put in all required fields
464 //username check
465 if($_POST["user"] == "" || !isset($_POST["user"])){
466 $errormsg .= "You have not input a Login Name.<br />";
467 }
468 else if(strlen($_POST["user"]) <= 5){
469 $errormsg .= "Your Login Name has to be longer than five characters.<br />";
470 }
471 if($_POST["email_addy"] == "" || !isset($_POST["email_addy"])){
472 $errormsg .= "You have not input an Email Address.<br />";
473 }
474 else if(strlen($_POST["email_addy"]) <= 8){
475 $errormsg .= "Your Email Address has to be longer than eight characters.<br />";
476 }
477 return $errormsg;
478 }
479 else {
480
481 $sql = "SELECT user_name FROM users WHERE user_name = '".
482 $_POST["user"]."' and user_email = '".$_POST["email_addy"]."'";
483 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
484 $num = mysql_num_rows($result);
485
486 if($num == 1){
487 //sql to update database so user is activated
488 $sql = "UPDATE users SET user_activated = 1 WHERE user_name = '".$_POST["user"]."'";
489 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
490 return 1;
491 }
492 else {
493 return "Login Name and/or Email Address Not Found.";
494 }
495 }
496}
497
498/*
499 Function name: activate
500 Parameters:
501 $random = random number in database
502 $user = username in database
503 Returns 1 if successful, 0 if user or random not found
504 Written by: John Branca (06/23/2005)
505*/
506
507function activate($random, $user){
508 //sql to detect if right information is gathered
509 $sql = "SELECT user_name FROM users WHERE user_name = '$user' and randnum = $random";
510 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
511 $num = mysql_num_rows($result);
512
513 if($num == 1){
514 //sql to update database so user is activated
515 $sql = "UPDATE users SET user_activated = 1 WHERE user_name = '$user'";
516 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
517 return 1;
518 }
519 else {
520 return 0;
521 }
522}
523
524/*
525 Function name: validate_email
526 Parameters:
527 $email = user inputted email address
528 Returns 1 if valid, 0 if invalid
529 Note: This was taken from the following website:
530 http://www.developer.com/lang/php/article.php/10941_3290141_2
531 Copied by: John Branca (06/23/2005)
532*/
533
534function validate_email($email)
535{
536 // Create the syntactical validation regular expression
537 $regexp = "^([_a-z0-9-]+)(\.[_a-z0-9-]+)*@([a-z0-9-]+)(\.[a-z0-9-]+)*(\.[a-z]{2,4})$";
538
539 // Presume that the email is invalid
540 $valid = 0;
541
542 // Validate the syntax
543 if (eregi($regexp, $email))
544 {
545 list($username,$domaintld) = split("@",$email);
546 // Validate the domain
547 if (getmxrr($domaintld,$mxrecords))
548 $valid = 1;
549 } else {
550 $valid = 0;
551 }
552
553 return $valid;
554}
555
556/*
557 Function name: registerEmail
558 Parameters:
559 $username = successfully registered username
560 $password = successfully registered password
561 $hideemail = Whether user wanted email hidden
562 $emailaddy = Where to send the email
563 $random = A random number generated, used to activate
564 Returns nothing
565 Note: this will send a registration email to the specified email address
566 Written by: John Branca (06/23/2005)
567*/
568
569function registerEmail($username, $password, $hideemail, $emailaddy, $random){
570 $recipients = array('To' => $_POST["email_addy"]);
571 $headers['MIME-Version'] = '1.0';
572 $headers['Content-type'] = "text/html; charset=iso-8859-1";
573 $headers['From'] = 'Fantasy Sports Manager <mannram@fantasysportsmanager.net>';
574 $headers['To'] = $_POST["email_addy"];
575 $headers['Subject'] = 'FSM Registration';
576 $body = "
577 <html>
578 <head>
579 <title>FSM Registration</title>
580 <style type='text/css'>
581 <!--
582 #middle {
583 background-color: #DDF;
584 height: 200px;
585 padding: 2px;
586 border: solid 1px black;
587 }
588 .row {
589 clear: both;
590 }
591 .col1 {
592 font-weight: bold;
593 float: left;
594 width: 100px;
595 }
596 .col2 {
597 float: left;
598 width: 200px;
599 }
600 -->
601 </style>
602 </head>
603 <body>
604 <p>Here is your registration information for Fantasy Sports Manager</p>
605 <div id='middle'>
606 <div class='row'>
607 <div class='col1'>Login Name</div>
608 <div class='col2'>".$_POST['username']."</div>
609 </div>
610 <div class='row'>
611 <div class='col1'>Password</div>
612 <div class='col2'>".$_POST['pass']."</div>
613 </div>
614 <div class='row'>
615 <div class='col1'>Hide Email</div>
616 <div class='col2'>";
617 if($_POST["hideemail"] == 1){
618 $body .= "Yes";
619 }
620 else {
621 $body .= "No";
622 }
623 $body .= "
