Files
nexusphp/public/takestaffmess.php

58 lines
1.7 KiB
PHP
Raw Normal View History

2020-12-26 01:42:23 +08:00
<?php
2021-01-13 19:32:26 +08:00
require "../include/bittorrent.php";
2020-12-26 01:42:23 +08:00
if ($_SERVER["REQUEST_METHOD"] != "POST")
stderr("Error", "Permission denied!");
dbconn();
2022-08-10 17:38:05 +08:00
loggedinorreturn();
2020-12-26 01:42:23 +08:00
if (get_user_class() < UC_ADMINISTRATOR)
stderr("Sorry", "Permission denied.");
$sender_id = ($_POST['sender'] == 'system' ? 0 : (int)$CURUSER['id']);
$dt = sqlesc(date("Y-m-d H:i:s"));
$msg = trim($_POST['msg']);
if (!$msg)
stderr("Error","Don't leave any fields blank.");
$updateset = $_POST['clases'];
if (is_array($updateset)) {
foreach ($updateset as &$class) {
$class=intval($class);
2020-12-26 01:42:23 +08:00
if (!is_valid_id($class) && $class != 0)
stderr("Error","Invalid Class");
}
}else{
if (!is_valid_id($updateset) && $updateset != 0)
stderr("Error","Invalid Class");
}
$subject = trim($_POST['subject']);
2022-08-10 17:38:05 +08:00
$size = 10000;
$page = 1;
set_time_limit(300);
2022-09-20 18:47:33 +08:00
$conditions = [];
if (!empty($_POST['classes'])) {
$conditions[] = "class IN (" . implode(', ', $_POST['classes']) . ")";
}
$conditions = apply_filter("role_query_conditions", $conditions, $_POST);
if (empty($conditions)) {
stderr("Error","No valid filter");
}
$whereStr = implode(' OR ', $conditions);
2022-08-10 17:38:05 +08:00
while (true) {
2022-08-11 23:41:11 +08:00
$msgValues = [];
2022-08-10 17:38:05 +08:00
$offset = ($page - 1) * $size;
2022-09-20 18:47:33 +08:00
$query = sql_query("SELECT id FROM users WHERE ($whereStr) and `enabled` = 'yes' and `status` = 'confirmed' limit $offset, $size");
2022-08-10 17:38:05 +08:00
while($dat=mysql_fetch_assoc($query))
{
$msgValues[] = sprintf('(%s, %s, %s, %s, %s)', $sender_id, $dat['id'], $dt, sqlesc($subject), sqlesc($msg));
}
2022-08-11 23:41:11 +08:00
if (empty($msgValues)) {
2022-08-10 17:38:05 +08:00
break;
}
$sql = "INSERT INTO messages (sender, receiver, added, subject, msg) VALUES " . implode(', ', $msgValues);
sql_query($sql);
$page++;
2020-12-26 01:42:23 +08:00
}
header("Location: staffmess.php?sent=1");
2020-12-26 01:42:23 +08:00
?>