人人商城

article.ctrl.php 9.4KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262
  1. <?php
  2. /**
  3. * [WeEngine System] Copyright (c) 2014 WE7.CC
  4. * WeEngine is NOT a free software, it under the license terms, visited http://www.we7.cc/ for more details.
  5. */
  6. defined('IN_IA') or exit('Access Denied');
  7. load()->func('file');
  8. load()->model('article');
  9. load()->model('account');
  10. $dos = array('display', 'post', 'del');
  11. $do = in_array($do, $dos) ? $do : 'display';
  12. permission_check_account_user('platform_site_article');
  13. $_W['page']['title'] = '文章管理 - 微官网';
  14. $category = pdo_fetchall("SELECT id,parentid,name FROM ".tablename('site_category')." WHERE uniacid = '{$_W['uniacid']}' AND enabled=1 ORDER BY parentid ASC, displayorder ASC, id ASC ", array(), 'id');
  15. $parent = array();
  16. $children = array();
  17. if (!empty($category)) {
  18. foreach ($category as $cid => $cate) {
  19. if (!empty($cate['parentid'])) {
  20. $children[$cate['parentid']][] = $cate;
  21. } else {
  22. $parent[$cate['id']] = $cate;
  23. }
  24. }
  25. }
  26. if ($do == 'display') {
  27. $pindex = max(1, intval($_GPC['page']));
  28. $psize = 20;
  29. $condition = '';
  30. $params = array();
  31. if (!empty($_GPC['keyword'])) {
  32. $condition .= " AND `title` LIKE :keyword";
  33. $params[':keyword'] = "%{$_GPC['keyword']}%";
  34. }
  35. if (!empty($_GPC['category']['childid'])) {
  36. $cid = intval($_GPC['category']['childid']);
  37. $condition .= " AND ccate = '{$cid}'";
  38. } elseif (!empty($_GPC['category']['parentid'])) {
  39. $cid = intval($_GPC['category']['parentid']);
  40. $condition .= " AND pcate = '{$cid}'";
  41. }
  42. $list = pdo_fetchall("SELECT * FROM ".tablename('site_article')." WHERE uniacid = '{$_W['uniacid']}' $condition ORDER BY displayorder DESC, edittime DESC, id DESC LIMIT ".($pindex - 1) * $psize.','.$psize, $params);
  43. $total = pdo_fetchcolumn('SELECT COUNT(*) FROM ' . tablename('site_article') . " WHERE uniacid = '{$_W['uniacid']}'".$condition, $params);
  44. $pager = pagination($total, $pindex, $psize);
  45. $article_ids = array();
  46. if (!empty($list)) {
  47. foreach ($list as $item) {
  48. $article_ids[] = $item['id'];
  49. }
  50. }
  51. $article_comment = table('sitearticlecomment')->srticleCommentUnread($article_ids);
  52. $setting = uni_setting($_W['uniacid']);
  53. template('site/article-display');
  54. } elseif ($do == 'post') {
  55. $id = intval($_GPC['id']);
  56. $template = uni_templates();
  57. $pcate = intval($_GPC['pcate']);
  58. $ccate = intval($_GPC['ccate']);
  59. if (!empty($id)) {
  60. $item = pdo_fetch("SELECT * FROM ".tablename('site_article')." WHERE id = :id" , array(':id' => $id));
  61. $item['type'] = explode(',', $item['type']);
  62. $pcate = $item['pcate'];
  63. $ccate = $item['ccate'];
  64. if (empty($item)) {
  65. itoast('抱歉,文章不存在或是已经删除!', '', 'error');
  66. }
  67. $key = pdo_fetchall('SELECT content FROM ' . tablename('rule_keyword') . ' WHERE rid = :rid AND uniacid = :uniacid', array(':rid' => $item['rid'], ':uniacid' => $_W['uniacid']));
  68. if (!empty($key)) {
  69. $keywords = array();
  70. foreach ($key as $row) {
  71. $keywords[] = $row['content'];
  72. }
  73. $keywords = implode(',', array_values($keywords));
  74. }
  75. $item['credit'] = iunserializer($item['credit']) ? iunserializer($item['credit']) : array();