624 </div>
625 </div>
626 <br /><br />
627 <div>
628 If you have any technical problems, please send an email to
629 <a href='mailto:mannram@fantasysportsmanager.net'>
630 mannram@fantasysportsmanager.net</a><br />
631 If you have any questions or comments about this process,
632 you can fill out our <a
633 href='http://www.fantasysportsmanager.net/comments.php'>
634 Comments/Suggestions</a> form.<br />
635 You can change your password and other information on your
636 <a href='http://www.fantasysportsmanager.net/editprofile.php'>
637 Profile</a> page.
638 </div>
639 </div>
640 </body>
641 </html>";
642 $params['sendmail_path'] = '/usr/lib/sendmail';
643 // Create the mail object using the Mail::factory method
644 $mail_object =& Mail::factory('sendmail', $params);
645 $mail_object->send($recipients, $headers, $body);
646}
647
648
649/*
650 Function name: register
651 Parameters:
652 $sess = php session of user
653 Returns 1 if register successful, error message(s) if not
654 Written by: John Branca (06/23/2005)
655*/
656
657function register($sess){
658 //error message variable
659 $errormsg = "";
660 //figure out if required fields were input or required lengths of fields were not matched
661 $check = $_POST["username"] != "" && isset($_POST["username"]) &&
662 $_POST["pass"] != "" && isset($_POST["pass"]) &&
663 $_POST["pass2"] != "" && isset($_POST["pass2"]) &&
664 $_POST["email_addy"] != "" && isset($_POST["email_addy"]) &&
665 $_POST["hideemail"] != "" && isset($_POST["hideemail"]) &&
666 strlen($_POST["username"]) > 5 && strlen($_POST["pass"]) > 5 &&
667 strlen($_POST["email_addy"]) > 8;
668
669 if(!$check){
670 //they have not put in all required fields
671 //username check
672 if($_POST["username"] == "" || !isset($_POST["username"])){
673 $errormsg .= "You have not input a Login Name.<br />";
674 }
675 else if(strlen($_POST["username"]) <= 5){
676 $errormsg .= "Your Login Name has to be longer than five characters.<br />";
677 }
678 if($_POST["pass"] == "" || !isset($_POST["pass"])){
679 $errormsg .= "You have not input a Password.<br />";
680 }
681 else if(strlen($_POST["pass"]) <= 5){
682 $errormsg .= "Your Password has to be longer than five characters.<br />";
683 }
684 if($_POST["pass2"] == "" || !isset($_POST["pass2"])){
685 $errormsg .= "You have not confirmed your Password.<br />";
686 }
687 if($_POST["email_addy"] == "" || !isset($_POST["email_addy"])){
688 $errormsg .= "You have not input an Email Address.<br />";
689 }
690 else if(strlen($_POST["email_addy"]) <= 8){
691 $errormsg .= "Your Email Address has to be longer than eight characters.<br />";
692 }
693 //make sure email is valid
694 else if(validate_email($_POST["email_addy"]) == 0){
695 $errormsg .= "Your Email Address is invalid.<br />";
696 }
697 if($_POST["hideemail"] == "" || !isset($_POST["hideemail"])){
698 $errormsg .= "Please choose whether or not you wish to hide your Email Address.<br />";
699 }
700 if($_POST["pass"] != "" && $_POST["pass2"] != "" &&
701 $_POST["pass"] != $_POST["pass2"]){
702 $errormsg .= "Your Passwords do not match.<br />";
703 }
704 return $errormsg;
705 }
706 //if everything A-OK
707 else {
708 //try to register person, first check if username already in database
709 $sql = "SELECT user_name FROM users WHERE user_name = '".$_POST["username"]."'";
710 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
711 $num = mysql_num_rows($result);
712 //username already in database
713 if($num > 0){
714 $errormsg .= "That Login Name already exists in our database.<br />";
715 return $errormsg;
716 }
717 //time to put fields in database with insert statement
718 else {
719 //generate random number for activation
720 srand(time());
721 $random = (rand()%999999);
722
723 $sql = "INSERT INTO users (user_name, user_sess, user_password, ".
