人人商城

post-step.ctrl.php 14KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365
  1. <?php
  2. /**
  3. * [WeEngine System] Copyright (c) 2014 WE7.CC
  4. * WeEngine is NOT a free software, it under the license terms, visited http://www.we7.cc/ for more details.
  5. */
  6. defined('IN_IA') or exit('Access Denied');
  7. load()->func('file');
  8. load()->model('module');
  9. load()->model('user');
  10. load()->model('account');
  11. load()->classs('weixin.platform');
  12. $_W['page']['title'] = '添加/编辑公众号 - 公众号管理';
  13. $uniacid = intval($_GPC['uniacid']);
  14. $step = intval($_GPC['step']) ? intval($_GPC['step']) : 1;
  15. $user_create_account_info = permission_user_account_num();
  16. if($step == 1) {
  17. if ($user_create_account_info['uniacid_limit'] <= 0 && !$_W['isfounder']) {
  18. $authurl = "javascript:alert('创建公众号已达上限!');";
  19. }
  20. if (empty($authurl) && !empty($_W['setting']['platform']['authstate'])) {
  21. $account_platform = new WeixinPlatform();
  22. $authurl = $account_platform->getAuthLoginUrl();
  23. }
  24. } elseif ($step == 2) {
  25. if (!empty($uniacid)) {
  26. $state = permission_account_user_role($uid, $uniacid);
  27. if ($state != ACCOUNT_MANAGE_NAME_FOUNDER && $state != ACCOUNT_MANAGE_NAME_OWNER) {
  28. itoast('没有该公众号操作权限!', '', '');
  29. }
  30. if (is_error($permission = permission_create_account($_W['uid'], 2))) {
  31. itoast($permission['message'], '' , 'error');
  32. }
  33. } else {
  34. if (empty($_W['isfounder']) && is_error($permission = permission_create_account($_W['uid'], 1))) {
  35. if (is_error($permission = permission_create_account($_W['uid'], 2))) {
  36. itoast($permission['message'], '' , 'error');
  37. }
  38. }
  39. }
  40. if (checksubmit('submit')) {
  41. if ($user_create_account_info['uniacid_limit'] <= 0 && !$_W['isfounder']) {
  42. itoast('创建公众号已达上限!');
  43. }
  44. $update = array();
  45. $update['name'] = trim($_GPC['cname']);
  46. if(empty($update['name'])) {
  47. itoast('公众号名称必须填写', '', '');
  48. }
  49. if (empty($uniacid)) {
  50. $name = trim($_GPC['cname']);
  51. $description = trim($_GPC['description']);
  52. $data = array(
  53. 'name' => $name,
  54. 'description' => $description,
  55. 'title_initial' => get_first_pinyin($name),
  56. 'groupid' => 0,
  57. );
  58. $account_table = table('account');
  59. $account_table->searchWithTitle($name);
  60. $account_table->searchWithType(ACCOUNT_TYPE_OFFCIAL_NORMAL);
  61. $check_uniacname = $account_table->searchAccountList();
  62. if (!empty($check_uniacname)) {
  63. itoast('该公众号名称已经存在', '', '');
  64. }
  65. if (!pdo_insert('uni_account', $data)) {
  66. itoast('添加公众号失败', '', '');
  67. }
  68. $uniacid = pdo_insertid();
  69. $template = pdo_fetch('SELECT id,title FROM ' . tablename('site_templates') . " WHERE name = 'default'");
  70. $styles['uniacid'] = $uniacid;
  71. $styles['templateid'] = $template['id'];
  72. $styles['name'] = $template['title'] . '_' . random(4);
  73. pdo_insert('site_styles', $styles);
  74. $styleid = pdo_insertid();
  75. $multi['uniacid'] = $uniacid;
  76. $multi['title'] = $data['name'];
  77. $multi['styleid'] = $styleid;
