HB/pages/envoyer_message.php

32 lines
1.8 KiB
PHP

<?php
session_start();
require_once 'bdd.php';
require('../template.php');
$template = new Template('../templates/'.$templates);
$template->set_filenames(array('mp_env' => 'mp_env.tpl'));
if (isset($_GET['pseudo'])) $p=$_GET['pseudo']; else $p='';
if (isset($_GET['ok'])) $_GET['ok']=1; else $_GET['ok']=0;
if (!isset($_GET['err'])) $_GET['err']=0;
if (isset($_POST)) {
if (isset($_POST['message_destinataire']) && $_POST['message_destinataire'] != '') {
$resultat = mysql_query("SELECT pseudo FROM user WHERE pseudo='".mysql_real_escape_string($_POST['message_destinataire'])."'"); // on vérifie l'existance
if(mysql_num_rows($resultat)>=1) { // si c'est bon on passe a la suite
if (isset($_POST['sujet_message']) && $_POST['sujet_message'] !='' ) { mysql_query("INSERT INTO mail VALUES('', '1', '".mysql_real_escape_string(htmlspecialchars($_POST['message_destinataire']))."', '".mysql_real_escape_string($pseudo)."', '".mysql_real_escape_string(htmlspecialchars($_POST['sujet_message']))."', '".mysql_real_escape_string(htmlspecialchars($_POST['message']))."', '".$temps."')"); header('Location: envoyer_message.php?ok=1'); exit; }
else $_GET['err'] = 3;
}
else $_GET['err'] = 4;
}
elseif (isset($_POST['message_destinataire'])) $_GET['err'] = 2;
}
if ($_GET['ok'] == 1) $ERREUR = '<tr><td colspan="2"><font color="lime">Message envoyé</font></td></tr>';
elseif ($_GET['err'] == 4) $ERREUR = '<tr><td colspan="2"><font color="red">Ce joueur n\'existe pas</font></td></tr>';
elseif ($_GET['err'] == 2) $ERREUR = '<tr><td colspan="2"><font color="red">Votre message n\'a pas de contenu</font></td></tr>';
elseif ($_GET['err'] == 3) $ERREUR = '<tr><td colspan="2"><font color="red">Précisez le sujet du message</font></td></tr>';
$template->assign_vars( array('ERREUR' => $ERREUR, 'PSEUDO' => $p));
$template->pparse('mp_env');
?>