Compare commits

...
1336 Commits
Author SHA1 Message Date
whitedot 0d247c542c security: KVE-2026-2424 LG 가상계좌 통보 보호와 5.6.40 배포 준비 2026-09-20 23:44:01 +00:00
섭웨이bandGitHub 148d748c2d fix: 그누보드 5.6.391 쇼핑몰 분류 표시 수정 배포 병합
fix: 그누보드 5.6.391 쇼핑몰 분류 표시 수정 배포
2026-09-15 15:20:13 +09:00
whitedot de7063192e chore: 5.6.391 버전과 쇼핑몰 분류 표시 수정 배포 안내 준비 2026-09-15 06:19:00 +00:00
whitedot e2d215c368 fix: 쇼핑몰 5단계 분류 경로와 서브메뉴 표시 일관성 보완
PC·basic 테마 breadcrumb를 5단계로 확장하고 기존 위치와 스타일을 유지한다. PC·모바일 서브메뉴는 5단계가 있으면 해당 목록만, 없으면 4단계 형제 목록만 표시한다.

검증: 8개 분류 경로와 네 스킨의 메뉴·선택 상태, Chromium 목록·상세 단계별 레이아웃 검사, PHP 5.2 및 현재 PHP 구문 검사 통과.
2026-09-15 06:19:00 +00:00
섭웨이bandGitHub c4cd61c916 security: KVE-2026-2140 그누보드 5.6.39 보안 업데이트 배포 병합
주문 보호와 설치·업그레이드 보완 및 배포 안내를 반영한다.
2026-09-14 15:54:57 +09:00
whitedot f7aa440a80 security: KVE-2026-2140 주문 보호와 5.6.39 보안 업데이트 배포 2026-09-14 06:53:14 +00:00
섭웨이bandGitHub 2517343d51 chore: 그누보드 5.6.38 보안 업데이트 배포 병합
chore: 그누보드 5.6.38 보안 업데이트 배포
2026-09-10 14:19:12 +09:00
whitedot 6dec001465 chore: 5.6.38 버전과 보안 업데이트 배포 안내 준비 2026-09-10 05:17:59 +00:00
whitedot 062b33dde3 refactor: 장바구니·KCP 통보·간편결제 코드의 분기와 출력 가독성 개선
KCP 거래 검증과 가상계좌 처리를 분리하고 압축된 조건문과 대입문을 풀어 쓴다. 장바구니 검증에는 명시적인 블록과 단계 설명을 추가하고, 간편결제 표시값을 지역변수로 명명하여 HTML 조합을 읽기 쉽게 정리한다.

기존 검증 순서, SQL 처리 순서, 통보 응답 및 HTML 출력은 유지한다. KVE-2026-2345 및 KVE-2026-2346 수정 코드의 가독성 정리이며 새로운 보안 정책 변경은 없다.

검증: 장바구니 공통 46개, MyISAM·InnoDB 장바구니 HTTP/DB 126개 및 KCP HTTP/DB 420개 통과. 간편결제 PHP·JavaScript 회귀 검사와 HTML 변경 전후 100개 조합 일치, PHP 문법 및 diff 공백 검사 통과. 실제 외부 PG 승인·입금은 수행하지 않았다.
2026-09-10 05:17:59 +00:00
whitedot 97b5d7e122 security: KVE-2026-2346 CRLF 설치본의 DB 업그레이드 중단 수정 2026-09-10 05:17:59 +00:00
whitedot 40096220e2 security: KVE-2026-2345 실제 설치 환경 검증 결과 기록
PHP·MySQL 실제 설치 환경의 수정 전 재현과 수정 후 차단, 정상 주문 저장 등 46개 시나리오 결과를 기록한다. 실제 PG와 브라우저 UI 등 미검증 범위를 구분한다.
2026-09-10 05:17:59 +00:00
whitedot 7a80ae913d security: KVE-2026-2346 KCP 통보 검증과 입금·망취소 재처리 보강
테스트·운영 발신지와 결제 당시 상점·거래·계좌·금액을 대조하여 위조 입금 처리를 차단한다. 개인결제와 연결 주문의 중복 가산을 막고 통보 이력과 목표값으로 MyISAM/InnoDB 중간 실패를 재처리한다.

DB 마이그레이션과 기존 거래 적용·복구 안내를 추가했다. 격리 HTTP/MySQL 검사 420개, PHP 문법 검사와 설치 스키마 대조가 통과했다. 실제 KCP 연동 확인과 배포·KISA 회신은 별도 진행이 필요하다.
2026-09-10 05:17:59 +00:00
whitedot 560aa0af47 security: KVE-2026-2345 승인 후 검증 실패 취소와 장바구니 병합 사전 검사
모바일 이니시스 승인 전 장바구니를 검증하고 승인 후 실패는 서버 세션으로 확인한 거래의 취소 결과를 기록한다. 기존 장바구니와 병합할 가격·수량 및 구매 자격도 변경 전에 확인한다.

공통 규칙 46개, SQLite 및 모의 PG 후속 회귀 25개와 PHP 문법 검사를 통과했다. 실제 MySQL·PG 통합 및 동시성 검증은 별도로 필요하다.
2026-09-10 05:17:59 +00:00
whitedot 6d4e75e1c9 security: KVE-2026-2345 장바구니 옵션 검증으로 상품대금 누락 차단
공통·기본 테마 AJAX와 일반 장바구니 요청에 동일한 상품·옵션 검증을 적용한다. 주문 준비 및 PC·모바일 주문 제출에서도 기존 행의 종류·가격·구성을 확인한다.

공통 규칙 46개와 격리 MySQL의 MyISAM·InnoDB HTTP/DB 검증 126개를 통과했다. 주문 검증은 PG·주문 저장 이전 경계까지이며 전체 결제 및 동시성 검증은 별도로 필요하다.
2026-09-10 05:17:59 +00:00
섭웨이bandGitHub 77e0cda39b Merge pull request #384 from gnuboard/promote/v5.6.37
release: 그누보드 5.6.37 배포
2026-09-09 16:59:48 +09:00
whitedot cf8fc646ea build: 배포 압축파일에서 로컬 검증 디렉터리 제외 2026-09-09 07:58:16 +00:00
whitedot e769d11b79 docs: 5.6.37 변경 사항과 필수 업그레이드 절차 정리 2026-09-09 07:58:16 +00:00
whitedot b356b3710c docs: 배포본에 없는 CLI 대신 관리자 DB업그레이드 절차 안내 2026-09-09 07:58:16 +00:00
whitedot 1ec79e8e33 chore: 그누보드 배포 버전을 5.6.37로 변경 2026-09-09 07:58:16 +00:00
whitedot 5bd9cd2d17 fix: 상품별 배송완료 시각을 기준으로 주문 포인트 지급
개별·일괄 완료 처리에서 완료 시각을 기록하고 해당 시각부터 지급 대기 기간을 계산한다. 기존 완료 상품은 종전 기준을 유지하며 0일 설정은 완료 처리 직후 지급한다.

신규 설치 스키마와 DB 마이그레이션을 추가했다. 임시 MySQL 테이블 회귀 테스트, PHP 문법 검사와 스키마 일치 검증을 통과했다.
2026-09-09 07:58:16 +00:00
whitedot e4bd69ab82 fix: 객체 캐시의 타입별 저장소 분리로 값 충돌 방지
기존 public 멤버를 유지하면서 기타 타입의 저장소에 타입 차원을 추가하고 캐시 접근 경로를 공통화한다. API와 clone 동작을 유지하고 직접 멤버 접근 코드의 이전 방법을 문서화한다.

검증: PHP 5.2.17 및 PHP 8.4.22에서 구문 검사와 객체 캐시 회귀 테스트 통과.
2026-09-09 07:58:16 +00:00
whitedot ff8e8741b3 security: KVE-2026-2344 관리자 날짜 필터 검증과 속성 인코딩으로 XSS 차단
보관함과 상품판매순위에서 날짜 전체 형식·실제 달력 날짜·기간 순서를 검증하고 잘못된 요청을 조회 전에 HTTP 400으로 거부한다. 날짜 출력과 조회 링크를 각각 인코딩하고 최초 조회·분류·정렬·페이징을 유지한다.

검증: 변경 PHP 문법 검사, 100개 잘못된 날짜 입력과 정상 조회·윤년·페이징 회귀 검사, Chromium 속성 주입 및 이벤트 차단 검사 통과. 실제 관리자 세션과 운영 DB 검증 및 배포는 미실행.
2026-09-09 07:58:16 +00:00
whitedot ded3349bfc fix: 간편결제 로고 확대를 없애고 큰 로고만 축소
L.pay·카카오페이·PAYCO는 원본 크기를 유지하고 다른 큰 로고를 축소한다. PNG 표시 폭이 원본 이하임을 확인하고 기본·테마 PC·모바일 표시를 검증했다.
2026-09-09 07:58:16 +00:00
whitedot 93b4352891 refactor: 일반 결제수단 아이콘 제거와 간편결제 로고 크기 통일
무통장입금·가상계좌·계좌이체·휴대폰·신용카드는 텍스트로 표시하고 사용하지 않는 SVG를 제거한다. 간편결제 로고는 비율을 유지하면서 표시 크기와 모바일 영역을 맞춘다. 기본·테마 PC·모바일 브라우저에서 표시와 선택 동작을 확인했다.
2026-09-09 07:58:16 +00:00
whitedot 53b954b47f fix: 입금과 가상계좌 아이콘 구분 및 토스페이·핀페이 로고 표시
무통장입금은 지폐와 입금 화살표, 가상계좌는 펼친 통장으로 구분한다. 토스페이와 핀페이 로고 원본 및 출처를 추가하고 기본·테마 PC·모바일에 적용한다. 브라우저에서 표시·정렬과 결제수단 선택을 확인했다.
2026-09-09 07:58:16 +00:00
whitedot 3510a03f57 fix: 결제수단 공통 CSS 충돌로 어긋난 아이콘과 텍스트 정렬 복구
기존 주문서의 label 표시 규칙이 아이콘 정렬을 덮어쓰지 않도록 선택자 우선순위를 보강한다. 실제 주문서와 동일한 상위 요소를 포함한 브라우저 화면에서 기본·테마 PC·모바일 표시와 선택 동작을 확인했다.
2026-09-09 07:58:16 +00:00
whitedot 83e3c00a05 refactor: 기본 결제수단 아이콘을 일관된 SVG 라인 스타일로 교체
무통장·가상계좌·계좌이체·휴대폰·신용카드 아이콘을 구분하고 기본 및 테마의 PC·모바일 크기와 정렬을 통일한다. 브라우저에서 네 가지 스타일의 아이콘 표시와 결제수단 선택을 확인했다.
2026-09-09 07:58:16 +00:00
whitedot 2adaa0a658 feat: PG별 간편결제 개별 표시와 기본 PG 우선 네이버페이 적용
KG이니시스·토스페이먼츠·NICEPAY·KCP의 설정과 PC·모바일 주문서 버튼을 공통 목록으로 관리한다. 기본 PG 네이버페이가 비활성인 경우에만 KCP 병용 경로를 제공한다.

토스 직접 호출 선택값과 일반 카드 전환 초기화, NICEPAY 결제수단 변경 이벤트, 토스 머니·복합결제 현금영수증 저장을 보완한다. 설정 컬럼 확장 마이그레이션과 회귀 테스트를 추가한다.

검증: 변경 PHP 14개 문법 검사, PHP·JavaScript 회귀 테스트, 신규 설치와 마이그레이션 스키마 비교 통과. 실제 PG 승인·취소 및 운영 DB 마이그레이션은 미실행.
2026-09-09 07:58:16 +00:00
whitedot a9ba776ef0 feat: 소셜 회원가입 휴대폰번호 수집과 입력 및 저장 지원
네이버 공식 JSON 프로필 API와 카카오 계정 프로필에서 동의한 정보를 수집한다. 카카오 국내 국가번호를 변환하고, PC·모바일 가입 화면에 닉네임·이메일·휴대폰번호 순서로 입력란을 표시한다.

필수값과 번호 형식을 검증하고 본인확인 사용 여부와 관계없이 휴대폰번호를 저장한다. 기존 본인확인 해시 검증은 유지한다.

검증: PHP 문법 검사, 모의 검증 85개, diff 공백 검사 통과. 실제 OAuth 가입·DB 저장·SMS/LMS 수신은 미검증.
2026-09-09 07:58:16 +00:00
whitedot 76b1122430 feat: 쇼핑몰 최하위 분류에서도 같은 단계 메뉴 유지 2026-09-09 07:58:16 +00:00
whitedot 313f1daeb0 docs: 보안 업데이트 배포 게시물과 운영자 조치 안내 초안 작성
고정 도메인 설정, 공식 CAPTCHA 서비스 이용, 기존 위험 첨부의 점검 및 웹 서버 설정 확인 사항을 배포 게시물 초안으로 정리한다.
2026-09-09 07:58:16 +00:00
whitedot 873839add7 security: KVE-2026-2329 XHTML 등 실행형 첨부를 저장 전에 차단
게시판·1:1문의·폼메일·쇼핑몰 로고의 PHP 업로드 검사에서 위험 확장자를 거부한다. 대소문자와 다중 확장자 등 파일명 변형을 검사하고 클라이언트 검사도 일치시킨다.

검증: 위험 파일 및 정상 이미지·문서 파일명 격리 검증, 저장 전 차단 검증, PHP·JavaScript 문법 검사 통과.
2026-09-09 07:58:16 +00:00
whitedot 65875b7f35 security: KVE-2026-2330 비회원 게시물 수정 인증과 토큰 발급 검증 강화
기존 비밀번호 확인 이력을 게시판·게시물·비밀번호에 결합하고 저장 전 검증한다. 인증은 30분 후 만료되며 저장 후 폐기한다. 일반 쓰기 토큰과 답변 세션으로 수정 인증을 대체할 수 없도록 한다.

1:1문의 토큰 발급을 로그인 회원의 해당 용도로 제한하고 게시판 토큰의 요청 경로와 대상을 확인한다. 최고관리자의 그누보드4 자료 이전은 유지한다.

검증: 비인증 수정 차단, 정상 비밀번호 변경 및 인증 폐기, 토큰 발급 엔드포인트 격리 검증과 PHP 문법 검사 통과.
2026-09-09 07:58:16 +00:00
whitedot fcc749bde3 security: KVE-2026-2269 KVE-2026-2331 보안 메일 링크를 고정 도메인으로 제한
검증된 G5_DOMAIN만 인증 및 수신 거부 링크에 사용하고 요청 Host로 대체하지 않는다. 설정 오류 시 인증값과 관련 회원정보를 변경하기 전에 발급을 중단한다.

검증: Host 변조 및 고정 주소 미설정·오류의 격리 메일 검증, PHP 문법 검사 통과.
2026-09-09 07:58:16 +00:00
whitedot 639b788ad1 fix: 게시물 제목을 UTF-8 문자 단위로 제한해 저장 오류 방지
제목의 255바이트 절단을 cut_str의 255자 제한으로 변경한다. 말줄임표를 붙이지 않아 허용 길이 이내의 한글 제목을 온전히 보존한다.

검증: 제보 제목과 한글·ASCII·혼합 문자열의 경계값, mbstring 유무, utf8·utf8mb4 임시 DB 저장 및 조회, PHP 문법 검사 통과.
2026-09-09 07:58:16 +00:00
whitedot 69709a79a7 feat: 관리자 회원 수정에 본인확인 정보 삭제 기능 추가
CI·DI 관련 식별값, 본인확인·성인인증 상태, 생년월일·성별과 인증 이력을 별도 요청으로 정리한다. 일반 회원정보와 이메일 인증 상태는 유지하고 삭제할 정보가 없는 경우 버튼을 숨긴다.

회원 수정·삭제 권한과 대상 회원 등급, POST·관리자 토큰·요청 출처를 검증한다.

검증: 변경 PHP 3개 문법 검사, 임시 DB의 권한·토큰·출처·대상 정보 삭제 및 다른 회원 보존 검사 통과. 브라우저에서 별도 폼 제출과 관리자 토큰 삽입 확인.
2026-09-09 07:58:16 +00:00
whitedot 672d05f968 feat: 메일 미인증 만료 회원을 기존 탈퇴 절차로 정리
메일 인증 기한이 지난 미인증 회원을 일일 정리에서 탈퇴 처리하고 본인확인 정보와 소셜 연결을 해제한다. 나머지 회원자료는 기존 탈퇴 후 삭제 정책에 따라 정리하며 아이디는 보존한다.

자진 탈퇴와 자동 정리에 공통 함수를 사용하고 인증 완료·재발송과의 동시 변경을 조건부 갱신으로 보호한다. 관리자 상태 표시와 설정 안내, 운영 문서를 함께 반영한다.

검증: 변경 PHP 6개 문법 검사, 임시 DB에서 만료 경계·재발송·동시 변경·자진 탈퇴·유예 후 정리 검사 통과.
2026-09-09 07:58:16 +00:00
whitedot d0f136cca0 feat: PC·모바일 주문서에 수량을 반영한 옵션가 표시 추가
장바구니 옵션금액과 수량을 곱한 합계를 상품별로 집계하여
PC·모바일 주문서에 옵션가를 표시한다. 기존 결제금액 계산은 유지한다.

검증: PC·모바일 주문서 PHP 문법 검사와 변경 내용 검토 완료.
2026-09-09 07:58:16 +00:00
whitedot fd303da77a chore: 로컬 운영 및 검증 스크립트 bin 디렉터리를 Git 추적에서 제외
bin 디렉터리를 무시 목록에 추가하고 기존 추적 파일을 인덱스에서 제거한다. 로컬 스크립트 파일은 유지한다.
2026-09-09 07:58:16 +00:00
whitedot e784186b0f feat: SIRK 전용 카카오페이 연동 종료와 기존 주문 지원 절차 추가
전용 신규 결제와 자동 취소를 차단하고 기존 주문 조회 및 실제 PG 취소 확인 후 수동 정리를 지원한다. 기존 DB와 일반 PG 경로를 보존하고 5.6.37 전환 및 사후지원 절차를 문서화한다.