  76. if (!empty($item['credit']['limit'])) {
  77. $credit_num = pdo_fetchcolumn('SELECT SUM(credit_value) FROM ' . tablename('mc_handsel') . ' WHERE uniacid = :uniacid AND module = :module AND sign = :sign', array(':uniacid' => $_W['uniacid'], ':module' => 'article', ':sign' => md5(iserializer(array('id' => $id)))));
  78. if (is_null($credit_num)) {
  79. $credit_num = 0;
  80. }
  81. $credit_yu = (($item['credit']['limit'] - $credit_num) < 0) ? 0 : $item['credit']['limit'] - $credit_num;
  82. }
  83. } else {
  84. $item['credit'] = array();
  85. $keywords = '';
  86. }
  87. if (checksubmit('submit')) {
  88. if (empty($_GPC['title'])) {
  89. itoast('标题不能为空,请输入标题!', '', '');
  90. }
  91. $sensitive_title = detect_sensitive_word($_GPC['title']);
  92. if (!empty($sensitive_title)) {
  93. itoast('不能使用敏感词:' . $sensitive_title, '', '');
  94. }
  95. $sensitive_content = detect_sensitive_word($_GPC['content']);
  96. if (!empty($sensitive_content)) {
  97. itoast('不能使用敏感词:' . $sensitive_content, '', '');
  98. }
  99. $data = array(
  100. 'uniacid' => $_W['uniacid'],
  101. 'iscommend' => intval($_GPC['option']['commend']),
  102. 'ishot' => intval($_GPC['option']['hot']),
  103. 'pcate' => intval($_GPC['category']['parentid']),
  104. 'ccate' => intval($_GPC['category']['childid']),
  105. 'template' => addslashes($_GPC['template']),
  106. 'title' => addslashes($_GPC['title']),
  107. 'description' => addslashes($_GPC['description']),
  108. 'content' => safe_gpc_html(htmlspecialchars_decode($_GPC['content'], ENT_QUOTES)),
  109. 'incontent' => intval($_GPC['incontent']),
  110. 'source' => addslashes($_GPC['source']),
  111. 'author' => addslashes($_GPC['author']),
  112. 'displayorder' => intval($_GPC['displayorder']),
  113. 'linkurl' => addslashes($_GPC['linkurl']),
  114. 'createtime' => TIMESTAMP,
  115. 'edittime' => TIMESTAMP,
  116. 'click' => intval($_GPC['click'])
  117. );
  118. if (!empty($_GPC['thumb'])) {
  119. if (file_is_image($_GPC['thumb'])) {
  120. $data['thumb'] = $_GPC['thumb'];
  121. }
  122. } elseif (!empty($_GPC['autolitpic'])) {
  123. $match = array();
  124. preg_match('/&lt;img.*?src=&quot;?(.+\.(jpg|jpeg|gif|bmp|png))&quot;/', $_GPC['content'], $match);
  125. if (!empty($match[1])) {
  126. $url = $match[1];
  127. $file = file_remote_attach_fetch($url);
  128. if (!is_error($file)) {
  129. $data['thumb'] = $file;
  130. file_remote_upload($file);
  131. }
  132. }
  133. } else {
  134. $data['thumb'] = '';
  135. }
  136. $keyword = str_replace(',', ',', trim($_GPC['keyword']));
  137. $keyword = explode(',', $keyword);
  138. if (!empty($keyword)) {
  139. $rule['uniacid'] = $_W['uniacid'];
  140. $rule['name'] = '文章:' . $_GPC['title'] . ' 触发规则';
  141. $rule['module'] = 'news';
  142. $rule['status'] = 1;
  143. $keywords = array();
  144. foreach ($keyword as $key) {
  145. $key = trim($key);
  146. if (empty($key)) continue;
  147. $keywords[] = array(
  148. 'uniacid' => $_W['uniacid'],
  149. 'module' => 'news',
  150. 'content' => $key,
  151. 'status' => 1,
  152. 'type' => 1,
  153. 'displayorder' => 1,
  154. );
  155. }
  156. $reply['title'] = $_GPC['title'];
  157. $reply['description'] = $_GPC['description'];
  158. $reply['thumb'] = $data['thumb'];
  159. $reply['url'] = murl('site/site/detail', array('id' => $id));
  160. }
  161. if (!empty($_GPC['credit']['status'])) {
  162. $credit['status'] = intval($_GPC['credit']['status']);