724 "user_email, user_hideemail, user_activated, user_join, randnum) VALUES ('".
725 $_POST["username"]."','$sess', '".md5($_POST["pass"])."','".
726 $_POST["email_addy"]."', ".$_POST["hideemail"].", 1, now(), $random)";
727
728 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
729
730 //put into words hideemail
731 switch($_POST["hideemail"]){
732 case 1:
733 $hide = "Yes";
734 break;
735 case 0:
736 $hide = "No";
737 break;
738 }
739 registerEmail($_POST["username"], $_POST["pass"],
740 $hide, $_POST["email_addy"], $random);
741 return 1;
742 }
743 }
744}
745
746/*
747 Function name: logout
748 Parameters:
749 $sess = php session of user
750 Returns: 1 if logout correctly, 0 if not
751 Written by: John Branca (06/23/2005)
752*/
753
754function logout($sess){
755 //get rid of session variable stored in database
756 $sql = "UPDATE users SET user_sess = '', user_currentdivision = 0, user_currentteam = 0 WHERE user_sess = '$sess'";
757 mysql_query($sql) or die("<span class='red'>Error: </span>There has been an error while logging you out. ".
758 "Please close your browser window to fully logout. Thank you.");
759
760 //redirect user to home page
761 header('HTTP/1.1 303 See Other');
762 header("Location: http://www.fantasysportsmanager.net/");
763 return 1;
764}
765
766/*
767 Function name: loginInfo
768 Parameters:
769 $sess = php session of user
770 Returns: 1 if logged in, 0 if not
771 Written by: John Branca (06/23/2005)
772*/
773
774function loginInfo($sess){
775 //select user info where user_sess = $sess
776 $sql = "SELECT user_id, user_email, user_name, user_admin,".
777 " user_currentdivision, user_currentteam FROM users WHERE user_sess = '$sess'";
778 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
779 $num = mysql_num_rows($result);
780 $row = mysql_fetch_array($result);
781
782 //where there is one user logged on using the session variable
783 if($num == 1){
784 //define login status as true
785 define("LOGIN",true);
786 //define variables to use on page
787 define("USERID",$row["user_id"]);
788 define("USERNAME",$row["user_name"]);
789 define("USEREMAIL",$row["user_email"]);
790 define("USERADMIN",$row["user_admin"]);
791
792 define("DIVISION",$row["user_currentdivision"]);
793 define("TEAM",$row["user_currentteam"]);
794
795 //figure out if user is logged into division
796 if($row["user_currentdivision"] != 0){
797 define("LOGINDIVISION", true);
798 }
799 else {
800 define("LOGINDIVISION", false);
801 }
802 //return 1 for success
803 return 1;
804 }
805 //there are either multiple users or no users, in either case return 0
806 else {
807 //define login status as false
808 define("LOGIN",false);
809 define("LOGINDIVISION", false);
810 define("USERADMIN",false);
811 define("LEADER",false);
812 return 0;
813 }
814}
815
816/*
817 Function name: loginDiv
818 Parameters:
819 $div = division trying to log into
820 $team = team trying to log into
821 $divtype = division type trying to log into
822 $sess = PHP SESSID, used to get user info from master table
823 Returns nothing
824 Note: Simply redirects you to the right page given the divisiontype
825 Written by: John Branca (06/26/2005)
826*/
827function loginDiv($div, $team, $divtype, $sess){
828 $sql = "SELECT user_id FROM users WHERE user_sess = '$sess'";
829 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
830 $num = mysql_num_rows($result);
831
832 //if successful login
833 if($num == 1){
834 //update user sessid in the database to use for information on other pages
835 $sql = "UPDATE users SET user_currentdivision = $div, user_currentteam = $team where user_sess = '$sess'";
836 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
837 switch($divtype){
838 case 1:
839 //baseball
840 $site = "http://www.fantasysportsmanager.net/mlb/divisionhome.php";
841 break;
842 case 2:
843 //football
844 $site = "http://www.fantasysportsmanager.net/nfl/divisionhome.php";
845 break;
846 case 3:
847 //ncaa b-ball
848 $site = "http://www.fantasysportsmanager.net/ncaab/divisionhome.php";
849 break;
850 }
851 header('HTTP/1.1 303 See Other');
852 header("Location: $site");
853 }
854}
855/*
856 Function name: login
857 Parameters:
858 $username = name of the user who is attempting to login
859 $pass = password of user who is attempting to login
860 $sess = php session of user who is attempting to login
861 $site = last site the user was on
862 Returns: error message or nothing if correct.
863 Written by: John Branca (06/23/2005)
864 Updated by: John Branca (06/25/2005)
865*/
866
867function login($username, $pass, $sess, $site){
868 //select user info from mysql database
869 $sql = "SELECT user_id,user_activated,user_class, user_email FROM users WHERE ".