검증: 변경 PHP 문법, SIRK 요청 차단, 설치 스키마 및 쇼핑몰 후설치 검사 통과. 실제 PG 결제·취소 검증은 별도 진행한다.
2026-09-09 07:58:05 +00:00
whitedot e74486e171 test: 쇼핑몰 미설치 업그레이드와 후설치 경로 검증 보강
전체 마이그레이션의 쇼핑몰 SQL 64개를 격리된 접두어에서 검사해 미설치 상태의 건너뛰기와 후설치 후 업그레이드를 확인한다. 쇼핑몰 추가 여부에 따른 운영 절차를 문서화한다.
2026-09-09 07:58:05 +00:00
whitedot 545e6a504d feat: DB업그레이드에서 기존 상태 검사와 확인 이력 등록 지원
미기록 항목의 실제 실행 조건을 읽기 전용으로 확인해 실행 불필요 상태를 구분한다. 명시적 요청에서 선행 항목부터 확인 이력을 등록하고 등록 버튼을 왼쪽에 배치한다.

부분 적용·게시판별 컬럼·조회 오류와 순차 등록·실패 이력·체크섬·잠금 보호 검증을 추가한다.
2026-09-09 07:58:05 +00:00
whitedot 1da82df500 feat: DB업그레이드에서 쇼핑몰 후설치 지원
쇼핑몰 미설치 사이트에서 최신 쇼핑몰 스키마를 명시적으로 추가한다. 기존 DB 설정을 보존하고 중복 설치를 차단하며, 기본 SMS 문구 길이를 보정한다.

격리된 접두어로 후설치·설정 보존·중복 실행 차단을 검증한다.
2026-09-09 07:58:05 +00:00
whitedot 5bdbf360b0 refactor: 일반 실행 경로의 DB 변경을 버전형 마이그레이션으로 이전
과거 누적 DDL과 데이터 보정을 시점별 SQL로 분리하고 관리자·CLI 실행기를 제공한다. 실행 순서, 잠금, 체크섬, 성공·실패 이력 및 개별 실행의 선행 조건을 검증한다.

기존 스키마의 부분 적용 복구와 설치 SQL 정합성 검사를 추가하고 실행·복구 절차를 문서화한다.
2026-09-09 07:58:05 +00:00
whitedot d111100856 feat: 메일 인증 링크 유효시간 설정 추가 2026-09-09 07:58:05 +00:00
whitedot 7b3c2e845b fix: 구 토스페이먼츠 테스트 MERT KEY 안내 보강
테스트결제 시 테스트용 MERT KEY로 변경해야 함을 환경설정 도움말, 저장 확인창과 관리자 상태 경고에 명시한다.
2026-09-09 07:58:04 +00:00
섭웨이bandGitHub c91b74d991 Merge pull request #383 from gnuboard/promote/v5.6.36
release: 그누보드 5.6.36 배포
2026-09-01 11:41:35 +09:00
whitedot 7ec4d3a66c chore: 그누보드 배포 버전을 5.6.36으로 변경 2026-09-01 11:40:16 +09:00
whitedot 05fe1b0cdb fix: JS와 CSS 캐시 버전을 파일 수정시간으로 자동 갱신
정적 자산 URL의 캐시 키를 파일 수정시간으로 생성하고 요청 내에서 같은 파일의 조회 결과를 재사용한다.
2026-09-01 11:40:15 +09:00
whitedot 0242e8f1a3 security: SVG 및 SVGZ 파일 업로드 차단
게시판, 1:1문의, 폼메일 및 쇼핑몰 설정의 클라이언트와 서버 검증에서 SVG 계열 파일 업로드를 거부한다.
2026-09-01 11:40:15 +09:00
whitedot 4e8474f231 chore: 제거된 알림톡 기능의 잔여 참조 정리
관리자 회원 내보내기와 결제 공통 파일에 남은 알림톡 관련 코드 및 스타일을 제거한다.
2026-09-01 11:40:15 +09:00
whitedot 71209fc7c9 security: KVE-2026-1899 KVE-2026-1900 KVE-2026-1909 입력 및 권한 검증 강화
상품 정렬값을 허용 목록으로 검증하고 관리자 권한 컨텍스트를 명확히 구분한다.

모바일 KCP의 Windows 명령 인자를 안전하게 조립하고 검증한다.
2026-09-01 11:40:15 +09:00
섭웨이bandGitHub 375a8336e8 Merge pull request #380 from gnuboard/promote/readme-public-pr-test
docs: 프로젝트 안내와 설치·보안·커밋 규칙 문서 추가
2026-08-25 15:30:14 +09:00
whitedot 120d2960f2 docs: 압축파일 설치에 GitHub Releases 다운로드 경로 추가 2026-08-25 15:28:04 +09:00
whitedot 9659cceae6 docs: README에 PHP·DB와 기능별 설치 요구사항 명시 2026-08-25 15:28:04 +09:00
whitedot 7e42eb78e4 docs: 한국어 문서와 커밋 메시지 작성 규칙 추가 2026-08-25 15:28:04 +09:00
whitedot e475219115 docs: expand installation and security guidance 2026-08-25 15:28:04 +09:00
whitedot c70260c8cf docs: add project README 2026-08-25 14:37:07 +09:00
thisgun bb6ed59052 버전 5.6.35 수정 2026-08-25 01:25:04 +00:00
thisgun d4dddaca57 [KVE-2026-1927] 관리자 메뉴 코드 요청값 개입 차단 및 회원 내보내기 저장 경로 보완
관리자 페이지는 자신의 메뉴 코드를 변수에 지정한 뒤 공통 파일을 include
하는데, 공통 파일의 extract 처리로 그 값이 요청값으로 대체될 수 있었다.
extract 이전에 요청 배열에서 해당 키를 제거하여 각 페이지가 지정한 값이
유지되도록 한다. 해당 키를 요청값으로 참조하는 코드는 없으므로 동작에
영향이 없다.

변수 자체를 unset 하는 방식은 페이지가 지정한 값까지 사라져 관리권한을
위임받은 계정이 자신의 메뉴에도 접근하지 못하게 되므로 사용하지 않는다.

회원 내보내기 파일의 저장 폴더와 파일 이름이 생성 시각만으로 구성되어
경로를 추측할 여지가 있어, 임의 문자열을 덧붙인다. 다운로드 주소는 서버가
생성해 전달하므로 기존 흐름에는 영향이 없으며, 지난 폴더 정리 조건도 함께
맞춘다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 7739b95be1fcbe764d888a9f0fba1522cc1ebacb)
2026-08-24 07:56:32 +00:00
thisgun 0080b199ea [KVE-2026-1823] 장바구니 배송비 구분값을 서버에서 결정하도록 수정
장바구니 담기에서 배송비 구분값을 요청값으로 받은 뒤 무료배송 상품과
착불 상품만 서버 값으로 다시 지정하고 있어, 일반 유료배송 상품은 요청값이
그대로 저장되고 배송비 산정 대상에서 빠졌다. 요청값 참조를 제거하고 상품
설정만으로 값을 결정하도록 하여 같은 기능의 AJAX 경로와 동작을 맞춘다.

네이버페이 주문에서도 장바구니에서 읽은 배송비 구분값을 요청 배열에 다시
담아 사용하던 것을 서버 전용 변수로 분리한다. 같은 키를 미리 채워 보내면
인덱스가 밀려 요청값이 사용될 수 있었다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 3dbb9034f6f9d6e91916d6dcb78b4c06bc11d733)
2026-08-24 07:56:32 +00:00
thisgun ebd18b6001 [KVE-2026-1813] 미완료주문 확정 처리 필드 정제 및 결제수단 출력 인코딩
미완료주문을 주문으로 확정할 때 임시 데이터에서 복원한 결제수단, 접속 IP,
테스트 결제 여부를 정제 없이 사용하던 것을 이웃 필드와 동일한 방식으로
처리한다. 접속 IP는 표기 형식에 맞지 않으면 저장하지 않고, 테스트 결제
여부는 정수로만 저장하며, 세 값 모두 배열로 전달된 경우를 함께 걸러낸다.

임시주문 저장 시 접속 IP와 테스트 결제 여부를 서버에서 결정하는 처리가
일반 주문 분기 안에만 있어 개인결제 경로에서는 요청값이 그대로 저장되던
것을 분기 밖으로 옮겨 항상 서버 값을 사용하도록 한다.

결제수단 값이 그대로 출력되던 관리자 주문상세, 주문목록, 부분취소 화면과
구매자 주문조회 화면(웹/모바일/테마)에 get_text() 인코딩을 적용한다.
주문상세는 표시 문자열을 여러 곳에서 재사용하므로 생성 지점에서 처리한다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 77069575096881a31b29fdf130c83226610bf8df)
2026-08-24 07:56:32 +00:00
thisgun 04a4de4923 스킨 목록 옵션 생성 시 디렉토리 열기 실패 처리 보강
get_list_skin_options()에서 존재하지 않는 스킨 경로가 지정된 경우
opendir() 반환값을 그대로 readdir()에 넘겨 PHP 8 이상에서 스크립트가
중단되던 문제를 수정한다. 아울러 결과 배열을 미리 초기화하여 패턴에
일치하는 스킨 파일이 하나도 없을 때 sort()에서 중단되던 경로도 함께
처리하고, readdir() 종료 조건을 명시적으로 비교하도록 변경한다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 4010d29295001c43b6ccd7b4e6414d0adfcc7b2e)
2026-08-24 07:44:22 +00:00
thisgun 96df43480b 게시판·1:1문의·쇼핑몰분류 상단/하단 파일 경로 처리 보강
콘텐츠와 동일하게, 게시판(bo_include)·1:1문의(qa_include)·쇼핑몰 분류
(ca_include)의 상단/하단 파일 경로도 저장 전에 먼저 정규화한 뒤 확장자와
위치를 검증하도록 순서를 조정한다. 정규화 과정에서 확장자가 사라져 검증을
우회하던 경로를 차단하고, data 디렉터리로 귀결되는 경로를 거부한다.

실행 직전 board_head/board_tail, qahead/qatail, shop 목록·상품 페이지에서도
승인 확장자와 data 디렉터리 여부를 다시 확인하는 is_content_include_allowed()
를 적용한다. 이미 저장된 경로도 실행 시 재확인된다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 0c6bca704725ebea2a584d4c06366282e9bc36d6)
2026-08-24 07:44:22 +00:00
thisgun 6571119db6 [KVE-2026-1806] 콘텐츠 include 경로 및 미완료주문 출력 처리 보강
콘텐츠 상단/하단 파일 경로를 저장 전에 먼저 정규화한 뒤 확장자와 위치를
검증하도록 순서를 조정한다. 정규화 과정에서 확장자가 사라져 검증을
우회하던 경로를 차단한다. 실행 직전 bbs/content.php 에서도 승인 확장자와
data 디렉터리 귀결 여부를 다시 확인하는 is_content_include_allowed() 를
적용하고, 콘텐츠 상단/하단 이미지 업로드는 이미지 파일만 허용하도록 검사한다.

미완료주문 상세의 결제방법 출력에 get_text() 인코딩을 적용하고, 임시주문
저장 시 정제한 결제수단 값을 원본에도 반영한다. 개인결제 주문 세션은
결제정보 검증을 통과한 뒤에만 설정한다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 196255d76912531d7e13861821bd59ca15c967d1)
2026-08-24 07:44:22 +00:00
thisgun 35acbfa750 나이스페이 API 통신 시 서버 인증서 검증 적용
nicepay_reqPost() 가 원격 서버 인증서를 검증하지 않고 통신하던 것을
검증하도록 변경한다. 이니시스 연동부는 이미 동일하게 처리하고 있다.
API 호스트 4곳(webapi, pg-api, dc1-api, dc2-api) 인증서 검증 통과를
확인했다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 6c888bd53d0a5949bb1e2fc96567c132622a6f8b)
2026-08-24 07:44:22 +00:00
thisgun d9c21ea018 나이스페이 에스크로 배송등록 및 현금영수증 처리 보정
에스크로 배송등록 실패 시 알림 대신 주문 관리자 메모에 결과를 기록하고
이후 처리를 중단한다. 현금영수증 발급 후 DB 반영에 실패한 경우 자동 취소
요청을 제거하고 관리자가 나이스페이에서 직접 확인하도록 안내를 변경한다.
가상계좌 취소 요청금액이 없을 때의 응답 코드를 명시한다.

patch_5631 의 '회귀 점검 후 결제 및 쿠폰존 보강'(4405ddc1c) 중
나이스페이 관련 변경만 적용했다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 3f6d013f9466d11eacba29e81ad515a9a0ceeeef)
2026-08-24 07:44:22 +00:00
thisgun 68be1c1f86 나이스페이 부분취소 및 취소응답 검증 보강
(cherry picked from commit df0bfff88cdccc93dd6a8315c166e49a9bb03a5a)
2026-08-24 07:44:22 +00:00
thisgun ff1f6d723b 나이스페이 승인 취소 안정성 보강
(cherry picked from commit 7c26e621c66805b2d162ed0293e570e29a11b4e8)
2026-08-24 07:44:22 +00:00
thisgun bb4d345add 나이스페이 부분취소 처리 보강
(cherry picked from commit ef0da4a903983f46934d5c14ac10adb93a673398)
2026-08-24 07:44:22 +00:00
thisgun 3678b92b2f 나이스페이 가상계좌 취소 환불정보 입력 추가
(cherry picked from commit bb6381d7a58e4690e438dafb0b625a175be4c34b)
2026-08-24 07:44:22 +00:00
thisgun c8d51529d1 관리자 나이스페이 결제 조회 추가
(cherry picked from commit 104123872ada30e75c3e11e6322b6ab16d808efa)
2026-08-24 07:44:22 +00:00
thisgun 129d0ea766 모바일 나이스페이 결제금액 동기화 수정
(cherry picked from commit 671693d3adefd7b9e7a1447fee2d046d8ebdf600)
2026-08-24 07:44:22 +00:00
thisgun d80289ff28 나이스페이 결제 검증 보강
(cherry picked from commit 8c8099c63eb30c5cfd4678cecedbfd029471065e)
2026-08-24 07:44:22 +00:00
thisgun c4b54a6219 나이스페이 실패 응답 처리 보강
(cherry picked from commit 1caea3176ef8d3fd6057fc9a7e6646878cdf3e0c)
2026-08-24 07:44:22 +00:00
thisgun 8e7ec335c3 나이스페이 결제 검증과 영수증 처리 보강
(cherry picked from commit 8bcd1bcbea25371bd0a5b196b71d2c1b4308479a)
2026-08-24 07:44:22 +00:00
thisgun 5a36b2d85d 나이스페이 통지와 취소 응답 처리 보강
(cherry picked from commit e65d17d227028fc5eabe4d6a831485bf27685c01)
2026-08-24 07:44:22 +00:00
thisgun 2b21804111 나이스페이 입금통지 주문 조건 완화
(cherry picked from commit 9c363f4bc31cfd9361b7631977c7f892942aee0b)
2026-08-24 07:44:22 +00:00
thisgun a21f3103bb 나이스페이 결제 응답 검증 보강
(cherry picked from commit 50c2d6b6cfeaa10bbb65b2537a05c0525528cc63)
2026-08-24 07:44:22 +00:00
thisgun f7106379b8 나이스페이 결제 검증 및 취소 처리 보강
(cherry picked from commit 1e03160280e0a6b23e9d4b01a8bd726bddccf2cd)
2026-08-24 07:44:22 +00:00
thisgun f4d184979f 쿠폰존 폼 초기화 배열의 중복 항목 정리
cp_price 가 두 번 선언되어 있어 하나를 제거하고, 폼 본문에서 참조하는
cz_id 를 초기화 대상에 추가한다.

cz_id 참조 지점은 현재 앞쪽 조건의 단축 평가로 도달하지 않으나,
조건이 바뀔 경우를 대비해 초기화 목록을 참조 항목과 일치시킨다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit c03b311e789642f0af3fe898e040afea28733e7c)
2026-08-24 07:44:22 +00:00
thisgun f6ec58ca18 session_check() 의 잘못된 이동 함수명 수정
그누보드4에서 5로 전환할 때 상수와 전역변수만 변경되고 함수명이
그대로 남아, 정의되지 않은 gotourl() 을 호출하고 있었다.
세션이 없는 상태로 이 함수가 실행되면 치명적 오류가 발생한다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit f62b0559b4c757da693e7fe1b78a5d5ec2364504)
2026-08-24 07:44:22 +00:00
thisgun a0e86f2bc8 환경설정 캡챠 입력란을 확인 버튼 옆으로 이동
캡챠가 문서 최하단에 생성되어, 확인을 누르면 페이지 끝까지 강제로
스크롤된 뒤 입력해야 했다. 페이지가 길어 위치를 찾기 어렵다는 의견이
있어 상단 고정 영역의 확인 버튼 옆에 노출하도록 변경한다.

- 캡챠 영역을 확인 버튼과 같은 고정 영역으로 이동하고 패널 형태로 표시
- 고정 노출이므로 강제 스크롤을 제거하고 입력란 포커스로 대체
- 좁은 화면에서 관리자 메뉴에 가려지지 않도록 표시 순서 조정

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 39b7637bab609600a21118966968f46ab1fb6546)
2026-08-24 07:44:22 +00:00
thisgun 4ecacec171 게시판그룹 삭제 경고의 게시판목록 링크 검색대상 값 정정
board_list.php 의 검색대상 값은 a.gr_id 이나 링크가 gr_id 로 전달하여
그룹에 속한 게시판이 조회되지 않던 문제를 수정한다.

접두사가 없는 gr_id 는 최고관리자가 아닌 경우 그룹 테이블을 함께
조회하는 구조에서 컬럼 모호성 오류가 발생하므로 a.gr_id 로 맞춘다.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit c6dd497a450bd5ba08d743efc26ba73fcdd9e626)
2026-08-24 07:44:22 +00:00
thisgun 913d1c66c7 쿠폰 다운로드 포인트 검사를 회원 단위로 직렬화
기존에는 쿠폰별로 잠금을 잡아, 같은 회원이 서로 다른 포인트 쿠폰을
동시에 요청하면 각 요청이 요청 시작 시점의 보유 포인트 값으로 검사를
통과하여 잔액보다 많은 쿠폰을 받을 수 있었다.

