include_once '../../sys/inc/start.php'; include_once '../../sys/inc/compress.php'; include_once '../../sys/inc/sess.php'; include_once '../../sys/inc/home.php'; include_once '../../sys/inc/settings.php'; include_once '../../sys/inc/db_connect.php'; include_once '../../sys/inc/ipua.php'; include_once '../../sys/inc/fnc.php'; include_once '../../sys/inc/user.php'; only_reg(); $width = ($webbrowser == 'web' ? '200' : '200'); if (isset($_GET['id']))$ank['id'] = my_esc($_GET['id']); $ank = get_user($ank['id']); if(!$ank || $ank['id'] == 0 || $ank['id'] == $user['id']){ header("Location: /index.php?".SID); exit; } $set['title']="Подарок для $ank[nick]"; include_once '../../sys/inc/thead.php'; title().aut(); if($user['group_access']>='2'){ $cate_v = null; $gift_v =null; $sev_gifts = null; $sev_cats=null; }else{ $cate_v = "AND `cet_set` = '0'"; $gift_v = "AND `set_pod` = '0'"; $sev_gifts = "WHERE `set_pod` = '0' "; $sev_cats = "WHERE `cet_set` = '0'"; } echo ''; if (isset($_GET['gift'],$_GET['category'])) { $category = mysql_fetch_assoc(PDO("SELECT * FROM `gift_categories` WHERE `id` = '" . my_esc($_GET['category']) . "' $cate_v LIMIT 1")); $gift = mysql_fetch_assoc(PDO("SELECT * FROM `gift_list` WHERE `id` = '" . my_esc($_GET['gift']) . "' $gift_v AND `id_category` = '".$category['id']."' LIMIT 1")); if(!$gift || !$category){ $_SESSION['err'] = 'Нет такого подарка или категории'; header("Location:/user/gift/categories.php?id=$ank[id]"); exit; } if (isset($_POST['anonim']) && ($_POST['anonim']==0 || $_POST['anonim']==1 || $_POST['anonim']==2)) { $gift['anonim']=my_esc($_POST['anonim']); PDO("UPDATE `gift` SET `anonim` = '$gift[anonim]' WHERE `id_gift` = '$gift[id]' LIMIT 1"); } if (isset($_POST['ok'],$_GET['tocken']) && $user['tocken'] == $_GET['tocken']) { $msg = my_esc($_POST['msg']); if (!isset($_GET['tocken']) || $_GET['tocken'] != $user['tocken']){$err[]='Подмена токена!';} $tesh2=mysql_fetch_assoc(mysql_query("SELECT * FROM `user_collision` WHERE `id_user` = '".$ank['id']."' AND `id_user2` = '".$user['id']."' OR `id_user` = '".$user['id']."' AND `id_user2` = '".$ank['id']."'")); if($user['id']==$tesh2['id_user2'] || $user['id']==$tesh2['id_user']){ $err='Дарить подарки на свои ники нельзя!'; }else if($user['time']<'1800'){$err='Чтобы иметь возможность дарить подарки проведите на сайте более 30-ти минут!';}else if ($user['money'] < $gift['money']){ $err = 'У вас не достаточно средств на счету';} elseif(strlen2($msg)>=4000){$err='Слишком большое сообщение!';} $black =mysql_fetch_assoc(mysql_query("SELECT * FROM `user_black` WHERE `id_user` = '".$ank['id']."' AND `id_black` = '".$user['id']."' AND `razdel` LIKE '%info%' AND (`time`='0' OR `time`>'$time' ) LIMIT 1")); if($black){$err='Вы находитесь в чёрном списке этого пользователя!';} include H.'activday/size.php'; if(!isset($err)){ include H.'activday/avto_ban.php'; PDO("UPDATE `user` SET `money` = '" . ($user['money'] - $gift['money']) . "' WHERE `id` = '$user[id]'"); PDO("INSERT INTO `money` (`user`, `money`, `mp`, `usl`, `time`) values('$user[id]', '$gift[money]', '0', 'Подарок обитателю [url=/id$ank[id]][b]$ank[nick][/b][/url] ', '$time')"); PDO("INSERT INTO `gifts_user` (`id_user`, `id_ank`, `id_gift`, `coment`, `time` , `status`, `anonim`) values('$ank[id]', '$user[id]', '$gift[id]', '$msg', '$time', '1', '$gift[anonim]')"); $id_gift = mysql_insert_id(); PDO("INSERT INTO `notification` (`avtor`, `id_user`, `id_object`, `type`, `time`) VALUES ('$user[id]', '$ank[id]', '$id_gift', 'new_gift', '$time')"); $_SESSION['message'] = 'Ваш подарок успешно отправлен'; header("Location: /id$ank[id]"); exit; } } err(); echo '
'; echo '"; echo"