  78. pdo_insert('site_multi', $multi);
  79. $multi_id = pdo_insertid();
  80. $unisettings['creditnames'] = array('credit1' => array('title' => '积分', 'enabled' => 1), 'credit2' => array('title' => '余额', 'enabled' => 1));
  81. $unisettings['creditnames'] = iserializer($unisettings['creditnames']);
  82. $unisettings['creditbehaviors'] = array('activity' => 'credit1', 'currency' => 'credit2');
  83. $unisettings['creditbehaviors'] = iserializer($unisettings['creditbehaviors']);
  84. $unisettings['uniacid'] = $uniacid;
  85. $unisettings['default_site'] = $multi_id;
  86. $unisettings['sync'] = iserializer(array('switch' => 0, 'acid' => ''));
  87. pdo_insert('uni_settings', $unisettings);
  88. pdo_insert('mc_groups', array('uniacid' => $uniacid, 'title' => '默认会员组', 'isdefault' => 1));
  89. $fields = pdo_getall('profile_fields');
  90. foreach($fields as $field) {
  91. $data = array(
  92. 'uniacid' => $uniacid,
  93. 'fieldid' => $field['id'],
  94. 'title' => $field['title'],
  95. 'available' => $field['available'],
  96. 'displayorder' => $field['displayorder'],
  97. );
  98. pdo_insert('mc_member_fields', $data);
  99. }
  100. }
  101. $update['account'] = trim($_GPC['account']);
  102. $update['original'] = trim($_GPC['original']);
  103. $update['level'] = intval($_GPC['level']);
  104. $update['key'] = trim($_GPC['key']);
  105. $update['secret'] = trim($_GPC['secret']);
  106. $update['type'] = ACCOUNT_TYPE_OFFCIAL_NORMAL;
  107. $update['encodingaeskey'] = trim($_GPC['encodingaeskey']);
  108. if (user_is_vice_founder()) {
  109. uni_user_account_role($uniacid, $_W['uid'], ACCOUNT_MANAGE_NAME_VICE_FOUNDER);
  110. }
  111. if (empty($acid)) {
  112. $acid = account_create($uniacid, $update);
  113. if(is_error($acid)) {
  114. itoast('添加公众号信息失败', url('account/post-step/', array('uniacid' => $uniacid, 'step' => 2)), 'error');
  115. }
  116. pdo_update('uni_account', array('default_acid' => $acid), array('uniacid' => $uniacid));
  117. if (empty($_W['isfounder'])) {
  118. uni_user_account_role($uniacid, $_W['uid'], ACCOUNT_MANAGE_NAME_OWNER);
  119. }
  120. if (!empty($_W['user']['owner_uid'])) {
  121. uni_user_account_role($uniacid, $_W['user']['owner_uid'], ACCOUNT_MANAGE_NAME_VICE_FOUNDER);
  122. }
  123. } else {
  124. pdo_update('account', array('type' => ACCOUNT_TYPE_OFFCIAL_NORMAL, 'hash' => ''), array('acid' => $acid, 'uniacid' => $uniacid));
  125. unset($update['type']);
  126. pdo_update('account_wechats', $update, array('acid' => $acid, 'uniacid' => $uniacid));
  127. }
  128. if(parse_path($_GPC['qrcode']) && in_array(pathinfo($_GPC['qrcode'], PATHINFO_EXTENSION), $_W['config']['upload']['image']['extentions'])) {
  129. copy($_GPC['qrcode'], IA_ROOT . '/attachment/qrcode_'.$acid.'.jpg');
  130. }
  131. if(parse_path($_GPC['headimg']) && in_array(pathinfo($_GPC['qrcode'], PATHINFO_EXTENSION), $_W['config']['upload']['image']['extentions'])) {
  132. copy($_GPC['headimg'], IA_ROOT . '/attachment/headimg_'.$acid.'.jpg');
  133. }
  134. $oauth = uni_setting($uniacid, array('oauth'));
  135. if ($acid && !empty($update['key']) && !empty($update['secret']) && empty($oauth['oauth']['account']) && $update['level'] == ACCOUNT_SERVICE_VERIFY) {