- 잠금 범위를 쿠폰별에서 회원별로 변경
- 보유 포인트를 잠금 획득 후 회원 테이블에서 다시 조회하여 검사

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit fd04b432cf34dfba52e281fc74391f8e2d48fe6b)
2026-08-24 07:44:22 +00:00
thisgun 42859072eb 회원가입 쿠폰 발급 재시도 상한 동작하도록 수정
쿠폰번호 중복 시 재생성을 반복하는 구간에서 재시도 횟수가 증가하지
않아 상한 검사가 동작하지 않았다. 중복이 계속 발생하면 조회를 반복하며
루프를 빠져나가지 못하므로 횟수 증가를 추가한다.

- bbs/register_form_update.php
- plugin/social/register_member_update.php

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit ad396a59d463df880739c1e9514e4aa61d883850)
2026-08-24 07:44:22 +00:00
thisgun 0ae67a652c [KVE-2026-1803] 쿠폰번호 생성에 안전한 난수원 적용
get_coupon_id() 가 microtime 기반 시드로 난수 생성기를 재시드하여
생성 가능한 쿠폰번호가 시드 공간 크기로 제한되던 문제를 수정한다.
기존 구현은 33^16 이 아닌 10^6 개의 값만 생성할 수 있어 전체 집합을
사전 계산할 수 있었다.

- get_random_token_string() 으로 난수 바이트를 얻어 쿠폰번호를 구성
- 문자 종류 수로 나누어 떨어지는 구간만 사용하여 문자 분포 편중 제거
- 헬퍼 미정의 환경을 위해 function_exists 가드 및 mt_rand 보완 경로 유지
- 쿠폰번호 형식(16자, 4자리 하이픈 구분)과 사용 문자는 기존과 동일

plugin/lgxpay/lgdacom/XPayClient.php 의 불필요한 재시드 호출 제거

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit a6cf071f405c79904f7861d5e5efc118f29005dc)
2026-08-24 07:44:22 +00:00
thisgun 516eac386f [KVE-2026-1785] 관리자 목록 검색필드 화이트리스트 누락 보완
검색필드가 SQL 컬럼명 위치에 검증 없이 삽입되던 관리자 목록 9개
파일에 허용 컬럼 목록을 추가한다. 허용 컬럼은 각 화면의 검색 UI가
제공하는 항목 기준이며, 미허용 값은 빈 문자열이 아닌 유효 컬럼으로
대체하여 SQL 문법 오류를 방지한다.

- adm/auth_list.php
- adm/board_list.php
- adm/boardgroup_list.php
- adm/boardgroupmember_list.php
- adm/point_list.php
- adm/poll_list.php
- adm/popular_list.php
- adm/shop_admin/inorderlist.php
- adm/shop_admin/personalpaylist.php

adm/member_list.php 의 불필요한 주석 제거

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit ff56beff8c6804013e830eb828779e02493cee52)
2026-08-24 07:44:22 +00:00
thisgun 188d0e30a0 KG이니시스 PRO 판정 조회 컬럼 통일
- 모니터 알림과 KG 대사 배치 쿼리에도 주문 환불금액을 포함해
  현황 목록·상세 화면과 동일한 기준으로 판정하도록 정리

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
(cherry picked from commit 1388bc323724128acf78b15a49767e39f9709491)
2026-08-24 07:44:22 +00:00
thisgun c450f8bbde 관리자 권한 문맥 오염 계열 접근권한 점검 및 보완
게시판/그룹 관리자 문맥(bo_table)으로 타 회원 콘텐츠에 접근·변조되지
않도록 $is_admin 판정을 최고관리자(super) 기준으로 통일.
- bbs/poll_etc_update.php : 설문 기타의견 삭제 소유권
- shop/itemqaformupdate.php : 상품문의 수정/삭제 소유권
- shop/itemuseformupdate.php : 사용후기 삭제 소유권
- bbs/current_connect.php : 게스트 IP 원본 표기
- shop/kakaopay/kakaopay_cancel.php : TID 기반 결제취소

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 46a005129464d1fbab518fcb70bf524b258e65fc)
2026-08-24 07:44:22 +00:00
thisgun b3aa81c74a [KVE-2026-1640] 1:1 문의 접근권한 우회 취약점 수정
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit a719c6ea5f6d38350f9dcda682a04dad31f6a454)
2026-08-24 07:44:22 +00:00
thisgun 11a26c82af [KVE-2026-1639] 쇼핑몰 주문정보 접근권한 우회 취약점 수정
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit d3e8ffc3d6a0af4e2abe9b798316ae1c504e7d37)
2026-08-24 07:44:21 +00:00
thisgun 43f626885e [KVE-2026-1638] 쇼핑몰 쿠폰 중복적용 취약점 수정
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit 88bfddd0e83353c15c424549b594b8f36593220f)
2026-08-24 07:44:21 +00:00
thisgun 0b6f081f76 버전 5.6.34 수정 2026-07-24 07:14:18 +00:00
thisgunandClaude Fable 5 adbd9c3acc KG이니시스 PRO 현황 부분취소 전액환불 종결 판정 추가
- 부분취소 합계로 전액 환불되고 주문도 취소된 거래는 일치 상태로 판정
- 현황 목록 필터·KG 대사·관리자 알림에 동일 기준 적용

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 07:11:51 +00:00
thisgunandClaude Fable 5 8fcbd2a9b1 INIpay PRO 주문 전체취소 흐름 개선
- 부분취소 이력이 있는 주문은 잔여 금액을 부분취소로 처리해 전체취소 지원
- 부분취소로 전액 환불된 주문과 KG에서 이미 취소된 주문은 주문 취소만 진행
- PG 승인취소 미선택 시 차단하지 않고 주문만 취소하며 처리 내용을 이력에 기록
- 남은 품목 취소로 주문 전체가 취소되는 경우에도 PG 취소 여부 확인창 표시

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 07:11:51 +00:00
thisgunandClaude Fable 5 f8c06a26cb 관리자 부분취소 팝업 처리 오류 수정
- 팝업에서 admin.js와 토큰키를 로드해 처리 요청이 검증을 통과하도록 수정
- 금액 입력 유효성 검사의 필드명 오타 수정

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 07:11:51 +00:00
thisgunandClaude Fable 5 1fd5ec46ae KG이니시스 PRO 현황 안내 문구 정비
- 안내 문구의 로컬 표현을 영카트로 통일
- PG와 영카트 주문이 모두 취소 상태로 일치하면 조치 불필요 문구 출력

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 06:25:17 +00:00
thisgunandClaude Fable 5 cbd70fbe18 KG이니시스 상점관리자에서 먼저 취소한 INIpay PRO 주문의 전체취소 허용
- 전체취소 전에 KG 거래상태를 조회해 이미 취소된 거래이면 주문 취소만 진행
- 조회 결과와 처리 사유를 결제 현황 이력에 기록

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 06:25:17 +00:00
thisgunandClaude Fable 5 bc07b8383e KG이니시스 INIpay PRO 주문자 이메일 확인 후 전달
- 주문서/개인결제 결제 시작 시 이메일 형식을 확인해 잘못된 경우 안내 후 중단
- 결제창 요청에서는 확인된 이메일만 선택 항목으로 전달해 결제가 막히지 않게 처리

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 06:25:17 +00:00
thisgunandClaude Opus 4.8 23c60a8ba1 SMS 아이코드 신청 링크 최신 경로로 교체
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-24 05:28:15 +00:00
thisgunandClaude Opus 4.8 abb777016d 부가서비스 신청 링크 최신화 및 나이스페이먼츠 추가
- 전자결제/본인확인/SMS 신청 링크를 sir.kr 최신 경로로 교체
- 신용카드 전자결제에 나이스페이먼츠 추가(4개 1열 배치, 카드 폭 조정)
- 나이스페이먼츠 신청 버튼 이미지 추가

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-24 05:19:41 +00:00
thisgun e45bd1d9e1 버전 5.6.33 수정 2026-07-24 01:04:31 +00:00
thisgunandClaude Fable 5 acdbcfd8ba KG이니시스 INIpay PRO 결제 연동 및 결제 처리 현황 추가
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 08:03:16 +00:00
thisgun 1f48f6bd80 버전 5.6.32 수정 2026-07-14 02:35:52 +00:00
thisgun 87d86d317e 소셜 로그인 앱 등록 링크 최신화 2026-07-13 08:55:10 +00:00
thisgun 7fa554f396 XSS 취약점 수정 2026-07-13 07:38:27 +00:00
thisgunandClaude Opus 4.8 6bc322c9d6 회원 여분필드 저장 시 입력값 정제 보완
- register_form_update.php에서 mb_1~mb_10을 다른 회원필드(mb_name 등)와
  동일하게 clean_xss_tags 처리하여 저장하도록 보완

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 07:36:19 +00:00
thisgun 43fba4407d [KVE-2025-1533] 미결제내역 임시주문 데이터 출력 시 이스케이프 보완 2026-07-13 07:36:19 +00:00
thisgunandClaude Opus 4.8 3d7fa04569 관리자 상태변경 엔드포인트에 요청 출처 검증 추가
- 상품이벤트/개인결제복사/SMS 번호·그룹·폼·업로드/방문로그 삭제 등
  POST 기반 상태변경 처리에 check_request_origin() 적용 (스킨 수정 불필요)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 07:20:32 +00:00
thisgun 82ee3ef438 [KVE-1525] SMS 번호·이모티콘 이동 처리 권한 속성 보완 2026-07-13 07:20:32 +00:00
thisgun 4049c6c164 [KVE-1524] 주문 상태변경 관리자 엔드포인트에 메뉴 권한 검증 추가 2026-07-13 07:15:09 +00:00
thisgun f80ed3946f Fix monthly visit date range end date 2026-07-01 08:41:11 +00:00
thisgunandClaude Opus 4.8 d7d5f26524 [KVE-2026-1233]취약점- 게시글 조회 시 wr_id 정수 처리 보완
- get_write() 진입 시 wr_id를 정수로 캐스팅하여 SQL 조건에 비정상 값이 전달되지 않도록 보완

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-30 02:05:11 +00:00
thisgun e0a42d8f46 버전 5.6.31 수정 2026-06-26 10:50:29 +00:00
thisgun 6c6787ec1f 상품 스킨 디렉토리 검증 보완 2026-06-26 10:40:28 +00:00
thisgunandClaude Opus 4.8 d419f430a9 [KVE-20206-1176]XSS 취약점 - 결제 전 주문 임시데이터 저장 요청 출처 검증 추가
- shop/ajax.orderdatasave.php에 check_request_origin() 적용하여
  외부 사이트발 자동 요청에 의한 임시 주문 데이터 교체 차단

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-24 07:10:24 +00:00
thisgunandClaude Opus 4.8 1a5661a995 접속자검색 접속경로 출력 시 속성값 이스케이프 보완
- vi_referer 디코딩 후 title 속성에 출력할 때 따옴표를 이스케이프하도록 보완

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 00:52:40 +00:00
thisgunandClaude Opus 4.8 8a5767dc70 [KVE-2026-1176]취약점수정 - 관리자 목록 정렬 파라미터 화이트리스트 적용 보완
- member_list·index·couponzonelist·inorderlist·personalpaylist의
  정렬 컬럼/방향 값을 허용 목록으로 제한하여 ORDER BY 절에 임의 값 삽입 차단
- 기존 다른 목록 파일과 동일한 in_array 화이트리스트 패턴 적용

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 00:48:42 +00:00
thisgunandClaude Opus 4.8 935ea84c7c [KVE-2026-1122]취약점 수정 - 주문·관리자·결제·소셜 등 사용자 입력 처리 보완
- 쿠폰/희망배송일/검색어/계정/결제 콜백 등 입력값을 SQL 컨텍스트에 맞게 재처리
- dt_data·PG 응답 등 비-GPC 값과 소셜 provider 입력 정제 보완

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 00:36:35 +00:00
thisgun 1cade844fb chore: allow CRLF in PHP whitespace checks 2026-06-22 08:30:20 +00:00
thisgun dfca17a599 버전 5.6.30 수정 2026-06-16 03:33:14 +00:00
thisgun 5ed691136d 나이스페이 가상계좌 취소금액 보정 2026-06-16 03:26:42 +00:00
thisgun cdda832081 Fix register form member defaults 2026-06-16 03:26:42 +00:00
thisgun 5374fb5f74 NHN KCP 본인확인 v2 설정 안내 보완 2026-06-16 03:17:44 +00:00
thisgun 16a8dca6f7 버전 5.6.29 수정 2026-06-09 02:34:30 +00:00
thisgun b00fc18275 Merge branch 'master' into tmp_install 2026-06-09 02:27:41 +00:00
thisgun 0c6ff731f6 관리권한 부여 목록에서 최고관리자 전용 메뉴 제외 2026-06-09 02:26:01 +00:00
thisgun 77835010df 메일 테스트 발송 안내 개선 2026-06-09 02:26:01 +00:00
thisgunandClaude Opus 4.8 33416852fc 나이스페이 가상계좌 채번 시 od_app_no 누락 수정
가상계좌(4100) 채번 시 od_app_no가 빈 AuthCode로 남아
입금통보 매칭(od_app_no = VbankNum)이 실패하던 문제 수정

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-09 01:34:33 +00:00
thisgun 3a4612420c Improve installer validation and error handling 2026-06-08 02:09:17 +00:00
thisgunandClaude Opus 4.8 6a55f1457d 현재접속자 처리 시 카운트 접근 null 보정 (PHP 8 호환)
html_process 의 접속자 처리에서 count 조회 결과 접근을 empty() 로
보정. 쿼리 실패 등 비정상 상황에서 빈 배열/undefined 키 접근으로
PHP 8.0+ 경고가 나는 경우를 예방. 동작 변화 없음.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 07:32:50 +00:00
thisgunandClaude Opus 4.8 76d83c2bae 게시판 정렬 필드 화이트리스트 검증 추가
게시판 설정의 bo_sort_field 가 허용 목록 검증 없이 저장·사용되어
목록 조회 ORDER BY 절에 임의 표현식이 들어갈 수 있던 문제 수정.
정렬값은 따옴표로 감싸지 않아 escape 로 막히지 않으므로,
게시판 관리 권한 계정이 저장한 값이 비로그인 목록 조회에서
실행될 수 있었음.

get_board_sort_fields() 의 허용 목록(관리자 드롭다운과 동일)으로
저장(adm/board_form_update.php)과 사용(bbs/list.php) 양쪽을 검증.
허용 목록 외 값은 기본 정렬로 무력화하여 이미 저장된 값도 차단.
function_exists 가드로 부분 패치 환경 대비.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 07:20:58 +00:00
thisgunandClaude Opus 4.8 afd8b35423 SMS 회원정보 업데이트 토큰 방식 불일치 수정
member_update.php 가 get_token()(HMAC) 으로 발급한 토큰을
member_update_run.php 가 check_admin_token()(세션) 으로 검증해
항상 불일치 → 오류 HTML 반환으로 AJAX JSON 파싱이 실패하던 문제 수정.

sms_admin 의 다른 _run 들과 동일하게 검증측(check_admin_token)은
유지하고, 실행 시 ajax.token.php 로 세션 토큰을 발급받아 본 요청에
사용하도록 변경. check_admin_token 의 1회용 소거 특성상 재실행에도
견고함.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 08:22:03 +00:00
thisgunandClaude Opus 4.8 e7c89675b6 회원관리/비디오 필터 null 인자 보정 (PHP 8.1 호환)
내장함수에 null 이 전달되어 PHP 8.1+ 에서 경고가 발생하던 것을
isset 삼항 / 문자열 캐스팅으로 보정.

- adm/member_form.php: number_format(mb_point), substr(mb_id) 2곳,
  substr(mp_register_day) — null/미정의 시 0 또는 빈 문자열 처리
- plugin/htmlpurifier/extend.video.php: strstr 인자 (string) 캐스팅

표시·동작 변화 없음. PHP 5.2~8.3 호환 유지(?? 미사용).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 07:55:39 +00:00
thisgun 10c6c18857 Fix JavaScript alert string escaping 2026-06-01 10:26:44 +00:00
thisgun 3e002199d5 버전 5.6.28 수정 2026-06-01 03:40:35 +00:00
thisgunandClaude Opus 4.8 7dde02d396 SMS 모듈 Add/Add2 매개변수 기본값 보정 (PHP 8 호환)
기본값 있는 $strDate 뒤에 기본값 없는 $nCount 가 선언되어 PHP 8.0+
에서 경고가 발생하던 것을 $nCount=0 기본값 부여로 해소.