  163. $credit['limit'] = intval($_GPC['credit']['limit']) ? intval($_GPC['credit']['limit']) : itoast('请设置积分上限', '', '');
  164. $credit['share'] = intval($_GPC['credit']['share']) ? intval($_GPC['credit']['share']) : itoast('请设置分享时赠送积分多少', '', '');
  165. $credit['click'] = intval($_GPC['credit']['click']) ? intval($_GPC['credit']['click']) : itoast('请设置阅读时赠送积分多少', '', '');
  166. $data['credit'] = iserializer($credit);
  167. } else {
  168. $data['credit'] = iserializer(array('status' => 0, 'limit' => 0, 'share' => 0, 'click' => 0));
  169. }
  170. if (empty($id)) {
  171. unset($data['edittime']);
  172. if (!empty($keywords)) {
  173. pdo_insert('rule', $rule);
  174. $rid = pdo_insertid();
  175. foreach ($keywords as $li) {
  176. $li['rid'] = $rid;
  177. pdo_insert('rule_keyword', $li);
  178. }
  179. $reply['rid'] = $rid;
  180. pdo_insert('news_reply', $reply);
  181. $data['rid'] = $rid;
  182. }
  183. pdo_insert('site_article', $data);
  184. $aid = pdo_insertid();
  185. pdo_update('news_reply', array('url' => murl('site/site/detail', array('id' => $aid))), array('rid' => $rid));
  186. } else {
  187. unset($data['createtime']);
  188. pdo_delete('rule', array('id' => $item['rid'], 'uniacid' => $_W['uniacid']));
  189. pdo_delete('rule_keyword', array('rid' => $item['rid'], 'uniacid' => $_W['uniacid']));
  190. pdo_delete('news_reply', array('rid' => $item['rid']));
  191. if (!empty($keywords)) {
  192. pdo_insert('rule', $rule);
  193. $rid = pdo_insertid();
  194. foreach ($keywords as $li) {
  195. $li['rid'] = $rid;
  196. pdo_insert('rule_keyword', $li);
  197. }
  198. $reply['rid'] = $rid;
  199. pdo_insert('news_reply', $reply);
  200. $data['rid'] = $rid;
  201. } else {
  202. $data['rid'] = 0;
  203. $data['kid'] = 0;
  204. }
  205. pdo_update('site_article', $data, array('id' => $id));
  206. }
  207. itoast('文章更新成功!', url('site/article/display'), 'success');
  208. } else {
  209. template('site/article-post');
  210. }
  211. } elseif($do == 'del') {
  212. if (checksubmit('submit')) {
  213. foreach ($_GPC['rid'] as $key => $id) {
  214. $id = intval($id);
  215. $row = pdo_get('site_article', array('id' => $id, 'uniacid' => $_W['uniacid']));
  216. if (empty($row)) {
  217. itoast('抱歉,文章不存在或是已经被删除!', '', '');
  218. }
  219. if (!empty($row['rid'])) {
  220. pdo_delete('rule', array('id' => $row['rid'], 'uniacid' => $_W['uniacid']));
  221. pdo_delete('rule_keyword', array('rid' => $row['rid'], 'uniacid' => $_W['uniacid']));
  222. pdo_delete('news_reply', array('rid' => $row['rid']));
  223. }
  224. pdo_delete('site_article', array('id' => $id, 'uniacid'=>$_W['uniacid']));
  225. }
  226. itoast('批量删除成功!', referer(), 'success');
  227. } else {
  228. $id = intval($_GPC['id']);
  229. $row = pdo_fetch("SELECT id,rid,kid,thumb FROM ".tablename('site_article')." WHERE id = :id", array(':id' => $id));
  230. if (empty($row)) {
  231. itoast('抱歉,文章不存在或是已经被删除!', '', '');
  232. }
  233. if (!empty($row['rid'])) {
  234. pdo_delete('rule', array('id' => $row['rid'], 'uniacid' => $_W['uniacid']));
  235. pdo_delete('rule_keyword', array('rid' => $row['rid'], 'uniacid' => $_W['uniacid']));
  236. pdo_delete('news_reply', array('rid' => $row['rid']));
  237. }
  238. if (pdo_delete('site_article', array('id' => $id,'uniacid'=>$_W['uniacid']))){
  239. itoast('删除成功!', referer(), 'success');
  240. } else {
  241. itoast('删除失败!', referer(), 'error');
  242. }
  243. }
  244. }