  136. pdo_update('uni_settings', array('oauth' => iserializer(array('account' => $acid, 'host' => $oauth['oauth']['host']))), array('uniacid' => $uniacid));
  137. }
  138. cache_delete(cache_system_key('unisetting', array('uniacid' => $uniacid)));
  139. if (!empty($_GPC['uniacid']) || empty($_W['isfounder'])) {
  140. header("Location: ".url('account/post-step/', array('uniacid' => $uniacid, 'acid' => $acid, 'step' => 4)));
  141. } else {
  142. header("Location: ".url('account/post-step/', array('uniacid' => $uniacid, 'acid' => $acid, 'step' => 3)));
  143. }
  144. exit;
  145. }
  146. }elseif ($step == 3) {
  147. $acid = intval($_GPC['acid']);
  148. $uniacid = intval($_GPC['uniacid']);
  149. if (empty($_W['isfounder'])) {
  150. itoast('您无权进行该操作!', '', '');
  151. }
  152. if ($_GPC['get_type'] == 'userinfo' && $_W['ispost']) {
  153. $result = array();
  154. $uid = intval($_GPC['uid'][0]);
  155. $user = user_single(array('uid' => $uid));
  156. if (empty($user)) {
  157. iajax(-1, '用户不存在或是已经被删除', '');
  158. }
  159. $result['username'] = $user['username'];
  160. $result['uid'] = $user['uid'];
  161. $result['group'] = user_group_detail_info($user['groupid']);
  162. $result['package'] = iunserializer($result['group']['package']);
  163. iajax(0, $result, '');
  164. exit;
  165. }
  166. if (checksubmit('submit')) {
  167. $uid = intval($_GPC['uid']);
  168. $groupid = intval($_GPC['groupid']);
  169. if (!empty($uid)) {
  170. $create_account_info = permission_user_account_num($uid);
  171. if ($create_account_info['uniacid_limit'] <= 0 && (!user_is_founder($_W['uid']) || user_is_vice_founder())) {
  172. itoast("您所设置的主管理员所在的用户组可添加的公众号数量已达上限,请选择其他人做主管理员!", referer(), 'error');
  173. }
  174. pdo_delete('uni_account_users', array('uniacid' => $uniacid, 'uid' => $uid));
  175. $owner = pdo_get('uni_account_users', array('uniacid' => $uniacid, 'role' => 'owner'));
  176. if (!empty($owner)) {
  177. pdo_update('uni_account_users', array('uid' => $uid), array('uniacid' => $uniacid, 'role' => 'owner'));
  178. } else {
  179. uni_user_account_role($uniacid, $uid, ACCOUNT_MANAGE_NAME_OWNER);
  180. }
  181. $user_vice_id = pdo_getcolumn('users', array('uid' => $uid), 'owner_uid');
  182. if ($_W['user']['founder_groupid'] != ACCOUNT_MANAGE_GROUP_VICE_FOUNDER && !empty($user_vice_id)) {
  183. uni_user_account_role($uniacid, $user_vice_id, ACCOUNT_MANAGE_NAME_VICE_FOUNDER);
  184. }
  185. }
  186. if (!empty($_GPC['signature'])) {
  187. $signature = trim($_GPC['signature']);
  188. $setting = pdo_get('uni_settings', array('uniacid' => $_W['uniacid']));
  189. $notify = iunserializer($setting['notify']);
  190. $notify['sms']['signature'] = $signature;
  191. uni_setting_save('notify', $notify);
  192. $notify = serialize($notify);
  193. pdo_update('uni_settings', array('notify' => $notify), array('uniacid' => $uniacid));
  194. }
  195. $user = array(
  196. 'uid' => $uid,
  197. 'groupid' => $groupid,
  198. );
  199. if ($_GPC['is-set-endtime'] == 1 && !empty($_GPC['endtime'])) {
  200. $user['endtime'] = strtotime($_GPC['endtime']);
  201. } else {