- plugin/sms5/sms5.lib.php: Add(), Add2()
- lib/icode.lms.lib.php: Add() (LMS 부모 클래스 동일 패턴)

LMS 분기 호출부는 $strDate, $nCount 를 항상 함께 전달하므로
동작 변화 없음. PHP 5.2~8.3 호환 유지.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-01 01:02:26 +00:00
thisgunandClaude Opus 4.8 31871ee3e6 [security] 주문자 휴대폰 출력 인코딩 및 리다이렉트 URL 호스트 검증
- adm/shop_admin/orderform.php: 주문상세 hidden 의 od_hp 출력에
  get_text() 적용 (인접한 od_name 과 동일 처리, 누락분 보완)
- bbs/member_cert_refresh_update.php: 본인확인 갱신 후 이동 URL 에
  check_url_host() 적용
- plugin/social/includes/functions.php: 소셜 로그인/연동 후 이동
  URL 2곳에 동일하게 check_url_host() 적용

login_check.php 등 기존 코드와 동일한 호스트 검증 패턴으로,
같은 도메인/상대경로 복귀는 그대로 동작하고 타 도메인 이동만 차단.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-29 09:16:29 +00:00
thisgun ff9a7534ed Restore data htaccess on admin and write upload 2026-05-29 07:22:08 +00:00
thisgunandClaude Opus 4.8 9869be5970 [security] 토스 결제창 customerName 출력 시 get_text 인코딩 적용
토스페이먼츠 결제 요청 폼의 customerName hidden 필드에 주문자명
($od_name)이 인코딩 없이 출력되던 것을 get_text() 적용으로 정리.
직전 주문 필드 인코딩 처리와 동일한 맥락의 마무리.

hidden value 의 엔티티는 결제 SDK 가 값을 읽을 때 브라우저가
디코딩하므로 토스로 전달되는 구매자명에는 영향 없음.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-29 06:30:29 +00:00
thisgunandClaude Opus 4.8 1fa4467cd1 [security] 주문 관련 필드 출력 시 get_text 인코딩 적용
영카트 주문자명/받는분/입금자명(od_name, od_b_name, od_deposit_name)
이 일부 출력 지점에서 인코딩 없이 노출되어, 저장된 값이 HTML/속성
컨텍스트에서 그대로 렌더링되던 문제 수정. 다음 출력에 get_text() 적용:

- adm/shop_admin/orderform.php, sale1today.php (관리자 주문 화면)
- shop/orderinquiryview.php (PC/모바일/테마 주문조회)
- shop/{inicis,kcp,lg,nicepay,toss}/taxsave_form.php (현금영수증 발행 폼)
- shop/mail/orderupdate{1,2,3}.mail.php, ordermail.mail.php (주문 메일)

비회원 주문 시 입력값이 관리자 화면에서 실행될 수 있는 경로를 차단.
폼 value 의 엔티티는 브라우저 제출 시 디코딩되므로 PG 전송값 및
정상 표시에는 영향 없음.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-29 06:25:12 +00:00
thisgun 3e75ccea65 NHN KCP 휴대폰 본인확인(api_v2) 버전 추가 2026-05-29 06:14:21 +00:00
thisgun be9f50f96b Fix RSS warnings for invalid board requests 2026-05-29 01:33:45 +00:00
thisgun 7c217cb41b Restore alert newline handling 2026-05-28 06:23:04 +00:00
thisgun 5fc1c3bc27 버전 5.6.27 수정 2026-05-27 03:35:09 +00:00
thisgunandClaude Opus 4.7 d707c5abac data/ 디렉터리 git 추적 제외 (.htaccess 인덱스 제거)
.gitignore 에는 이미 data/ 가 등록되어 있으나 data/.htaccess
한 파일이 이전부터 트래킹되고 있어 배포본에 함께 포함되던 문제 정리.
디스크 파일은 그대로 두고 인덱스에서만 제거.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-27 02:28:39 +00:00
thisgunandClaude Opus 4.7 eeea46cb69 NHN KCP 가상계좌 발급 응답 코드 V000 허용
KCP 가이드 개정으로 가상계좌 발급 정상 응답이 0000 에서 V000 으로
변경되어, 기존 코드가 발급 성공을 실패로 인식하던 문제를 수정.
결제 hub 의 res_cd 비교 두 곳에서 V000 을 0000 과 동등하게 처리.

가상계좌 입금 완료 처리는 Webhook 입금통보가 담당하므로 본 변경과
무관. 취소/현금영수증/본인인증 경로는 V000 응답 대상이 아니므로
0000 단독 비교 유지.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 11:55:56 +00:00
thisgunandClaude Opus 4.7 669cce7011 주소 jibeon 값 화이트리스트에 'J' 추가
카카오 우편번호 서비스의 oncomplete 콜백이 userSelectedType
으로 'R'(도로명) 또는 'J'(지번)을 반환하는데, 서버 측 정규식이
'N|R' 만 허용해 지번 선택 시 빈 문자열로 저장되던 문제를 수정.
N 은 print_address() 의 도로명 표기 분기를 위한 레거시 값으로
호환을 위해 유지.

적용 위치: 회원가입(bbs/register_form_update.php), PC/모바일
주문(shop/, mobile/shop/ orderformupdate.php), 관리자 미완료
주문(adm/shop_admin/inorderformupdate.php) 의 7곳.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 11:46:36 +00:00
thisgunandClaude Opus 4.7 ee8b57eb13 미완료 주문 목록 PG 표시에 토스페이먼츠/NICEPAY 케이스 추가
dt_pg 값이 'toss' 또는 'nicepay' 인 건이 default 분기로 빠져
일괄 'KCP' 로 잘못 표시되던 문제 수정.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 11:40:18 +00:00
thisgun c927925a05 Fix PHP 5.2 compatibility issues 2026-05-26 09:34:18 +00:00
thisgun d914a7843d Fix PHP legacy array syntax 2026-05-26 08:10:57 +00:00
thisgun c04591e24a NHN_KCP 가상계좌 테스트 url 변경 2026-05-26 07:34:49 +00:00
thisgunandClaude Opus 4.7 a6fbbe6ad2 [security] 엑셀/CSV 다운로드 출력값 안전 처리
lib/common.lib.php 에 csv_safe_cell() 헬퍼 추가 (function_exists
가드 포함). 셀 값이 = + - @ TAB CR 로 시작하면 작은따옴표를 prefix
하여 스프레드시트가 수식으로 해석하지 못하도록 변환.

다음 출력 지점에서 사용자 입력 컬럼에 적용:
- adm/shop_admin/orderprintresult.php (CSV + XLS 두 분기)
- adm/shop_admin/orderdeliveryexcel.php
- adm/member_list_exel_export.php
- adm/sms_admin/num_book_file_download.php

호출부는 function_exists('csv_safe_cell') ? ... : 원본 폴백 형태로
감싸서 lib 미업데이트 환경에서도 fatal error 없이 동작하도록 함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:30:21 +00:00
thisgunandClaude Opus 4.7 4c00c60006 [security]KVE-2026-0882 race condition 잔액 부족 시 결제 취소 처리로 변경
이전 커밋(e53689ac3)의 미수금 처리 방식은 사용자에게 결제 금액과
다른 청구가 발생해 혼란/분쟁을 유발할 수 있어, 동시 주문 race 로
포인트 잔액이 부족하면 결제 자체를 취소하는 방식으로 변경.

- PG 결제가 진행된 경우 (\$tno 존재): cancel_pg.inc.php 로 환불 요청
- 장바구니 복구: 기존 line 839 동일 패턴 (od_id = tmp_cart_id, ct_status = '쇼핑')
- 주문 삭제: g5_shop_order_table 에서 od_id 제거
- 사용자에게 die 로 명확한 오류 메시지 표시

lock timeout 케이스도 동일하게 결제 취소 처리 (보수적).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:10:53 +00:00
thisgunandClaude Opus 4.7 56b1958d37 [security]KVE-2026-0882 주문 포인트 차감 Race Condition (Double Spend) 수정
shop/orderformupdate.php / mobile/shop/orderformupdate.php 의 포인트
검증과 차감 사이에 TOCTOU race 가 존재하여, 동일 회원이 여러 세션으로
동시에 주문 제출 시 같은 포인트 잔액을 반복 검증 통과 → 다중 차감으로
mb_point 가 음수가 되는 double spend 가 가능했음.

insert_point() 의 기존 named lock 은 (mb_id, rel_table, rel_id, rel_action)
조합 키 기반이라 서로 다른 od_id 주문 간에는 lock 이 다르고, 주문 차감
호출에 rel_* 가 전달되지 않아 lock 미적용 상태였음.

조치: KVE-2026-0687 (쇼핑몰 쿠폰) 와 동일한 회원 단위 MySQL GET_LOCK
패턴을 적용. lock 획득 후 g5_point SUM 으로 잔액을 재조회하여
- 충분하면 정상 차감
- race 로 부족하면 사용 가능한 만큼만 차감 + 부족분은 od_receipt_point
  보정 + od_misu(미수금) 으로 반영하여 매장 손실 방지.

MyISAM 정책상 트랜잭션 금지이므로 named lock 으로 직렬화하는 방식이
가장 적합. 데스크톱·모바일 동일 패턴 적용.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:52:25 +00:00
thisgunandClaude Opus 4.7 6b2f9e094c [security] ORDER BY sst/sod 화이트리스트 누락 Blind SQL Injection 수정
KVE-2026-0876 동일 패턴 추가 발견 5건 일괄 수정.

- shop/itemuselist.php / mobile/shop/itemuselist.php (상품후기 목록)
- shop/itemqalist.php / mobile/shop/itemqalist.php (상품문의 목록)
  → 비회원 접근 가능한 공개 페이지에서 sst/sod 가 ORDER BY 절에
    검증 없이 삽입되어 CASE WHEN/SLEEP 기반 blind SQLi 가능했음.
    sst 는 컬럼 화이트리스트, sod 는 asc/desc 정규식으로 검증.

- bbs/list.php (게시판 목록)
  → sst 는 wr_datetime/wr_hit/wr_good/wr_nogood 화이트리스트 적용
    되어 있으나 sod 가 검증 누락되어 ORDER BY 절에 함수 표현식
    삽입이 가능했음. sod 에 asc/desc 정규식 검증 추가.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:32:28 +00:00
thisgun a781b4aef3 [KVE-2026-0876] 모바일 상품 리스트 sort 파라미터 Blind SQL Injection 수정 2026-05-26 06:27:53 +00:00
thisgun 8be4476f56 [KVE-2026-0869] 인스톨러 관리자 입력값 SQL Injection 수정 2026-05-26 05:22:52 +00:00
thisgunandClaude Opus 4.7 59d0b3c19c [security]KVE-2026-0859 KCP CLI Windows 환경 명령 인젝션(RCE) 수정
shop/kcp/pp_cli_hub_lib.php, shop/kcp/pp_ax_hub_lib.php 의
mf_do_tx() Windows 분기가 사용자 입력이 포함된 KCP CLI 인자를
큰따옴표로 감싼 단일 문자열로 만들어 mf_exec() 첫 인자로 전달했고,
mf_exec() 는 첫 인자를 escape 없이 exec() 에 넘겨 Windows cmd.exe
메타문자(`"`, `&` 등)로 인증 없는 OS 명령 실행이 가능했음.

Linux 분기와 동일하게 실행 파일 경로와 콤마 구분 인자 문자열을
분리하여 mf_exec($bin_exe, $args) 형태로 호출하도록 변경.
mf_exec() 의 foreach 가 두 번째 이후 인자에 escapeshellarg() 를
자동 적용하여 cmd.exe 메타문자가 안전하게 wrapping 됨.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:35:51 +00:00
thisgunandClaude Opus 4.7 f4f8c57a74 [security] 관리자 영역 권한 검증 누락 및 CSRF 토큰 누락 수정
- adm/qa_config_update.php / adm/contentformupdate.php :
  qa_include_head/tail, co_include_head/tail 가 super 가드 없이 변경 가능해
  하위 관리자가 임의 PHP 경로를 include 시킬 수 있던 LFI 위험을
  board_form_update.php 와 동일한 패턴(super 외에는 기존 값 유지)으로 차단.

- adm/member_form_update.php / adm/member_list_update.php :
  신규 회원 생성·일괄 수정 시 부여하려는 mb_level 상한 검증이 없어
  하위 관리자가 자기보다 높은 등급을 부여할 수 있던 권한 상승을 차단.

- adm/shop_admin/categorylistupdate.php /
  adm/shop_admin/itemformupdate.php :
  is_include_path_check 호출에서 두 번째 인자(is_input=1) 누락으로
  rar/php/zip wrapper 등 경로 wrapper 차단이 동작하지 않던 부분을
  is_include_path_check($file, 1) 로 강화.

- adm/shop_admin/orderdeliveryupdate.php /
  adm/shop_admin/orderpartcancelupdate.php /
  adm/sendmail_test.php :
  상태 변경 동작에 check_admin_token() 누락으로 발생하던 CSRF 위험을
  토큰 검증 추가로 차단. sendmail_test 폼에는 hidden token 필드 추가.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:35:29 +00:00
thisgunandClaude Opus 4.7 d5619707bc [security] 인스톨러 g5_shop_prefix PHP 코드 인젝션(RCE) 수정
install/install_db.php 의 g5_shop_prefix 가 dbconfig.php 의
define('G5_SHOP_TABLE_PREFIX','...') 문자열에 작은따옴표 escape 없이
삽입되어, 설치 전 노출된 인스톨러를 통해 임의 PHP 코드 주입 후 RCE
가능하던 문제를 수정. table_prefix·admin_id 와 동일하게 [^0-9a-z_]+
정규식 검증을 추가하여 영문자·숫자·언더스코어만 허용하도록 함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:34:55 +00:00
thisgunandClaude Opus 4.7 9e7465319b [security]KVE-2026-0822 댓글 수정 textarea wr_content 미이스케이프 Stored XSS 수정
view_comment.skin.php 8종(skin/, mobile/skin/, theme/basic/ 하위 basic·
gallery)에서 댓글 수정($w == 'cu') 시 \$c_wr_content 가 textarea 내부에
이스케이프 없이 출력되어 </textarea> 페이로드로 탈출 가능하던 문제를
get_text() 적용으로 일괄 수정. 게시글 본문 수정(bbs/write.php) 과
동일한 escape 패턴을 댓글 수정에도 적용함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:32:43 +00:00
thisgunandClaude Opus 4.7 f1f2150c67 [security]KVE-2026-0795 게시물 이동/복사 시 대상 게시판 권한 검증 누락 수정
bbs/move_update.php 가 원본 게시판 기준 $is_admin 만 검사하고 사용자
입력 chk_bo_table[] 의 대상 게시판에 대해서는 존재 여부만 확인하던
문제를 수정. 게시판 관리자(board)·그룹 관리자(group) 권한일 경우
대상 게시판의 bo_admin 또는 그룹의 gr_admin 이 본인인지 재검증하고,
일치하지 않으면 해당 대상 게시판 처리를 건너뛰도록 함. super 관리자는
기존 동작 유지.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:32:18 +00:00
thisgunandClaude Opus 4.7 3de722d3df [security]KVE-2026-0787 alert() JavaScript 이스케이프 누락 Stored XSS 수정
bbs/alert.php, bbs/alert_close.php 가 alert("$msg") 형태로 메시지를
JS 문자열 컨텍스트에 직접 삽입하던 부분을 수정. lib/common.lib.php 에
PHP 5.2 호환 폴백을 갖춘 get_js_safe_string() 헬퍼를 추가하고,
호출부에는 function_exists 가드를 걸어 부분 패치 환경에서도 안전하게
폴백되도록 함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:31:24 +00:00
thisgunandClaude Opus 4.7 7119b4f612 [security]KVE-2026-0711 PG 리턴 처리 POST 키 이름 Reflected XSS 수정
XenoPostToForm::makeInputArray() 에서 POST 값·배열 인덱스는 이스케이프
되지만 최상위 POST 키 이름이 name 속성에 그대로 삽입되던 문제를 수정.
재귀 진입 시점에 htmlspecialchars() 로 키를 이스케이프하여 모든 깊이에서
안전하도록 함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:30:47 +00:00
thisgunandClaude Opus 4.7 efaefbbd0e [security]KVE-2026-0687 쇼핑몰 쿠폰 다운로드 TOCTOU Race Condition 수정
MySQL GET_LOCK 으로 동일 회원·동일 쿠폰 다운로드 요청을 직렬화하여,
동시 요청 시 is_coupon_downloaded() 체크를 중복 통과해 쿠폰이 중복
발급되는 문제를 방지함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:30:19 +00:00
thisgun b12bf551ec [security]XSS 취약점 및 token 추가 2026-05-26 03:29:51 +00:00
thisgun 65a419e9cd 버전 5.6.26 수정 2026-04-16 04:38:38 +00:00
thisgunandClaude Opus 4.6 3f32ecd3e6 회원정보 수정 시 약관변경내역 로그가 매번 쌓이는 버그 수정
수신설정 섹션이 폼에 표시되지 않는 경우(cf_use_promotion 미사용, 휴대폰 미사용,
아이코드 미사용 등) _default 변수가 undefined 상태가 되어 비교 시 항상 "변경됨"으로
판단되던 문제를 해결. _default 변수를 명시적으로 초기화하고, 폼에 없는 항목은
기존 DB 값을 유지하도록 수정.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 04:01:37 +00:00
thisgun b5d218d446 인증서 교체로 인한 (구)엘지모듈 토스 결제 안되는 문제 수정 2026-04-16 03:46:30 +00:00
thisgun f2e7dbc5ed [security]그누보드5 XSS, SQL Injection 취약점 수정 2026-04-16 03:46:02 +00:00
thisgunandClaude Opus 4.6 c38de4c94b [security]KVE-2026-0701 .shtml 확장자 필터 누락으로 인한 RCE 수정
- bbs/write_update.php, bbs/qawrite_update.php: 업로드 블랙리스트에 shtml|shtm 추가
- install/install_db.php, data/.htaccess: FilesMatch 정규식에 [Ss]? 추가하여 .shtml 차단

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:39:31 +00:00
thisgunandClaude Opus 4.6 7d8a660642 [security]KVE-2026-0693 비밀번호 재설정 토큰 예측 가능 취약점 수정
rand() 대신 CSPRNG 기반 get_random_token_string() 사용
- mb_nonce: 128비트 CSPRNG 토큰으로 시드 브루트포스 차단
- change_password: CSPRNG 기반 10자리 hex로 변경

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:39:12 +00:00
thisgunandClaude Opus 4.6 5875e8b86b [security]KVE-2026-0690 설문조사 결과 페이지 Local File Inclusion 수정
skin_dir 파라미터에 디렉토리 트래버설 검증이 없어
임의 경로의 PHP 파일을 include할 수 있는 취약점을
clean_relative_paths()로 경로 조작 문자열 제거하여 수정

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:38:41 +00:00
thisgunandClaude Opus 4.6 68a5b9c25a [security]KVE-2026-0689 SNS 공유 스킨 Reflected XSS 수정
$_SERVER['REQUEST_URI']를 JavaScript 문자열에 이스케이프 없이
출력하여 URL을 통한 Reflected XSS가 가능한 취약점을
json_encode()로 안전하게 이스케이프 처리

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:38:21 +00:00
thisgun 2dff49914b [security]KVE-2026-0710 그누보드5 SQL Injection 수정 2026-04-16 03:35:29 +00:00
thisgun 51518e45e4 [security]KVE-2026-0709 그누보드5 SQL Injection 수정 2026-04-16 03:31:35 +00:00
thisgun 7883ff65dc check_token 함수 쓰는곳 없지만 요청사항으로 인해 타임스탬프 추가 수정 2026-04-16 03:30:19 +00:00
thisgunandClaude Opus 4.6 a2608754bd [fix]SMS 직접입력 발송 시 PHP 8.x Undefined array key 경고 수정
case 'h' 직접입력 항목에 bg_no, mb_id, bk_no 키 누락으로 257행에서 Warning 발생

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:24:09 +00:00
thisgunandClaude Opus 4.6 758bb67b7b [security]KVE-2026-0685 소셜 로그인 계정 연결 CSRF 방어
popup.php에서 mylink 진입 시 Referer 검증 및 세션 토큰 설정
functions.php에서 social_user_profile_replace() 호출 전 세션 토큰 검증

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:23:50 +00:00
thisgun 0037f72cce [security]KVE-2026-0678 사용자 영역 CSRF 방어 추가 2026-04-16 03:23:00 +00:00
thisgunandClaude Opus 4.6 df940f8168 [security]KVE-2026-0676 폼메일 발신자 위장 및 Rate Limit 우회 수정
비회원 폼메일 발송 시 From 헤더를 관리자 이메일로 고정하고 사용자 입력은 Reply-To로 설정
formmail_send.php에 세션 기반 발송 횟수 제한 추가 (직접 POST 우회 방지)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:18:19 +00:00
thisgunandClaude Opus 4.6 614b040960 [security]KVE-2026-0673 비인증 이메일 변경을 통한 계정 탈취 취약점 수정
register_email_update.php에 로그인 검증·소유권 강제·ckey HMAC 검증·SQL 이스케이프 추가
member_cert_refresh_update.php에 로그인 검증 및 소유권 강제 추가 (연관 IDOR 선제 조치)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 02:55:19 +00:00
thisgun dccb50d8a3 [security]회원 ID/이메일 열거 공격 차단 2026-04-16 02:54:05 +00:00
thisgun 5331aa8be5 [security]sql_query() 에러 노출 시 SQL/스키마 정보 차단
sql_query()의 에러 처리가 die()로 SQL 쿼리 전문, MySQL 에러 메시지,
스크립트 파일 경로를 사용자에게 그대로 노출하고 있었음. 기본값
G5_DISPLAY_SQL_ERROR=false 덕분에 일반 호출에서는 트리거되지 않으나,
일부 admin 파일이 명시적으로 sql_query(\$sql, true)로 호출하여
관리자에게 raw SQL을 노출했고, SQLi 공격 시도 중 발생한 에러로 DB
구조(테이블/컬럼명)가 학습되어 정밀 공격에 활용될 수 있었음.