870 "user_name = '$username' AND user_password = md5('$pass')";
871 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
872 $num = mysql_num_rows($result);
873 $row = mysql_fetch_array($result);
874 $activate = $row["user_activated"];
875
876 //if successful login
877 if($num == 1 && $activate == 1){
878 //update user sessid in the database to use for information on other pages
879 $sql = "UPDATE users SET user_sess = '$sess', user_lastvisit = now() where user_id = ".$row["user_id"];
880 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
881 header('HTTP/1.1 303 See Other');
882 header("Location: $site");
883
884 }
885 //if user is successful but hasn't activated yet.
886 else if($num == 1 && $activate == 0){
887 return "<span class='red'>Error: </span>You did not <a href='activate.php'>activate</a> your account.";
888 }
889 //if no user exists with that login data
890else {
891 session_unset();
892 session_destroy();
893 return "<span class='red'>Error: </span>You did not enter a correct username and/or password.";
894 }
895}
896
897
898/*
899 Function name: sqlToArray
900 Parameters:
901 $sqltext = SQL to process, please do not use select * because
902 it will return nothing
903 $name = What you wish to name array
904 $check = Number that means nothing as of now
905 Returns: nothing
906
907 Note: It will print out a javascript menu so that it may be used to
908 dynamically change a select box, etc.
909 Written by: John Branca (12/02/2004)
910*/
911
912function sqlToArray($sqltext,$name,$check){
913 $resultofsql = mysql_query($sqltext) or die(sql_failure_handler($sqltext, mysql_error(), $linkprefix));
914 $num = mysql_num_fields($resultofsql);
915 echo("<script type=\"text/javascript\">\n");
916 echo("var $name = new Array($num);\n");
917
918 $i = 0;
919 $field = "0";
920 $fields = Array();
921
922 while($i < $num){
923 $field = mysql_fetch_field($resultofsql);
924 $fields[$i] = $field->name;
925 $i++;
926 }
927 $rowofdata = mysql_fetch_array($resultofsql);
928 $j = 0;
929
930 while($rowofdata != ""){
931 for($i = 0; $i < $num; $i++){
932 if($j == 0){
933 echo($name);
934 echo("[");
935 echo("\"$fields[$i]\"");
936 echo("]");
937 echo(" = new Array();\n");
938 }
939 echo($name);
940 echo("[");
941 echo("\"$fields[$i]\"");
942 echo("]");
943 echo("[$j]");
944 echo(" = ");
945 echo("\"");
946 $temp = $rowofdata[$fields[$i]];
947
948 if($check == 1){
949 $temp = str_replace("\"","&temp;",$temp);
950 while($temp != strip_tags($temp)) {
951 $temp = strip_tags($temp);
952 }
953 }
954 echo($temp);
955 echo("\"");
956 echo(";\n");
957 }
958 $j++;
959 $rowofdata = mysql_fetch_array($resultofsql);
960 }
961 echo("</script>\n");
962}
963
964/*
965 Function name: sqlToArray
966 Parameters:
967 $sqltext = SQL to process, please do not use select * because
968 it will return nothing
969 Returns: an array that is dynamically determined based on the SQL provided.
970 Written by: John Branca (11/30/2004)
971*/
972
973function sqlToPHP($sqltext){
974 $resultofsql = mysql_query($sqltext) or die(sql_failure_handler($sqltext, mysql_error(), $linkprefix));
975 $num = mysql_num_fields($resultofsql);
976 $i = 0;
977 $fields = Array();
978 $sqlarray = Array();
979
980 while($i < $num){
981 $field = mysql_fetch_field($resultofsql);
982 $fields[$i] = $field->name;
983 $i++;
984 }
985 $rowofdata = mysql_fetch_array($resultofsql);
986 $j = 0;
987
988 while($rowofdata != ""){
989 for($i = 0; $i < $num; $i++){
990 if($j == 0){
991 $sqlarray[$fields[$i]] = Array();
992 }
993 $sqlarray[$fields[$i]][$j] = $rowofdata[$fields[$i]];
994 }
995 $j++;
996 $rowofdata = mysql_fetch_array($resultofsql);
997 }
998 return $sqlarray;
999}
1000
1001function makeRegion($str){
1002 $newRegion = "";
1003 $len = strlen($str);
1004 $i = 0;
1005
1006 while($i < $len){
1007 $newRegion = $newRegion . substr($str,$i,1);
1008 $newRegion = $newRegion . '<br />';
1009 $i++;
1010 }
1011 return $newRegion;
1012}
1013/*
1014 Function name: yearText
1015 Parameters: divisionyear - the year of the current division
1016 Returns: yeartext - text that includes the html to show and pick the year
1017 Written by: John Branca (02/11/2005)
1018*/
1019
1020//include year at the top of a fantasy page
1021function yearText($divisionyear){
1022 $othersql = "SELECT distinct(a.Year) as num ".