  202. $user['endtime'] = 0;
  203. }
  204. if (!empty($user)) {
  205. user_update($user);
  206. }
  207. pdo_delete('uni_account_group', array('uniacid' => $uniacid));
  208. if (!empty($_GPC['package'])) {
  209. $group = pdo_get('users_group', array('id' => $groupid));
  210. $group['package'] = iunserializer($group['package']);
  211. if (!is_array($group['package']) || !in_array('-1', $group['package'])) {
  212. foreach ($_GPC['package'] as $packageid) {
  213. if (!empty($packageid)) {
  214. pdo_insert('uni_account_group', array(
  215. 'uniacid' => $uniacid,
  216. 'groupid' => $packageid,
  217. ));
  218. }
  219. }
  220. }
  221. }
  222. if (!empty($_GPC['extra']['modules']) || !empty($_GPC['extra']['templates'])) {
  223. $data = array(
  224. 'modules' => array('modules' => array(), 'wxapp' => array(), 'webapp' => array(), 'xzapp' => array(), 'phoneapp' => array()),
  225. 'templates' => iserializer($_GPC['extra']['templates']),
  226. 'uniacid' => $uniacid,
  227. 'name' => '',
  228. );
  229. $account = pdo_get('account', array('uniacid' => $uniacid));
  230. if (empty($account)) {
  231. itoast('无效的 uniacid', '', '');
  232. }
  233. switch ($account['type']) {
  234. case ACCOUNT_TYPE_OFFCIAL_NORMAL:
  235. case ACCOUNT_TYPE_OFFCIAL_AUTH:
  236. $data['modules']['modules'] = $_GPC['extra']['modules'];
  237. break;
  238. case ACCOUNT_TYPE_APP_NORMAL:
  239. case ACCOUNT_TYPE_APP_AUTH:
  240. case ACCOUNT_TYPE_WXAPP_WORK:
  241. $data['modules']['wxapp'] = $_GPC['extra']['modules'];
  242. break;
  243. case ACCOUNT_TYPE_WEBAPP_NORMAL:
  244. $data['modules']['webapp'] = $_GPC['extra']['modules'];
  245. break;
  246. case ACCOUNT_TYPE_XZAPP_NORMAL:
  247. case ACCOUNT_TYPE_XZAPP_AUTH:
  248. $data['modules']['xzapp'] = $_GPC['extra']['modules'];
  249. break;
  250. case ACCOUNT_TYPE_PHONEAPP_NORMAL:
  251. $data['modules']['phoneapp'] = $_GPC['extra']['modules'];
  252. break;
  253. }
  254. $data['modules'] = iserializer($data['modules']);
  255. $id = pdo_fetchcolumn("SELECT id FROM ".tablename('uni_group')." WHERE uniacid = :uniacid", array(':uniacid' => $uniacid));
  256. if (empty($id)) {
  257. pdo_insert('uni_group', $data);
  258. } else {
  259. pdo_update('uni_group', $data, array('id' => $id));
  260. }
  261. } else {
  262. pdo_delete('uni_group', array('uniacid' => $uniacid));
  263. }
  264. cache_delete(cache_system_key('uniaccount', array('uniacid' => $uniacid)));
  265. cache_delete(cache_system_key('unimodules', array('uniacid' => $uniacid, 'enabled' => 1)));
  266. cache_delete(cache_system_key('unimodules', array('uniacid' => $uniacid, 'enabled' => '')));
  267. cache_delete(cache_system_key('accesstoken', array('acid' => $acid)));
  268. cache_delete(cache_system_key('proxy_wechatpay_account'));
  269. cache_clean(cache_system_key('user_accounts'));
  270. if (!empty($_GPC['from'])) {
  271. itoast('公众号权限修改成功', url('account/post-step/', array('uniacid' => $uniacid, 'step' => 3, 'from' => 'list')), 'success');
  272. } else {
  273. header("Location: ".url('account/post-step/', array('uniacid' => $uniacid, 'acid' => $acid, 'step' => 4)));
  274. exit;
  275. }
  276. }
