<?php
# Copyright by Manuel
# Support www.ilch.de
defined (
'main'
)
or
die
(
'no direct access'
);
$datum
=
date
(
"H:i - j.n.y"
);
$strich
=
date
(
"<br>"
);
if
( loggedin() ) {
$shoutbox_VALUE_name
=
$_SESSION
[
'authname'
];
}
else
{
$shoutbox_VALUE_name
=
'Nickname'
;
}
if
( !
empty
(
$_POST
[
'shoutbox_submit'
]) AND chk_antispam (
'shoutbox'
)) {
$shoutbox_nickname
= escape(
$_POST
[
'shoutbox_nickname'
],
'string'
);
$shoutbox_nickname
=
substr
(
$shoutbox_nickname
, 0, 19);
$shoutbox_textarea
= escape(
$_POST
[
'shoutbox_textarea'
],
'textarea'
);
$shoutbox_textarea
= preg_replace(
"/\[.?(url|b|i|u|img|code|quote)[^\]]*?\]/i"
,
""
,
$shoutbox_textarea
);
$shoutbox_textarea
=
strip_tags
(
$shoutbox_textarea
);
if
( !
empty
(
$shoutbox_nickname
) AND !
empty
(
$shoutbox_textarea
) ) {
db_query(
'INSERT INTO `prefix_shoutbox` VALUES ( "" , "'
.
$shoutbox_nickname
.
'" , "<br>'
.
$datum
.
'<br>'
.
$strich
.
'<br>'
.
$shoutbox_textarea
.
'" ) '
);
}
}
$users
=
''
;
if
(has_right(-1)) {
$readonly
=
'readonly="readonly"'
;
$user
=
'u'
;
$onfocus
=
''
;
}
else
{
$user
=
'g'
;
$uquery
= db_query(
"SELECT name FROM prefix_user"
);
while
(
$uds
= db_fetch_object(
$uquery
)) {
$username
=
$uds
-> name;
if
(!
empty
(
$users
))
$users
=
$users
.
', '
;
$users
=
$users
.
'"'
.
$username
.
'"'
;
}
$onfocus
=
'onFocus="if (value == \''
.
$shoutbox_VALUE_name
.
'\') {value = \'\'}" onBlur="if (value == \'\') {value = \''
.
$shoutbox_VALUE_name
.
'\'}"'
;
}
echo
'<script language="JavaScript" type="text/javascript">'
;
echo
' user = new Array('
.
$users
.
');'
;
echo
' </script>'
;
echo
' <script language="JavaScript" src="include/includes/js/comments.js" type="text/javascript"></script>'
;
echo
'<form action="index.php" method="POST" name="shoutbox" onsubmit="return chkShoutbox'
.
$user
.
'()">'
;
echo
'<input type="text" size="15" name="shoutbox_nickname" value="'
.
$shoutbox_VALUE_name
.
'" '
.
$onfocus
.
' maxlength="15" '
.
$readonly
.
' >'
;
echo
'<br /><textarea style="width: 80%" cols="19" rows="2" name="shoutbox_textarea"></textarea><br />'
;
if
(!has_right(-1))
echo
get_antispam (
'shoutbox'
, 0);
echo
'<input type="submit" value="'
.
$lang
[
'formsub'
].
'" name="shoutbox_submit">'
;
echo
'</form><table width="90%" class="border" cellpadding="2" cellspacing="1" border="0">'
;
$erg
= db_query(
'SELECT * FROM `prefix_shoutbox` ORDER BY id DESC LIMIT 5'
);
$class
=
'Cnorm'
;
while
(
$row
= db_fetch_object(
$erg
) ) {
$class
= (
$class
==
'Cmite'
?
'Cnorm'
:
'Cmite'
);
echo
'<tr class="'
.
$class
.
'"><td><b>'
.
$row
->nickname.
':</b><br />'
.preg_replace(
'/([^\s]{20})(?=[^\s])/'
,
"$1\n"
,
$row
->textarea).
'</td></tr>'
;
}
echo
'</table><a class="box" href="index.php?shoutbox">'
.
$lang
[
'archiv'
].
'</a>'
;
?>