1023 "FROM tblteam a, tbldivisions b, tblList c ".
1024 "WHERE a.team_id = c.team_id AND c.game_id = b.game_id AND ".
1025 "b.division_id = ".DIVISION." ".
1026 "ORDER BY Year DESC";
1027 $otherresult = mysql_query($othersql) or die(sql_failure_handler($othersql, mysql_error(), $linkprefix));
1028 $otherrow = mysql_fetch_array($otherresult);
1029
1030 $yeartext .= "<div style='text-align: left;'>\n";
1031 $years = array();
1032 $yearscount = 0;
1033 $yearcheck = $divisionyear;
1034
1035 if($otherrow != ""){
1036 define("YEARTEXT", true);
1037 $yeartext .= "<form action='' method='post'>\n";
1038 $yeartext .= "<div><select name='poolyear' size='1'>\n";
1039 }
1040 else {
1041 define("YEARTEXT", false);
1042 }
1043 while($otherrow != ""){
1044 $yeartext .= "<option value='".$otherrow["num"]."'";
1045 if((!isset($_POST["year"]) && $otherrow["num"] == $yearcheck) ||
1046 (isset($_POST["year"]) && $otherrow["num"] == $_POST["year"])){
1047 $yeartext .= " selected=\"selected\"";
1048 }
1049 $yeartext .= ">".$otherrow["num"]."</option>\n";
1050 $years[$yearscount] = $otherrow["num"];
1051 $otherrow = mysql_fetch_array($otherresult);
1052 $yearscount++;
1053 }
1054 if($yearscount > 0){
1055 $yeartext .= "</select>\n";
1056 $yeartext .= "<input type='submit' value='Change Year' /></div>\n";
1057 $yeartext .= "</form>\n</div>";
1058 }
1059 return $yeartext;
1060}
1061
1062/*
1063 Function name: joinDivision
1064 Parameters: divisiontype - a number that refers to what type the division is
1065 teamname - a string that refers to what teamname the user wants
1066 division - a number that refers to the division_id
1067 Returns: new team id - number that refers to the new team id in the db
1068 Written by: John Branca (02/11/2005)
1069*/
1070
1071function joinDivision($divisiontype, $teamname, $division, $userid){
1072 $sql = "SELECT stat_value FROM game_stats WHERE stat_name='Year' AND ".
1073 "division_type_id = $divisiontype";
1074 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
1075 $row = mysql_fetch_array($result);
1076 $year = $row["stat_value"];
1077
1078 $sql = "INSERT INTO tblteam (descript, Year) VALUES ('$teamname', $year) ";
1079 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
1080
1081 $new_team_id = mysql_insert_id();
1082
1083 $sql = "INSERT INTO tblList (master_id, team_id) VALUES ".
1084 "($userid, LAST_INSERT_ID()) ";
1085 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
1086
1087 $sql = "INSERT INTO tbldivisions (division_id, game_id, User) ".
1088 "VALUES ($division, LAST_INSERT_ID(), 1) ";
1089 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
1090
1091 $sql = "SELECT descript FROM tbldivisions_list WHERE division_id = $division";
1092 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
1093 $row = mysql_fetch_array($result);
1094 $divisionname = $row["descript"];
1095
1096 //add standings info to the results table for football
1097
1098 if($divisiontype == 2){
1099 for($i = 1; $i <= 18; $i++){
1100 $sql = "INSERT INTO nfl_results (team_id, week, correct) ".
1101 "VALUES ($new_team_id, $i, 0)";
1102 $result = mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
1103 }
1104 }
1105 $sql = "INSERT INTO team_stats (team_id, stat_name, stat_value) ".
1106 "VALUES ($new_team_id, 'Paid', 'No') ";
1107 mysql_query($sql) or die(sql_failure_handler($sql, mysql_error(), $linkprefix));
1108 return $new_team_id;
1109}
1110?>