  277. $unigroups = uni_groups();
  278. if(!empty($unigroups['modules'])) {
  279. foreach ($unigroups['modules'] as $module_key => $module_val) {
  280. if(file_exists(IA_ROOT.'/addons/'.$module_val['name'].'/icon-custom.jpg')) {
  281. $unigroups['modules'][$module_key]['logo'] = tomedia(IA_ROOT.'/addons/'.$module_val['name'].'/icon-custom.jpg');
  282. }else {
  283. $unigroups['modules'][$module_key]['logo'] = tomedia(IA_ROOT.'/addons/'.$module_val['name'].'/icon.jpg');
  284. }
  285. }
  286. }
  287. $settings = uni_setting($uniacid, array('notify'));
  288. $notify = $settings['notify'] ? $settings['notify'] : array();
  289. $ownerid = pdo_fetchcolumn("SELECT uid FROM ".tablename('uni_account_users')." WHERE uniacid = :uniacid AND role = 'owner'", array(':uniacid' => $uniacid));
  290. if (!empty($ownerid)) {
  291. $owner = user_single(array('uid' => $ownerid));
  292. $owner['group'] = pdo_fetch("SELECT id, name, package FROM ".tablename('users_group')." WHERE id = :id", array(':id' => $owner['groupid']));
  293. $owner['group']['package'] = iunserializer($owner['group']['package']);
  294. }
  295. $extend = pdo_fetch("SELECT * FROM ".tablename('uni_group')." WHERE uniacid = :uniacid", array(':uniacid' => $uniacid));
  296. $extend['templates'] = iunserializer($extend['templates']);
  297. $extend['modules'] = iunserializer($extend['modules']);
  298. if (!empty($extend['modules'])) {
  299. $extend_modules = $extend['modules'];
  300. $extend['modules'] = array();
  301. foreach ($extend_modules as $modulenames) {
  302. if (!empty($modulenames)) {
  303. $extend['modules'] = array_merge($extend['modules'], $modulenames);
  304. }
  305. }
  306. $owner['extend']['modules'] = pdo_getall('modules', array('name' => $extend['modules']));
  307. if (!empty($owner['extend']['modules'])) {
  308. foreach ($owner['extend']['modules'] as &$extend_module) {
  309. if (file_exists(IA_ROOT.'/addons/'.$extend_module['name'].'/icon-custom.jpg')) {
  310. $extend_module['logo'] = tomedia(IA_ROOT.'/addons/'.$extend_module['name'].'/icon-custom.jpg');
  311. } else {
  312. $extend_module['logo'] = tomedia(IA_ROOT.'/addons/'.$extend_module['name'].'/icon.jpg');
  313. }
  314. }
  315. unset($extend_module);
  316. }
  317. }
  318. if (!empty($extend['templates'])) {
  319. $owner['extend']['templates'] = pdo_getall('site_templates', array('id' => $extend['templates']));
  320. }
  321. $extend['package'] = pdo_getall('uni_account_group', array('uniacid' => $uniacid), array(), 'groupid');
  322. $groups = user_group();
  323. $modules = user_modules($_W['uid']);
  324. $modules = array_filter($modules, function($module) {
  325. return empty($module['issystem']);
  326. });
  327. $templates = pdo_fetchall("SELECT * FROM ".tablename('site_templates'));
  328. } elseif($step == 4) {
  329. $uniacid = intval($_GPC['uniacid']);
  330. $acid = intval($_GPC['acid']);
  331. $uni_account = pdo_get('uni_account', array('uniacid' => $uniacid));
  332. if (empty($uni_account)) {
  333. itoast('非法访问', '', '');
  334. }
  335. $account = account_fetch($uni_account['default_acid']);
  336. }
  337. template('account/post-step' . $template_show);