조치:
- 서버 로그(error_log)에는 항상 상세 기록 → 운영자가 디버깅 가능
- \$is_debug 모드(G5_DEBUG=true 또는 super admin)에서만 상세 표시
  + XSS 방지를 위해 htmlspecialchars로 escape
- 그 외 환경에서는 "데이터베이스 처리 중 오류가 발생했습니다." 만 표시
- mysqli/mysql 폴백 분기 둘 다 동일하게 적용

변경:
- lib/common.lib.php:1932 (mysqli 분기)
- lib/common.lib.php:1942 (mysql 분기, 레거시 PHP 5.x 폴백)

PHP 5.2.17 호환 유지 (htmlspecialchars + ENT_QUOTES 모두 PHP 4.0+).
2026-04-16 02:48:31 +00:00
thisgun 79f915988b [security]개인결제 hash 검증을 strict 비교(===)로 강화
shop/personalpayformupdate.php와 lib/shop.lib.php의 ss_personalpay_hash
검증이 loose 비교(==/!=)를 사용하여 PHP type juggling 잠재적 우회 가능성이
있었음. md5 결과 중 "0e..." 형식 hash는 PHP의 loose 비교에서 0e 지수
표기법으로 해석되어 다른 "0e..." 해시와 동등 판정될 수 있음
(소위 magic hash collision 패턴).

실제 익스플로잇 가능성은 낮지만 (md5 출력은 32자 hex 문자열이고 PHP의
문자열 vs 문자열 비교에서는 0e... 패턴이 적용되지 않는 경우가 많음),
defense in depth 차원에서 strict 비교로 변경.

mobile/shop/personalpayformupdate.php는 이미 strict 비교를 사용 중이라
core 두 곳만 동일한 패턴으로 정렬.

- shop/personalpayformupdate.php:35: != / != → !== / !==
- lib/shop.lib.php:2333: == → ===
2026-04-16 02:46:49 +00:00
thisgun 3cfe8b6b84 [security]현금영수증 발급 페이지 IDOR 취약점 수정 2026-04-16 02:43:22 +00:00
thisgun 31ef78e916 [perf]strstr() 불린 검사를 strpos() !== false 로 교체
strstr()은 일치하는 부분 문자열 전체를 반환하므로 존재 여부만 체크할
때는 메모리 할당이 낭비됨. strpos()는 위치(int) 또는 false만 반환하여
메모리 할당 없이 더 빠르게 동일 동작 수행.

적용 파일 (19개, 약 25곳):
- lib/common.lib.php: wr_option html1/html2/secret 검사 3곳
- lib/shop.lib.php: de_taxsave_types 검사 2곳
- lib/latest.lib.php: wr_option secret 검사 1곳
- lib/thumbnail.lib.php: wr_option secret 검사 1곳
- lib/URI/uri.class.php: URI 확장자 검사 1곳
- bbs/view.php: subject/wr_option/content 검사 4곳
- bbs/view_comment.php: wr_option secret 검사 1곳
- bbs/search.php: wr_option/sfl 검사 3곳
- bbs/rss.php: wr_option html 검사 1곳
- bbs/write_update.php: html1/html2 검사 2곳
- bbs/move_update.php: wr_option html 검사 1곳
- adm/admin.lib.php: auth 권한 검사 1곳
- adm/admin.head.php: 메뉴 권한 검사 1곳
- adm/session_file_delete.php: sess_ prefix 검사 1곳
- adm/point_list.php, adm/auth_list.php: sfl mb_id 검사 2곳
- adm/sms_admin/_common.php: install.php 검사 1곳
- adm/shop_admin/configform.php: de_taxsave_types 검사 3곳
- head.sub.php: admin dir 검사 1곳

규칙:
  strstr($a, $b)       → strpos($a, $b) !== false
  !strstr($a, $b)      → strpos($a, $b) === false

제외:
- theme/, skin/, plugin/ (사용자 커스터마이징/서드파티)
- strstr() 반환값을 실제로 사용하는 케이스 (예: lib/common.lib.php:4135
  if( \$freg = strstr(\$ori_params, '#') ), extend/gif2mp4.extend.php)
2026-04-16 02:29:32 +00:00
thisgun a612e69d3e [perf]for 루프 조건의 count() 호출을 루프 밖으로 추출 (핵심 파일)
for ($i=0; $i<count(\$arr); $i++) 패턴은 매 반복마다 count()를 호출하여
불필요한 CPU 오버헤드를 발생시킴. 루프 전에 한 번만 count()를 계산하여
변수에 저장하는 고전적인 최적화.

적용 파일 (19개, 41곳):
- lib/common.lib.php (8)
- common.php (2)
- lib/shop.lib.php (5)
- lib/naverpay.lib.php (1)
- lib/thumbnail.lib.php (2)
- bbs/list.php (1), bbs/search.php (4), bbs/qalist.php (1), bbs/qawrite.php (1)
- bbs/ajax.filter.php (1), bbs/write_update.php (4)
- bbs/write_comment_update.php (1), bbs/memo_form_update.php (2)
- bbs/new_delete.php (1), bbs/move_update.php (4)
- shop/search.php (1), shop/orderform.sub.php (1)
- mobile/shop/search.php (1), mobile/shop/orderform.sub.php (1)

부수 효과:
- lib/shop.lib.php line 2115: 동일 루프 내 strstr($dlcomp, $company)를
  strpos($dlcomp, $company) !== false 로 변경 (strstr 최적화의 일부)

제외:
- theme/, skin/, plugin/ (사용자 커스터마이징/서드파티)
- lib/PHPExcel/ (서드파티 라이브러리)
- adm/ 및 shop/mail/ (관리자/드문 경로, 별도 후속 작업 여지)
- 주석 처리된 코드 (bbs/delete.php:127, bbs/delete_all.php:143)
2026-04-16 02:26:59 +00:00
thisgun 29e55de1fa [perf]url_auto_link() 다중 regex 호출 조건부 실행으로 최적화
기존 구현은 일반 텍스트 게시글(URL/이메일이 전혀 없는 대부분의 경우)
에서도 3개의 preg_replace를 항상 호출하여, 모든 게시글 본문 렌더링
마다 불필요한 regex 컴파일/스캔 오버헤드가 발생.

개선:
1. Fast bailout: ://, www., @, &, ' 가 하나도 없으면 즉시 반환하여
   forward/reverse str_replace와 3개의 preg_replace를 모두 생략.
2. 조건부 regex 실행: 각 regex 호출 전에 해당 패턴이 실제로 존재하는지
   strpos로 먼저 확인. URL 패턴 없으면 URL regex 생략, 이메일 없으면
   email regex 생략 등.

strpos x5 (~1ms) vs preg_replace x3 (~20ms+) 이므로 일반 텍스트 게시글
에서 10~20배 이상 빠르게 동작. 페이지에 수십~수백 개 게시글을 표시하는
목록/검색 페이지에서 누적 효과가 큼.

의미론적 동등성 유지: 각 marker가 없으면 해당 regex가 원래도 no-op였으므로
조건부 실행은 결과에 영향 없음. Fast path는 모든 marker가 없을 때만
동작하므로 str_replace의 부작용(& entity 디코딩 등)도 발생할 여지가 없음.
2026-04-16 02:25:49 +00:00
thisgun c4db6e7751 [perf]cut_str() 메모리 사용량과 CPU 오버헤드 감소
기존 구현은 preg_split("//u")로 입력 문자열의 모든 문자를 PHP 배열로
분해한 뒤 count/array_slice/join 3단계로 처리하여, 짧은 문자열이든
긴 문자열이든 항상 문자 수만큼 배열 원소를 할당하고 regex를 호출함.

게시글 목록의 제목/내용 표시 등 페이지당 수십~수백 회 호출되는
핫패스에서 불필요한 오버헤드를 발생시킴.

개선:
1. 바이트 길이 빠른 경로: strlen(str) <= len이면 UTF-8 특성상 문자 수도
   보장되므로 즉시 반환. ASCII/짧은 제목은 mb_strlen 호출 없이 종료.
2. mbstring 확장 사용: mb_strlen + mb_substr로 배열 생성 없이 상수
   메모리로 길이 체크/절단 처리.
3. preg_split 기반 기존 로직은 mbstring 미설치 환경 폴백으로 유지.

의미론적 동등성 유지 (잘라낸 결과와 suffix 부착 조건 모두 동일).
2026-04-16 02:25:12 +00:00
thisgun 47a3790c57 [perf]bbs/list.php N+1 쿼리 2건을 IN 쿼리로 배치 조회로 전환
게시판 목록 페이지에서 발생하던 N+1 쿼리 패턴 2건을 제거:

1. 공지 처리 루프 (line 94~120):
   기존에는 bo_notice의 각 wr_id마다 sql_fetch를 따로 호출하여 공지가 N개면
   N개의 쿼리가 발생. 유효한 wr_id를 정수화하여 수집한 뒤 단일 IN 쿼리로
   일괄 조회하고, id 기반 해시맵으로 원래 순서대로 처리.

2. 검색 결과 2차 조회 (line 199~200):
   DISTINCT wr_parent 쿼리로 ID만 받은 뒤, 각 행마다 sql_fetch를 호출하여
   검색 결과가 N건이면 추가로 N개의 쿼리가 발생. 단일 IN 쿼리로 모든 부모
   글을 일괄 조회 후 $rows_to_process 배열에 원래 순서대로 정렬하여 공통
   처리 루프에서 소비. 검색/비검색 분기에서 중복되던 row→list 변환 로직도
   공통화.

효과 (공지 5개 + 검색 결과 20건 기준):
  기존: 1 DISTINCT + 20 fetch + 5 notice fetch = 26 쿼리
  개선: 1 DISTINCT + 1 IN(search) + 1 IN(notice) = 3 쿼리

부수 효과:
- 삭제된 공지/부모글에 대한 에러 처리 개선
  (기존은 empty row를 get_list에 넘겨 잠재적 오류, 개선판은 자동 스킵)
- wr_id 정수화로 SQL injection 방지 계층 추가
2026-04-16 02:23:24 +00:00
thisgun 2894c269ea [security]이메일 인증 페이지 접근 토큰을 HMAC-SHA256으로 강화 2026-04-16 02:21:23 +00:00
thisgun c00c73465a [security]비회원 주문/개인결제 조회 uid를 HMAC-SHA256으로 강화 2026-04-16 02:15:29 +00:00
thisgun 3e0e8be6da [security]쇼핑몰 update 엔드포인트 CSRF 보호 추가 2026-04-16 02:02:26 +00:00
thisgun 92a052fa7a [perf]html_purifier() 메모리 사용량 최적화
한 요청에서 html_purifier()가 N번 호출되면 매번 약 10~15MB의 HTMLPurifier
인스턴스를 새로 생성하여, 게시글 목록처럼 반복 호출되는 페이지에서
수백 MB~GB 단위로 메모리가 낭비되었음.

- HTMLPurifier 인스턴스를 요청 단위로 캐싱 (admin/normal 2개 변형만 유지)
- safeiframe.txt 파일 I/O + 파싱 결과도 요청 단위로 캐싱
- G5_HTMLPURIFIER_NO_CACHE 상수로 캐싱 opt-out 가능
  ($html 내용에 따라 config를 동적 변경하는 플러그인 호환용)

동작 변경:
- html_purifier_config / html_purifier_safeiframes hook은 캐시 미스 시점에만
  실행됨 (요청당 최대 2회). 정적 config를 설정하는 일반적인 hook에는 영향 없음.
- html_purifier_result hook은 매 호출마다 정상 실행됨.

효과 (게시글 목록 30건 + 첨부파일 평균 3개 = 120회 호출 기준):
  기존 ~1.8GB → 개선 후 ~15MB
2026-04-16 01:36:59 +00:00
thisgun 4ebdd8ba30 [fix]포인트 사용/환원 함수의 race condition 수정
insert_use_point, delete_use_point, delete_expire_point 함수의 SELECT-then-UPDATE
패턴이 동시 호출 시 데이터 무결성을 깰 수 있는 race condition을 가지고 있었음.
같은 회원의 포인트 작업이 동시에 발생하면 PHP 단에서 캐시한 잔여량을 기준으로
판단하여 결과적으로 음수/초과 차감 등 포인트가 꼬이는 현상이 발생.

MyISAM은 트랜잭션과 FOR UPDATE를 지원하지 않으므로, 락 없이 무결성을 보장하는
lock-free atomic UPDATE 패턴으로 재구현:

- 매 단계마다 가장 우선 처리할 행 1개를 SELECT (LIMIT 1)
- WHERE 절에 사전 검증 조건(잔여량/상태)을 포함한 원자적 UPDATE
- get_sql_affected_rows()로 성공/실패 판별, 실패 시 재시도
- max_iter=1000 안전장치로 무한루프 방지

특징:
- 단일 행 차감(가장 흔한 케이스)에서 기존과 동일한 쿼리 수
- GET_LOCK 등 추가 락 없음 → 같은 사용자 동시 요청도 throughput 손실 없음
- MyISAM/InnoDB 모두 호환, MySQL 5.0~8.x 모두 동작
2026-04-16 01:35:45 +00:00
thisgun 4d5c597665 [KVE-2026-0610]그누보드5 자동 로그인 취약점 수정 2026-04-16 01:31:19 +00:00
thisgun 7e65a297bf [KVE-2026-0608]그누보드5 Race Condition 취약점 수정
- bbs/poll_update.php: 설문조사 중복 투표 방지 (FIND_IN_SET을 WHERE에 포함한 원자적 UPDATE)
- bbs/good.php: 추천/비추천 카운터 부풀리기 방지 (INSERT IGNORE 우선 후 카운터 증가)
- lib/common.lib.php: insert_point() 포인트 중복 지급 방지 (MySQL named lock GET_LOCK 사용)
2026-04-16 01:07:17 +00:00
thisgun ddcc82d89b .gitignore 에 CLAUDE.local.md 추가 2026-04-16 01:00:28 +00:00
thisgun ad99ea7673 [KVE-2026-0599]그누보드5 XSS 취약점 수정 2026-04-06 06:27:09 +00:00
thisgun b3fa6dc127 [KVE-2026-0595]영카트5 SQL Injection 취약점 수정 2026-04-06 06:26:20 +00:00
thisgun e6780f3b4b 버전 5.6.25 수정 2026-04-06 03:47:15 +00:00
thisgun bededeaf01 .gitignore에 IDE 및 AI 도구 설정 파일 추가 2026-04-06 03:46:41 +00:00
thisgunandClaude Opus 4.6 73b868a444 Cloudflare IPv4 대역 업데이트: 104.16.0.0/12 → 104.16.0.0/13
공식 Cloudflare IP 목록(https://www.cloudflare.com/ips)에 맞게 수정

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 03:29:55 +00:00
thisgun eb249a2aee Merge branch 'master' of github.com:gnuboard/gnuboard5 2026-04-06 03:21:45 +00:00
HanbitGaram(ハンビッガラム)andGitHub 813fdef0c7 다음 우편번호 서비스 네임스페이스 및 서비스 도메인 변경 (#374) 2026-04-06 12:20:42 +09:00
kms0219kmsandGitHub f8561e9398 ✏️ feat: 토스페이먼츠 상점관리자 - ‘테스트모드‘ 추가 반영, NHN KCP 상점관리자 주소 변경 (#368)
* ✏️ feat: 토스페이먼츠 테스트모드 반영, KCP 주소 업데이트

* ✏️ feat: 토스페이먼츠 테스트모드 문구 반영, KCP 주소 업데이트

* ✏️ typo: KCP 테스트환경 주소 변경
2026-04-06 12:19:11 +09:00
thisgun 52590509d5 [KVE-2026-0559]그누보드5 SQL Injection 취약점 수정 2026-04-03 03:59:23 +00:00
thisgun 604cef808e [보안패치]그누보드 영카트 SQL_injection 취약점 수정 2026-03-31 01:21:11 +00:00
thisgun 82574fd4a8 [KVE-2026-0570]그누보드,영카트 SQL Injection 취약점 수정 2026-03-30 12:01:44 +00:00
thisgun c3db9b454e [KVE-2026-0569]그누보드,영카트 SQL Injection 취약점 수정 2026-03-30 11:50:30 +00:00
thisgun bf19cd8bf5 [KVE-2026-0568]영카트 SQL Injection 취약점 수정 2026-03-30 11:03:16 +00:00
thisgun b2c0e1af29 [KVE-2026-0554]그누보드,영카트 SQL Injection 취약점 수정 2026-03-30 09:52:41 +00:00
thisgun 60d37b853b [KVE-2026-0553]그누보드 SQL Injection 취약점 수정 2026-03-30 09:50:38 +00:00
thisgun 919b75a138 [KVE-2026-0340]그누보드_SQL_Injection취약점_수정 2026-03-26 03:38:19 +00:00
thisgun 01fab8136e git commit -am "[KVE-2026-0330]영카트_SQL_Injection취약점_수정"; 2026-03-26 01:32:14 +00:00
thisgun 5054e24631 [KVE-2026-0243]영카트주문시_쿠폰중복사용취약점_수정 2026-03-25 09:18:48 +00:00
thisgun deff7d2079 warning 메시지 수정 2026-03-25 05:06:29 +00:00
thisgun 5e6b4fa668 [KVE-2026-0242]영카트주문취소시_포인트복구취약점_수정 2026-03-25 04:59:56 +00:00
thisgun ef1be317e1 버전 5.6.24 수정 2026-02-03 06:25:50 +00:00
thisgun 137d78ff73 영카트 관리자모드 분류출력 개선 2026-02-03 06:24:34 +00:00
thisgun 0ddcda4b0c toss 모바일결제 포인트 적용시 결제 오류 수정 2026-02-02 09:37:49 +00:00
thisgun bf27af3925 영카트 shop_is_taxsave 에서 볌수 코드 오타 수정 2026-02-02 07:33:36 +00:00
thisgun 607e15424d 토스결제 비회원결제가 안되는 오류 및 모바일 개인결제 취소과정 코드 수정 2026-02-02 07:18:28 +00:00
thisgun 7c490448ec 메일보내기 발신자 위장 방지 및 암호화 키의 안전성 취약점 수정 2026-01-30 05:00:43 +00:00
thisgun d775d2255f [KVE-2026-0029]Stored XSS 취약점 수정 2026-01-27 05:50:34 +00:00
thisgun b94771de92 썸네일 파일 코드 위치변경 2026-01-27 03:34:20 +00:00
thisgun b29e16a198 게시판 관리자가 게시판 수정시 자동등록방지 숫자가 틀렸습니다 라고 나오는 오류 수정 2026-01-26 09:40:43 +00:00
thisgun 0e06b4f9ce 영카트5에서 사용자가 현금영수증 발급버튼이 출력되지 않는 오류 수정 2026-01-26 09:33:19 +00:00
thisgun f2ab751e5f [KVE-2025-0828]영카트 취약점 수정 2025-11-14 07:30:47 +00:00
thisgun 3432497efe 삼성브라우저PC버전 대응 2025-11-14 02:08:02 +00:00
총andGitHub 60bb03049e Merge pull request #61 from gnuboard/fix/admin-member-header
style: 관리자 > 회원관리 > 목록, 광고성 정보 수신 동의에 따른 테이블 폭 조정 처리
2025-09-25 10:07:49 +09:00
whitedot a7541256cb style: 관리자 > 회원관리 > 목록, 광고성 정보 수신 동의에 따른 테이블 폭 조정 처리 2025-09-25 10:02:25 +09:00
thisgun e26fb62f5d 버전 5.6.23 수정 2025-09-22 11:06:20 +09:00
thisgun 887833089b php warning 메시지 코드 수정 2025-09-22 11:05:39 +09:00
thisgun 1438f8d557 충돌수정 2025-09-22 10:39:44 +09:00
총andGitHub 25e359facd Merge pull request #57 from gnuboard/release/toss-version-update-squash
feat: 토스페이먼츠 v2 결제 모듈 연동 작업 완료
2025-09-22 10:04:39 +09:00
chym1217 b98d45615c 회원관리파일 병합연산자 -> 삼항연산자로 수정 2025-09-19 17:54:35 +09:00
chym1217 7e8eff5395 팝빌 알림톡 제거 완료
- 광고성 및 회원관리파일(친구톡 코드만 제거) 제외
2025-09-19 17:53:50 +09:00
chym1217 f4718a71a2 feat: 관리자페이지 토스페이먼츠 명칭 변경 및 테스트결제 안내 추가
- 기존 : 토스페이먼츠 -> 토스페이먼츠(구버전)
- 토스페이먼츠 V2 -> 토스페이먼츠 API
- 기타 css 및 주석 수정
2025-09-17 10:44:40 +09:00
chym1217 46ea2d03b5 토스페이먼츠 v2 결제 모듈 연동 2025-09-16 16:34:15 +09:00
thisgun 1eee11e433 회원관리파일 export 에 권한체크 추가 2025-09-12 14:27:11 +09:00
thisgun a71192a63b 버전 5.6.22 수정 2025-09-12 13:56:31 +09:00
thisgun 633ff46596 전체검색시 페이징 되지 않는 오류 수정 2025-09-12 10:50:08 +09:00
chym1217 8a1f350d67 fix: 회원/게시판 추가 시시 Undefined array key 다수 발생 현상 수정 2025-09-09 09:36:42 +09:00
chym1217 ef364e1430 fix: 재입고 알림 DB 업그레이드 – 영카트 미설치 시 발생 오류 해결 2025-09-08 16:37:03 +09:00
thisgun f6a6a5622d 버전 5.6.21 수정 2025-09-08 09:59:55 +09:00
thisgun 63d6f7c43f Merge branch 'master' of github.com:gnuboard/g5-update 2025-09-08 09:43:00 +09:00
총andGitHub 6e101c4647 Merge pull request #54 from gnuboard/release/popbill-squashed
feat: #23 팝빌 알림톡 기능 추가 작업 완료
2025-09-08 09:42:09 +09:00
thisgun fa792efacb kcaptcha html 에 hook 적용 2025-09-08 09:37:43 +09:00
chym1217 66f6a75a10 팝빌 알림톡 기능 추가 2025-09-04 12:37:12 +09:00
thisgun de2502fad5 버전 5.6.17 수정 2025-09-02 18:29:27 +09:00
thisgun 54171e1903 5.6.16 버전에서 게시판 생성이 안되는 오류 수정 2025-09-02 18:27:55 +09:00
thisgun 44172c1d1f Merge branch 'master' of github.com:gnuboard/g5-update 2025-09-01 11:32:50 +09:00
thisgun 41945c62f8 버전 5.6.16 수정 2025-09-01 11:23:45 +09:00
총andGitHub 37d0dcb48f Merge pull request #47 from gnuboard/fix/sms5-table-prefix
[#42] fix: sms5 TABLE 생성 및 패치 시 G5_TABLE_PREFIX 사용
2025-08-29 17:04:42 +09:00
thisgun 002e43e5fb XSS 취약점 수정 2025-08-28 13:35:14 +09:00
thisgun 9510aa9cf1 Merge branch 'master' of github.com:gnuboard/g5-update 2025-08-27 18:52:02 +09:00
thisgun 6a3c2b1002 [KVE-2025-0464]영카트 XSS 취약점 수정 2025-08-27 17:58:06 +09:00
총 f69b66dced [KVE-2025-0510] Stored XSS (bypass html_purify patch) to RCE 취약점 수정 2025-08-27 11:48:36 +09:00
chym1217 cb1fadba4c fix: #42 SMS5 DB에 G5_TABLE_PREFIX 적용
- 기존 sms5_* 테이블 존재 시 dbupgrade에서 테이블명 변경
2025-08-19 15:31:58 +09:00
thisgun 5da91ab73e 버전 5.6.15 수정 2025-07-31 20:25:39 +09:00
thisgun d5b541724f create_hash 함수에 fclose 코드 추가 2025-07-31 20:23:59 +09:00
thisgun 9758007f91 NHN_KCP 네이버페이 간편결제 카드 또는 머니결제로 분리 2025-07-31 20:21:22 +09:00
thisgun 9d5f8e137f 관리자 로그인시 새글 테이블 OPIMIZE 실행시 딜레이 되는 문제 개선2 2025-07-31 17:12:43 +09:00
thisgun f1da95f055 Open redirect 취약점 수정 2025-07-30 15:03:01 +09:00
thisgun 9602f3c7a7 php warning 메시지 코드 수정 2025-07-21 12:48:53 +09:00
thisgun d357f5a0a4 Merge branch 'master' of github.com:gnuboard/gnuboard5 2025-07-08 11:41:40 +09:00
thisgun a9eab8d86a insert_use_point 함수에 hook 추가 #363 2025-07-08 11:40:47 +09:00
thisgun 9191199ef4 db_table.optimize.php 파일에 hook 추가 #362 2025-07-08 11:16:26 +09:00
thisgun 2556753530 url_auto_link함수에 url_auto_link_before hook 추가 #361 2025-07-08 11:02:34 +09:00
thisgun 57983a6dbc 토스페이먼츠 머트키 확인방법 설명문 수정 2025-07-08 10:45:10 +09:00
restarea92andGitHub 327e7ba7ba feat: add list.php theme override (#358)
* feat: add theme override in shop/list.php

* feat: add theme override in mobile/shop/list.php
2025-06-27 09:35:52 +09:00
thisgun 67415cf8d3 get_uniqid 함수에 hook 추가 2025-06-18 10:53:46 +09:00
thisgun aa88ff68a1 KG이니시스 IDC 센터코드 검증 추가2 2025-06-12 17:34:53 +09:00
thisgun 07a0245f85 버전 5.6.14 수정 2025-06-12 17:17:33 +09:00
thisgun d3de613a8c 관리자 로그인시 새글 테이블 OPIMIZE 실행시 딜레이 되는 문제 개선 2025-06-12 17:05:55 +09:00
thisgun bb1f69e86c KG이니시스 IDC 센터코드 검증 추가 2025-06-05 16:11:20 +09:00
thisgun dc4c2a79d9 XSS 취약점 수정 박재형님 제보 2025-06-05 14:12:55 +09:00
thisgun 38451a7d3d [KVE-2025-0384]XSS lead to RCE 취약점 수정 2025-06-04 17:44:50 +09:00
thisgun 87d11d5c78 변수 초기화 되지 않아 warning 메시지 출려되는 현상 수정 2025-06-04 14:40:18 +09:00
thisgun c1bbce1114 KG이니시스 가상계좌 에스크로 IP 추가 2025-05-28 11:27:59 +09:00
thisgun 61576d3e87 [KVE-2025-0351]ip 검증 취약점 수정 2025-05-28 10:57:33 +09:00
thisgun c9100d2e38 NHN_KCP 본인인증 테스트 오류 수정 2025-05-23 12:19:22 +09:00
thisgun 7714153faf 버전 5.6.13 수정 2025-05-15 15:31:41 +09:00
thisgun 654fd7ba68 방문자 기록 sql 문 수정 2025-05-15 15:30:40 +09:00
thisgun ea9f618de8 KG이니시스 모바일 가상계좌 IP 추가 2025-05-15 15:29:26 +09:00
thisgun eea5a2477b 쇼핑몰관리자 나이스페이신청 URL 링크 수정 2025-05-15 14:23:38 +09:00
thisgun 8cc101b617 접근차단 ip코드 다시 재수정 2025-05-15 14:09:27 +09:00
thisgun 316d3542a9 [KVE-2025-0259]XSS 취약점 수정 2025-05-15 09:53:28 +09:00
thisgun c2da219473 [KVE-2025-0286]XSS 취약점 수정 2025-05-14 12:49:03 +09:00
thisgun 6874e767c2 kcp 모바일 테스트결제 url 변경 2025-05-14 12:00:09 +09:00
thisgun 5a91d37365 php warning 메시지 코드 수정 2025-05-14 11:59:40 +09:00
thisgun f9c972d866 [KVE-2025-0191] Stored XSS (bypass html_purify via Open Redirect) 취약점 수정 2025-04-17 16:04:01 +09:00
thisgun ada8f28aae 버전 5.6.12 수정 2025-04-15 16:33:05 +09:00
thisgun 11afc52b84 접근차단 ip 코드의 위치 다시 재수정 2025-04-15 16:31:27 +09:00
thisgun d9c3f0e66c Merge branch 'master' of github.com:gnuboard/gnuboard5 2025-04-15 12:06:31 +09:00
thisgun 49da5c33df 버전 5.6.11 수정 2025-04-15 11:56:53 +09:00
thisgun 29250f264a 첩근차단 ip코드의 위치 수정 2025-04-15 11:44:40 +09:00
thisgun df00641290 php warning 메시지 코드 수정 2025-04-15 11:20:44 +09:00
thisgun a05a1403f5 Merge branch 'master' of github.com:gnuboard/g5-update 2025-04-15 10:52:11 +09:00
총 c5817594d0 [KVE-2025-0234] 관리자 XSS 취약점 수정 2025-04-15 10:11:31 +09:00
kagla 68a9e45337 Revert "경로 수정 및 불필요한 파일 삭제: CSS 파일 경로를 절대 경로로 변경하고, 사용되지 않는 install.css 및 이미지 파일을 삭제함. 또한, 여러 파일에서 include 경로를 수정하여 일관성을 유지함."
This reverts commit b8da0f0890.
2025-04-11 13:06:43 +09:00
kagla b8da0f0890 경로 수정 및 불필요한 파일 삭제: CSS 파일 경로를 절대 경로로 변경하고, 사용되지 않는 install.css 및 이미지 파일을 삭제함. 또한, 여러 파일에서 include 경로를 수정하여 일관성을 유지함. 2025-04-11 12:56:45 +09:00
thisgun 62ff45b31f php warning 메시지 코드 수정 2025-03-31 15:36:32 +09:00
thisgun 918ad48675 이미지 태그에 loading=lazy 가 있을경우 viewimagereisze 함수에서 width 속성을 추가하지 않도록 수정#355 2025-03-14 16:40:26 +09:00
thisgun e5128bf02e cheditor5 에 지도아이콘 제거 2025-02-20 12:52:39 +09:00
thisgun 0a0d6e7228 버전 5.6.10 수정 2025-02-04 11:17:21 +09:00
thisgun 69180914f8 쇼핑몰 가상계좌 정보(toss)에 은행이름이 하나 더 붙은 문제 수정 2025-02-04 11:01:41 +09:00
thisgun 5552fda906 사이드뷰에서 잘못된 닉네임 또는 이름이 출력되는 오류 수정 2025-02-04 10:49:01 +09:00
thisgun 13759821fe 메일 함수 예외 로그 추가 #354 2025-02-03 17:56:42 +09:00
thisgun 2e7843da56 php warning 메시지 코드 수정 2025-02-03 11:36:01 +09:00
thisgun 33ee904f60 버전 5.6.9 수정 2025-01-21 16:26:06 +09:00
thisgun 3e8bedb1e9 토스페이먼츠 (구)상점관리자 서비스 종료 관련 수정 #353 2025-01-21 16:24:42 +09:00
thisgun 4f3ad37bf4 쇼핑몰 택배업체 url 추가 및 수정 2025-01-15 16:07:02 +09:00
thisgun af92ea064e 버전 5.6.8 수정 2024-11-26 17:36:29 +09:00
thisgun dab5abb89a NHN_KCP 휴대폰 본인인증 인증키 입력없이 사용할수 있도록 적용 2024-11-26 17:33:04 +09:00
thisgun 8893b112fa 일부 특수문자가 mysql charset 이 uft8 인 경우 기록이 안되는 현상 수정 2024-11-21 11:58:55 +09:00
thisgun d65fa99e3c CloudFlare 환경과 적용에 대한 코드 다시 재수정 2024-11-04 16:13:43 +09:00
thisgun 29381da2ce 버전 5.6.7 수정 2024-10-31 16:19:11 +09:00
thisgun d96f47f93d NHN_KCP 휴대폰 본인인증 설정 가맹점 인증키 추가 2024-10-31 12:17:26 +09:00
thisgun 830994b637 소셜로그인 테이블 PK 수정 2024-10-28 10:55:14 +09:00
thisgun 0d586e2101 htmlpurifier 4.15.0 버전으로 수정 2024-10-25 17:52:55 +09:00
thisgun 5e6549a22c 영카트 관리자페이지 주문내역출력 페이지 코드 수정 2024-10-25 16:25:54 +09:00
thisgun ab204cfa59 CloudFlare 환경과 적용에 대한 코드 수정 #349 2024-10-25 11:46:50 +09:00
thisgun 3ca77a38fb 위시리스트에서 주문하기시 상품이 잘못 장바구니 담기되는 오류 수정 2024-10-23 15:23:47 +09:00
thisgun 67051c74a8 latest 함수 PHP 8 optional parameter issue 수정 2024-10-22 17:48:08 +09:00
thisgun 2a0bf12e65 버전 5.6.6 수정 2024-09-24 16:05:45 +09:00
thisgun dfa16adf31 KG이니시스 통합인증 9032 중복된 주문 에러와 회원정보 찾기 오류 수정 2024-09-24 16:03:42 +09:00
thisgun 96b30e0df6 Toss Payments - XPay 호출 도메인 변경 lgdacom.conf url 수정 #341 2024-09-04 20:03:13 +09:00
thisgun ef99a886cc 버전 5.6.5 수정 2024-09-04 12:56:35 +09:00
thisgun 20eb993757 나이스페이 주문정보 입력 오류시 결제 취소 코드 추가 및 불필요한 코드 제거 2024-09-04 12:55:05 +09:00
thisgun 3474be175d 토스페이먼츠 (구)lg XPay 테스트 에스크로 배송 url 수정 2024-09-03 18:03:21 +09:00
thisgun 532bf6f0f4 토스페이먼츠 (구)lg XPay 도메인 지원종료에 따른 결제도메인 수정 2024-09-03 17:17:55 +09:00
thisgun c4c1e50f68 Merge branch 'master' of github.com:gnuboard/gnuboard5 2024-07-18 10:28:57 +09:00
thisgun 7754e12194 토스페이먼츠 테스트 결제 url 수정 2024-07-18 10:28:26 +09:00
thisgun 287d68790f 토스페이먼츠 모바일 결제수단 키 수정 2024-07-18 10:18:57 +09:00
kaglaandGitHub 7d396b1749 Merge pull request #331 from gnuboard/php8.3
창고재고 없을때 '재고 부족' sound 처리하는 잘못 노출된 span 태그 제거
2024-07-18 08:24:17 +09:00
kagla d666e3467f 창고재고 없을때 '재고 부족' sound 처리하는 잘못 노출된 span 태그 제거 2024-07-18 08:18:11 +09:00
kagla d4c158cfa4 php-mysql 미설치시, 그누보드 설치 경고창에 정보 안나오는 경우 해결 2024-07-16 10:56:06 +09:00
thisgun f1af936c7d Cloudflare 환경에서 REMOTE_ADDR에 사용자 아이피 적용 2024-07-11 18:30:03 +09:00
thisgun 72d52b594c Deprecated: Optional parameter warning message 경고메시지 나오는 함수 코드 수정 2024-07-08 11:22:58 +09:00
thisgun 5622b38c17 버전 5.6.4 수정 2024-07-03 12:59:54 +09:00
thisgun cef3a48ff1 Merge branch 'master' of github.com:gnuboard/gnuboard5 2024-07-03 12:50:21 +09:00
thisgun c6b58bb16b 그누보드 open redirect 취약점 수정 2024-07-03 12:50:12 +09:00
thisgun 14ffe72574 영카트 관리자 주문내역에서 개인결제 추가시 토큰오류 문제 수정 2024-07-03 11:56:33 +09:00
kkigomiandGitHub 02baf1589f fix: get_member 함수에서 hook에 잘못된 아이디가 전달될 수 있는 문제 고침 (#328)
* fix: get_member 함수에서 hook에 잘못된 아이디가 전달될 수 있는 문제 고침

trim()이 mysql 쿼리에서만 처리되어 hook에 잘못된 회원아이디가 전달될 수 있는 문제.

* 잘못된 파라미터 타입 수정
2024-06-18 09:45:34 +09:00
thisgun 9a1067862a 버전 5.6.3 수정 2024-06-07 14:28:31 +09:00
thisgun 07f848e1c7 Merge branch 'master' of github.com:gnuboard/gnuboard5 2024-06-07 12:43:59 +09:00
thisgun 80846ac637 5.5버전 브랜치와 충돌수정 2024-06-07 12:43:34 +09:00
thisgun 62c0803cf5 초기화되지 않은 변수 수정 #325 2024-06-07 12:38:32 +09:00
thisgun 08df872863 HTMLPurifier_Filter_iframevideo 클래스명의 대소문자 불일치 수정#324 2024-06-07 12:31:17 +09:00
zipuragiandGitHub ca30e27b27 게시판에서 회원 아이디로 댓글 검색시 잘못된 결과가 나오는 문제 (#322) 2024-06-07 12:25:31 +09:00
thisgun 56615a5e9e 비회원인 상태에서 장바구니에서 주문하기 후 로그인하면 장바구니가 비어있는 문제 수정 2024-06-07 12:24:41 +09:00
총andGitHub 9c44d234ed Create SECURITY.md 2024-06-05 16:18:50 +09:00
thisgun e03e01d410 Open Redirect 취약점 수정 #318 2024-06-05 14:56:50 +09:00
thisgun 940e701fa4 관리자 회원관리에서 PHP WARNING 경고문이 나오는 코드 수정 #316 2024-06-05 10:09:24 +09:00
thisgun 031f8b4ef9 소셜로그인 타임아웃 설정타임 수정 #315 2024-06-04 17:59:31 +09:00
thisgun ed6b7f3326 글쓰기 임시저장과 쪽지쓰기 코드 수정 2024-06-04 17:38:33 +09:00
thisgun 0ded1df66d 삼품재고관리가 제대로 표시되지 않는 문제 수정 2024-06-04 11:27:16 +09:00
thisgun f4dfbacf03 글복사 sql query에 볋칭 as 추가 및 포인트 업데이트 코드 수정 2024-06-04 10:25:59 +09:00
thisgun 3fd8740c92 관리자 기본환경설정에서 불필요한 코드 제거 2024-06-03 18:16:59 +09:00
thisgun 68dc0bd4ec KG이니시스 MID SEED대칭키 수정 2024-06-03 18:16:17 +09:00
thisgun cc96048dfa NHN_KCP 결제정보 검증기능 추가 적용 2024-06-03 18:15:45 +09:00
thisgun 6697327265 쇼핑몰 주문 SMS 파일의 금액변수에 (int) 형 추가 2024-06-03 18:15:39 +09:00
thisgun a301d3e1f0 관리자 기본환경설정에서 불필요한 코드 제거 2024-06-03 12:39:48 +09:00
thisgun 2c0e05bbcc KG이니시스 MID SEED대칭키 수정 2024-05-31 19:23:42 +09:00
thisgun 92c1052cf5 NHN_KCP 결제정보 검증기능 추가 적용 2024-05-14 17:10:00 +09:00
thisgun c4763a64d8 쇼핑몰 주문 SMS 파일의 금액변수에 (int) 형 추가 2024-05-14 16:04:14 +09:00
kit rioandthisgun 02e0996eb4 kisa seed_cbc undefined 변수 수정
SEED_CBC_Decrypt 함수
return null 전에 초기화
2024-04-17 18:41:44 +09:00
thisgun 82648dcbfc 버전 5.6.2 수정 2024-04-17 18:29:23 +09:00
thisgun 61a0236938 버전 5.5.16 수정 2024-04-17 18:23:10 +09:00
thisgun 712172a0ea NHN_KCP 결제정보 검증기능 적용 2024-04-17 18:19:43 +09:00
thisgun d0eadcb12e 나이스페이 관리자 테스트결제 경고문 표시 및 모바일결제 스크립트 오류 수정 2024-04-17 15:45:36 +09:00
thisgun f38baea729 Merge branch 'master' of github.com:gnuboard/g5-update 2024-04-17 15:22:12 +09:00
thisgun 6048a8a1c5 NHN_KCP 결제정보 검증기능 적용 2024-04-17 15:21:55 +09:00
총andGitHub b84a6114f4 Merge pull request #12 from gnuboard/fix/cbc
seed_cbc undefined 변수 수정
2024-04-12 16:09:56 +09:00
kit rio b3ea5f19a8 kisa seed_cbc undefined 변수 수정
SEED_CBC_Decrypt 함수
return null 전에 초기화
2024-04-11 17:46:58 +09:00
thisgun b52a1f4da4 버전 5.6.1 수정 2024-04-11 12:32:58 +09:00
thisgun ce89cba2c7 버전 5.5.15 수정 2024-04-11 12:14:00 +09:00
thisgun c3634c05f7 KG이니시스 통합인증 암호화적용 여부 선택옵션 추가 2024-04-11 12:10:59 +09:00
thisgun 470d65d92a KG이니시스 통합인증 암호화적용 여부 선택옵션 추가 2024-04-11 11:55:55 +09:00
thisgun 2aff3cd491 버전 5.6 수정 2024-04-03 10:45:11 +09:00
thisgun 84669cb47f 나이스페이 결제수단 추가 2024-04-03 10:42:04 +09:00
thisgun baa114c471 버전 5.5.14 수정 2024-04-03 10:02:42 +09:00
thisgun 2bfd995e49 쇼핑몰 결제시 결세수단 체크 과정 추가 2024-04-03 09:59:02 +09:00
thisgun 1e72d7e81c DB 업그레이드시 기본설정,QA설정,로그인,방문자,쇼핑몰설정 테이블에 pk auto_increment 추가 2024-04-03 09:58:49 +09:00
thisgun 79b0066ec1 Merge branch 'master' of github.com:gnuboard/gnuboard5 2024-04-03 09:57:01 +09:00
kaglaandGitHub 47e243c0ad Fix/db (#311)
* QA설정테이블에 qa_id pkey auto_increment 추가

* 설정, 로그인, 방문자 테이블에 pkey, auto_increment 추가

* 쇼핑몰 설정테이블에 de_id pkey auto_increment 추가
2024-04-03 09:56:45 +09:00
thisgun bf6678e036 글쓰기 sql query 에 별칭 as 추가 #309 2024-04-03 09:44:37 +09:00
thisgun aba7d75de6 쇼핑몰 모바일 상품 리스트 페이지에서 불필요한 변수 제거 #308 2024-03-27 12:21:54 +09:00
thisgun 474fc8f9a9 관리자 xss 체크 alert이 너무 자주 발생하는 문제 #301 수정 2024-03-27 11:22:25 +09:00
thisgun a0eb804918 [KVE-2024-0023] 답변이 달린 상품문의글 수정가능 취약점 수정 2024-03-25 10:47:29 +09:00
thisgun 0d9c773d22 [KVE-2024-0022] 쇼핑몰 사용후기 별점 조작 취약점 수정 2024-03-25 10:03:07 +09:00
thisgun 6705d014f9 [KVE-2024-0021] Stored XSS 취약점 수정 2024-03-25 09:25:53 +09:00
thisgun 985546fbad G5_USE_SHOP 상수가 false 시 기본테마 로그인에 warning 경고문이 나오는 문제 수정 2024-02-19 18:07:18 +09:00
thisgun fa6aa881de 게시글 복사시 첨부파일 변수명값이 초기화가 안된 오류 수정 2024-02-19 12:49:17 +09:00
thisgun 06750e248b 버전 5.5.13 수정 2024-02-19 10:08:31 +09:00
thisgun c1c4089883 Union based SQL injection 취약점 수정 2024-02-15 15:28:48 +09:00
thisgun 248cb2b173 관리자 페이지 원격 명령 실행 취약점 수정 2024-02-14 19:09:20 +09:00
thisgun 8d912e3511 Open Redirection 취약점 다시 재수정 2024-02-14 18:31:52 +09:00
thisgun c67118f374 버전 5.5.12 수정 2024-01-25 16:58:48 +09:00
thisgun 15f2037790 OpenRediect 취약점 수정 2024-01-25 16:50:47 +09:00
thisgun cb6b39cb60 이니시스 본인인증 모듈 최근것으로 적용 2024-01-25 12:30:43 +09:00
thisgun 73a5f4cc47 NHN_KCP 에스크로 마크 상점코드가 SIR로 나왔던 오류 수정 2024-01-24 10:53:16 +09:00
thisgun 5f910f192e 버전 5.5.11 수정 2024-01-02 10:28:48 +09:00
thisgun bc2c939d72 Merge branch 'patch_5.5.11' of github.com:gnuboard/gnuboard5 2024-01-02 10:18:41 +09:00
kkigomiandGitHub b7c557f44e #297 보안취약점 처리 보완 (#300) 2024-01-02 10:17:41 +09:00
thisgun 1ff5df8215 KCP 모바일 결제중 Deprecated 메시지로 결제가 안되는 오류 수정 2024-01-02 09:59:06 +09:00
thisgun 72d03f305c 카카오로 링크 내보내기 스크립트 수정 2023-12-29 18:14:54 +09:00
thisgun 1ec9a0ee12 게시판 아이디를 content로 생성하면 짧은주소 기능과 충돌하는 문제 수정 #299 2023-12-29 11:56:32 +09:00
thisgun a061d6c863 동시성 문제로 wr_seo_title 값이 중복되는 문제 수정 #293 2023-12-18 17:26:30 +09:00
thisgun 4f2f725de8 보안취약점 수정 #297 2023-12-18 12:39:55 +09:00
thisgun fae53d3cd5 관리페이지에서 환경설정을 저장할 때 변조된 데이터가 사용될 수 있는 문제 수정 #296 2023-12-18 11:55:15 +09:00
thisgun 1fc3a343c2 영카트 상품의 짧은주소에 사용되는 it_seo_title이 중복되는 문제 수정 #295 2023-12-18 11:29:37 +09:00
thisgun 5e1ab9c1e7 [KVE-2023-5525] 그누보드(영카트) lgxpay plugin XSS취약점 수정 2023-12-04 18:16:20 +09:00
thisgun 5605b539f4 버전 5.5.10 수정 2023-11-10 14:12:48 +09:00
thisgun a8baa8dd7d ss_mb_key 체크함수의 user_agent 에 hook 추가 2023-11-10 13:57:24 +09:00
thisgun 16051b3049 비회원이 비밀글을 작성할 경우 패스워드를 묻는 오류 문제 수정 2023-11-10 12:47:10 +09:00
thisgun db1d56e07b G5_DOMAIN 설정시 url에 타 도메인을 지정할수 없습니다. 메시지가 나오는 오류 수정 #290 2023-11-10 12:21:19 +09:00
thisgun 4455f7d3c9 버전 5.5.9 수정 2023-10-19 11:29:24 +09:00
thisgun 398967f804 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-10-19 11:28:28 +09:00
KkigomiandGitHub ee75b32b3c adm/index.php 페이지에 컨텐츠를 삽입할 수 있는 Hook 추가 (#283)
* 코드 포맷

* adm/index.php 페이지에 컨텐츠를 삽입할 수 있는 Hook 추가

- adm_index_addtional_content_before
- adm_index_addtional_content_after
2023-10-19 11:27:18 +09:00
MayCactusandGitHub c869f29f0d 세션 쿠키 보안 강화 (#282)
* Enhance Session Cookie Security

* Fix user registration link path
2023-10-19 11:27:00 +09:00
KkigomiandGitHub c95168fb0c IP 변경으로 인한 관리페이지 접근 시 접속이 제한되는 문제 해결 (#284)
* `ss_mb_key`를 생성하고 검증할 때 IP를 제거하고 대체 함

프록시 등의 사용으로 IP가 수시로 변경되는 환경이라면 관리페이지 접근에 수시로 제한이 되는 문제를 해결하기 위함

* `ss_mb_key` 세션 값 생성 코드의 중복을 제거하기 위해 정리

* client_key 유효 시간을 세션 동안만 유지되도록 변경
2023-10-19 11:26:28 +09:00
thisgun b8ffd99362 비밀글이 게시판 목록에서 내용, 썸네일이 노출되는 문제 수정#287 2023-10-19 11:17:16 +09:00
thisgun 64e1fbe786 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-10-18 17:23:56 +09:00
thisgun 91715ff830 KG이니시스 통합인증 테스트키 수정 2023-10-18 17:23:43 +09:00
thisgunandGitHub 1fb9e28510 Merge pull request #273 from maycactus-FOSS/bug
Refactor: str_encrypt 클래스의 변수 이름 수정
2023-10-18 12:58:13 +09:00
thisgunandGitHub babbc9afdb Merge pull request #278 from kkigomi/master-2
`$wr_id` 전역변수의 값이 잘못된 타입으로 할당되는 문제 고침
2023-10-18 12:57:37 +09:00
thisgunandGitHub 04030f9274 Merge pull request #280 from kkigomi/patch-comment
불필요한 주석 제거
2023-10-18 12:56:55 +09:00
thisgunandGitHub 3085703c61 Merge pull request #279 from kkigomi/patch-1
`delete_cache_latest` Hook 추가
2023-10-18 12:56:31 +09:00
thisgunandGitHub 20dc211a82 Merge pull request #285 from kkigomi/feature/auth.au_menu
관리권한 설정 시 메뉴명(au_menu)의 길이 제한으로 인한 문제 개선
2023-10-18 10:33:39 +09:00
thisgunandGitHub a773839338 Merge pull request #289 from kkigomi/feature/deprecated-sql_password
sql_password() 함수를 사용하는 것을 권장하지 않음을 표기
2023-10-18 10:31:04 +09:00
kkigomi 84b22909c5 sql_password() 함수를 사용하는 것을 권장하지 않음을 표기
https://github.com/gnuboard/gnuboard5/issues/247
2023-10-15 20:39:44 +09:00
kkigomi 28bfcea9c2 관리권한 설정 시 메뉴 ID(au_menu)의 길이 제한을 20에서 50으로 확장 2023-09-09 21:48:34 +09:00
kkigomi 8cd1df0f43 불필요한 주석 제거 2023-08-31 21:18:41 +09:00
KkigomiandGitHub cf2a8ab282 delete_cache_latest Hook 추가
`delete_cache_latest()` 함수에 `delete_cache_latest` Hook 추가
2023-08-30 01:06:07 +09:00
KkigomiandGitHub 941f3e135a $wr_id 전역변수의 값이 잘못된 타입으로 할당되는 문제 고침
짧은 주소 '글 이름' 주소로 접근할 때 `$wr_id` 전역변수의 값이 `string` 타입으로  잘못 할당되는 문제를 `int` 타입으로 올바르게 바로 잡습니다
2023-08-21 09:24:30 +09:00
thisgun 4b9b1af01e 버전 5.5.8.3.4 수정 2023-08-17 14:40:08 +09:00
thisgun 41d48891f4 wr_num 필드 값이 동시성 문제로 겹치는 경우 답변글에 대한 권한이 잘못 주어지는 등의 문제 다시 수정 #265 2023-08-17 14:39:05 +09:00
maycactus 616f5b8d46 Refactor: str_encrypt 클래스의 변수 이름 수정 2023-08-16 15:37:08 -04:00
thisgun a96460948c 버전 5.5.8.3.3 수정 2023-08-16 15:52:11 +09:00
thisgun 337ee4e68f Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-08-16 15:49:14 +09:00
thisgunandGitHub 7af4888458 Merge pull request #268 from kkigomi/feature/hook-qawrite_update
1:1문의 답변 시 `qawrite_update` Hook에서 답변 글의 ID를 전달하도록 개선
2023-08-16 15:47:52 +09:00
thisgunandGitHub fdc695d08c Merge pull request #270 from kkigomi/feature/hook-shop-itemcopy
영카트 상품 복사 후 `shop_admin_itemcopy` Event Hook 추가
2023-08-16 15:47:09 +09:00
thisgunandGitHub 9fe34dae1d Merge pull request #267 from kkigomi/feature/hook-qa_delete
`qa_delete` Event Hook에서 실제 삭제된 ID 목록을 전달하도록 개선
2023-08-16 15:46:28 +09:00
thisgunandGitHub 4364058313 Merge pull request #266 from kkigomi/patch-qadelete-answer
QA에서 질문글 삭제 시 답변글의 첨부파일 및 썸네일을 삭제하지 못하는 문제 수정
2023-08-16 15:45:25 +09:00
thisgunandGitHub 0642c48106 Merge pull request #263 from kkigomi/patch-owl
owl.video.play.png 파일이 없어 발생하는 오류 수정
2023-08-16 15:44:15 +09:00
thisgunandGitHub d74c7b24bf Merge pull request #259 from kkigomi/patch-1
adm/view.php 파일에서 $sub_menu 등 변수 위치를 변경
2023-08-16 15:43:58 +09:00
thisgunandGitHub fec5569c71 Merge pull request #256 from maycactus-FOSS/bug
코드 일관성, 가독성 향상 및 버그 수정
2023-08-16 15:43:42 +09:00
thisgun 876534a440 wr_num 필드 값이 동시성 문제로 겹치는 경우 답변글에 대한 권한이 잘못 주어지는 등의 문제 #265 2023-08-16 13:01:05 +09:00
thisgun 5d4ba1030e 관리페이지 메뉴 접근 권한이 부여된 경우 관리페이지의 index 페이지의 정보가 노출되는 문제 #258 2023-08-16 11:44:42 +09:00
thisgun e43e424d80 세션 고정 취약점 수정 #257 2023-08-16 10:01:07 +09:00
kkigomi 5036254b69 php 5.2 호환성 문제 수정 2023-08-13 21:48:08 +09:00
kkigomi 2ae4046d29 영카트 상품 복사 후 shop_admin_itemcopy Event Hook 추가 2023-08-12 19:08:39 +09:00
kkigomi ccdbdebdec 1:1문의 답변 시 qawrite_update Hook에서 답변 글의 ID를 전달하도록 개선 2023-08-11 21:19:42 +09:00
kkigomi 1c4465a692 qa_delete Event Hook에서 실제 삭제된 ID 목록을 전달하도록 개선
`$tmp_array` 목록은 삭제를 요청한 목록이지만 작성자, 답글 등의 이유로 실제 삭제되지 않을 수 있음. 두번째 인자로 실제로 삭제 처리된 목록을 넘겨주도록 개선 함.
2023-08-11 19:41:25 +09:00
kkigomi bcbabf50f2 QA에서 질문글 삭제 시 답변글의 첨부파일 및 썸네일을 삭제하지 못하는 문제 수정
답변글의 정보를 잘못 가져오는 문제로 답변글의 첨부파일, 첨부파일의 썸네일, 에디터 이미지의 썸네일을 삭제하지 못하는 문제 고침
2023-08-11 19:29:50 +09:00
maycactus 3da5145bef Fix undefined variable issue in mobile login page 2023-08-09 11:48:53 -04:00
thisgun 6868cee8d1 영카트 모바일 주문시 SQL Injection 취약점 수정 2023-08-07 10:26:50 +09:00
kkigomi 870dcec68d owl.video.play.png 파일이 없어 발생하는 오류 수정
https://github.com/OwlCarousel2/OwlCarousel2/blob/develop/dist/assets/owl.video.play.png
2023-08-01 00:38:45 +09:00
kkigomiandGitHub 4735d62770 adm/view.php 파일에서 $sub_menu 등 변수 위치를 변경
`$sub_menu`, `$g5['title']` 변수를 생성처리가 `admin_request_handler_*` Event Hook 보다 이후에 실행되어 해당 Hook에서 이를 활용하지 못하는 문제를 해결합니다.
2023-07-26 12:13:07 +09:00
maycactus 2c88ef6d13 Update CSS styles for improved consistency
This commit updates the CSS styles for better consistency and correctness. The changes involve:

1. Replacing 'z-index: -1px' with 'z-index: -1' to correct the z-index value. The value should be an integer, not a length with a unit.
2. Replacing 'font-size:bold;' with 'font-weight:bold;' to set the font weight to bold properly.

Please note that I haven't tested the changes yet, but they should have a positive impact on the overall appearance and functionality of the elements styled with these CSS rules.
2023-07-25 14:06:43 -04:00
maycactus 12ce06c2d2 Refactor CSS styles for improved readability
This commit refactors the CSS styles by removing unnecessary closing parentheses from the box-shadow declarations and redundant empty color declarations. Additionally, it corrects the missing CSS property values in the .btn_submit and #mb_login_notmb p rules for proper styling.

The changes do not affect the visual appearance of the elements but make the CSS code cleaner and more maintainable.
2023-07-25 13:50:30 -04:00
maycactus 3a7d06b19e Fix array element and string offset access using square brackets
In accordance with the PHP RFC deprecating the curly brace syntax for accessing array elements and string offsets, this commit replaces all instances of {} with [].

By making this change, we ensure the codebase remains compliant with the recommended syntax, enhancing code readability and maintainability. The deprecation of curly brace syntax was done to align with best practices and promote a consistent code style.
2023-07-25 13:34:00 -04:00
thisgun 641656047d 버전 5.5.8.3.2 수정 2023-07-17 12:12:52 +09:00
thisgun 3becc03d23 CHEditor에서 이미지 업로드시 서버 내 경로가 노출되는 문제 수정 #248 2023-07-17 11:55:45 +09:00
thisgun 6eaa6ee22a Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-07-17 11:54:08 +09:00
thisgunandGitHub a8524eb070 Merge pull request #243 from kkigomi/feature/admin-hooks
관리자 페이지 및 일부 데이터 업데이트 시 Event hook 추가
2023-07-17 11:47:50 +09:00
thisgunandGitHub db9b4ffd50 Merge pull request #246 from kkigomi/feature/cheditor-hook-get_editor_upload_url
CHEditor에서 이미지 업로드시 get_editor_upload_url Hook에 파일의 정보 추가
2023-07-17 11:47:37 +09:00
thisgunandGitHub 9416b7dd9a Merge pull request #250 from kkigomi/patch-1
add_replace()에서 $args 값을 1로 변경
2023-07-17 11:47:24 +09:00
thisgunandGitHub 1634065870 Merge pull request #252 from kkigomi/patch-3
get_microtime 함수 개선
2023-07-17 11:47:11 +09:00
thisgun 14af11d0fa 옵션 재고 이후에 상품 재고를 체크하도록 수정 2023-07-11 11:17:29 +09:00
thisgun ec3fdce5c7 장바구니 업데이트시 sum_qty변수 형변환 수정 2023-07-11 10:41:33 +09:00
thisgun 79ce9ec984 6월 25일 제보한 영카트 보안취약점 수정 #249 2023-07-11 10:33:39 +09:00
thisgun 8eb1d46be1 저장소에 포함된 의미없는 파일삭제 #245 2023-07-10 18:38:22 +09:00
thisgun cbdaccbdec Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-07-10 18:03:15 +09:00
thisgunandGitHub ff6b160774 Merge pull request #244 from kkigomi/patch-2
Hook에 Closure를 리스너로 등록할 수 있도록 개선
2023-07-10 12:38:34 +09:00
kkigomiandGitHub f96ff445b9 get_microtime 함수 개선
불필요한 연산 제거
2023-07-09 05:05:12 +09:00
kkigomiandGitHub 6e684e80f2 add_replace()에서 $args 값을 1로 변경
replace hook은 값을 반환해야하므로 항상 최소 1개의 인자를 받아야하지만 기본 값이 0이어서 매번 이를 변경해줘야하는 문제
2023-07-08 06:58:03 +09:00
thisgun ffc8706a76 [KVE-2023-5153] XSS 취약점 수정 2023-07-04 18:37:23 +09:00
kkigomi 8ec09b0059 CHEditor에서 이미지 업로드시 get_editor_upload_url Hook에 파일의 정보 추가
`get_editor_upload_url` Hook의 세번째 인자에 파일의 추가 정보를 전달.
smarteditor2에서 정의한 것과 동일한 유형으로 데이터를 담음.
2023-06-30 22:18:30 +09:00
kkigomi af64737b63 PRS-12 코드 포맷 2023-06-30 22:02:42 +09:00
kkigomiandGitHub 81792d2595 Hook에 Closure를 리스너로 등록할 수 있도록 개선 2023-06-26 22:34:49 +09:00
kkigomi bbbc568db8 관리자 페이지 및 일부 데이터 업데이트 시 Event hook 추가 2023-06-25 03:49:10 +09:00
thisgun 4eba618a82 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-06-19 17:55:43 +09:00
thisgun accf20044f 버전 5.5.8.3.1 수정 2023-06-19 17:52:34 +09:00
thisgun aaadf1487d 영카트 쿠폰 발행 시 UX 오류 #230 2023-06-19 17:36:14 +09:00
thisgun 44798a4ef5 설치시 자동생성되는 게시판 글읽기 포인트로 인한 문제 수정 #231 2023-06-19 17:20:51 +09:00
thisgun 992641dfad 구글 서치 콘솔에 맞지 않는 게시판xml 수정 #234 2023-06-19 17:00:42 +09:00
thisgunandGitHub 451ece8d8c Merge pull request #238 from kkigomi/feature/html-purifier
Hook - HTMLPurifier 설정을 변경할 수 있는 `html_purifier_config` 이벤트 Hook 추가
2023-06-19 15:10:39 +09:00
thisgun bcda18cbd5 1:1문의 삭제시 hook 이벤트 추가 2023-06-19 15:08:56 +09:00
thisgun 2a8f5f6035 상품 검색 페이지 xss 취약점 수정 2023-06-16 17:20:18 +09:00
thisgun f4821aa49a 비회원으로 상품을 장바구니에 담아두고 후 로그인하면 mb_id가 누락되는 문제 수정 2023-06-15 17:16:47 +09:00
kkigomi 476b06792a 코드 포맷 2023-06-01 18:15:48 +09:00
kkigomi 9489254bbf html_purifier() 함수에 html_purifier_config 이벤트 Hook 추가
리스너에서는 첫번째 인자로 `HTMLPurifier_Config` 객체를 받아 설정을 변경할 수 있다
2023-06-01 18:15:26 +09:00
thisgun 8bcac60bda 버전 5.5.8.3 수정 2023-04-17 14:42:58 +09:00
thisgun fe03163cce XSS 취약점 수정 2023-04-17 14:41:38 +09:00
thisgun 8ecc5ba241 min_wr_num Undefined 경고문이 나올수 있는 코드 수정 2023-04-17 12:29:42 +09:00
thisgun 4204f7970e 안드로이드 chrome 112.0.5615.48에서 상품옵션선택이 안되는 문제 수정 2023-04-17 12:16:12 +09:00
thisgun 9cd2841006 버전 5.5.8.2.9 수정 2023-04-13 20:11:54 +09:00
thisgun 4b92543c61 KG이니시스 TX모듈을 사용하는 코드를 API로 전환 건 2023-04-13 20:10:48 +09:00
thisgun b01adc51c7 버전 5.5.8.2.8 수정 2023-03-23 12:54:34 +09:00
thisgun bfdc48b021 NHN_KCP 애플페이 추가 2023-03-23 12:52:40 +09:00
thisgun 10b3a9c841 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-03-23 12:25:33 +09:00
thisgunandGitHub 3f27a5e32d Merge pull request #223 from kkigomi/feature/rewrite
rewrite 룰 제안에 Hook 추가
2023-03-23 12:18:59 +09:00
thisgun a904c5c634 Object cache의 데이터를 삭제하지 못하는 버그 수정 2023-03-23 12:00:05 +09:00
thisgun d603f2d5b3 undefined error 경고문에 따른 return_url변수 초기화 2023-03-23 11:19:29 +09:00
thisgun 275f7e5d8a PHP8버전대에서 경고문 나오는 FAQ Undefined variable 수정 2023-03-23 11:10:28 +09:00
thisgun 2595a7a45d 모바일 위시리스트 상품 URL 코드 수정 2023-03-21 19:07:44 +09:00
thisgun cb346b08c1 쇼핑몰 상품 주문시 it_name 에 태그가 포함되어있는 경우 발생되는 오류 수정 2023-03-21 19:00:13 +09:00
kkigomiandGitHub 3db2dc8be3 Merge branch 'gnuboard:master' into feature/rewrite 2023-01-25 19:32:47 +09:00
kkigomi b3451f1cc2 rewrite 설정 코드 보기에서 기존 hook 보다 앞선 출력 위치에 hook 추가
기존 rule 때문에 hook으로 추가해도 접근 차단등의 룰을 적용하지 못하는 문제를 해결하기 위함
- add_nginx_conf_pre_rules
- add_mod_rewrite_pre_rules
2023-01-25 16:58:00 +09:00
kkigomi b557483e1d 코드 포맷. PSR-12 2023-01-25 16:53:10 +09:00
thisgun d28be44108 버전 5.5.8.2.7 수정 2023-01-25 16:52:29 +09:00
thisgun f61d6cc09a SMS관리 휴대폰관리 페이지 PHP특정버전에서 오류나는 문제 수정 2023-01-25 12:30:13 +09:00
thisgun 6fa0f0e704 정렬 기능에 짧은 주소 적용 오류를 다시 수정 2023-01-25 11:06:07 +09:00
thisgun 66039a4b37 PHP8 버전에서 경고문이 나오는 코드 수정 2023-01-20 11:17:50 +09:00
thisgun aca4733b12 쇼핑몰 장바구니에서 재고 이상 주문할수 있는 오류 수정 2023-01-20 11:17:20 +09:00
thisgun 85b97f4b29 버전 5.5.8.2.6 수정 2023-01-13 11:06:48 +09:00
thisgun 724a4e4bf6 [KVE-2023-0046] 그누보드5(gnuboard5) SQL Injection 취약점 2023-01-13 11:00:00 +09:00
thisgun 9cf8804611 Merge branch 'master' of github.com:gnuboard/g5-update 2023-01-12 10:43:41 +09:00
thisgun 8f3893bb43 중복코드 삭제 및 경고문이 나오는 코드 수정 2023-01-12 10:43:25 +09:00
kir rio 7617aba611 cheditor this.URI 추가 2023-01-11 12:06:25 +09:00
kir rio d99641d122 cheditor 5.1.9.4 버전 업데이트 2023-01-11 10:21:44 +09:00
thisgun 7516424989 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-01-09 16:06:27 +09:00
thisgunandGitHub 1cb12d9f2c Merge pull request #215 from kkigomi/feature/sql_query_fix
#212 PR에서 DB 커넥션 지정 오류 수정 & sql_query_after 이벤트에 누락된 $source 파라메터 추가
2023-01-09 16:00:52 +09:00
thisgunandGitHub dbcb6a2cb6 Merge pull request #218 from kkigomi/feature/sideview
회원 sideview 메뉴에 Replace Hook 추가
2023-01-09 16:00:38 +09:00
thisgunandGitHub 18c42a648e Merge pull request #219 from kkigomi/feature/goto_url
goto_url 함수에 Event Hook 추가
2023-01-09 16:00:06 +09:00
thisgunandGitHub f5e2252997 Merge pull request #220 from kkigomi/feature/html_process_buffer
html_process->run()에 Replace Hook 추가
2023-01-09 15:59:44 +09:00
thisgun 6fd339174e 내용관리 hook 코드 추가 2023-01-09 15:33:03 +09:00
kkigomi 1891b5eb38 회원 sideview 메뉴에 Replace Hook 추가 2023-01-08 03:35:26 +09:00
kkigomi 3fcc1f2d5f html_process->run()에 Replace Hook 추가 2023-01-07 01:32:14 +09:00
kkigomi 4958cc9e35 goto_url 함수에 Event Hook 추가 2023-01-07 01:31:05 +09:00
thisgun 1750e957d2 모바일 상품 페이지 오타 수정 2023-01-03 15:16:33 +09:00
thisgun abfeee5e92 1:1문의 답변 파일첨부 기능 추가 2023-01-03 14:53:08 +09:00
thisgun c3272f9170 게시판, 1:1문의, 쇼핑몰상품 상단내용 하단내용에 hook 적용 2023-01-02 17:58:22 +09:00
thisgun df176c6ad9 NHN_KCP 본인인증 모바일에서 새창열기 방식으로 수정 2022-12-20 17:41:22 +09:00
thisgun 22bfc5e9bb 모바일에서 패스워드 찾기 본인인증시 NHN_KCP 본인인증 스크립트 오류 수정 2022-12-19 14:05:33 +09:00
thisgun 4e0cd0d911 게시판 정렬 기능에 짧은주소 적용 2022-12-19 11:18:28 +09:00
thisgun 25091a201b PHP8 버전에서 경고문이 나올수 있는 코드 수정 2022-12-19 11:13:08 +09:00
kkigomi 3706ef99d3 #212 PR에서 DB 커넥션 지정 오류 수정 & sql_query_after 이벤트에 누락된 $source 파라메터 추가 2022-12-10 17:12:22 +09:00
thisgun 69a4998fce 버전 5.5.8.2.5 수정 2022-12-08 16:19:16 +09:00
thisgun 513976b5a2 [KVE-2022-2037] Gnuboard5 관리자페이지 내 Stored XSS 취약점 수정 2022-12-08 16:12:48 +09:00
thisgun 97a8352117 [KVE-2022-2036] Gnuboard5 관리자페이지 내 Stored XSS 취약점 수정 2022-12-01 15:22:48 +09:00
thisgun 21dc36199f Merge branch 'master' of github.com:gnuboard/gnuboard5 2022-12-01 10:27:52 +09:00
thisgunandGitHub 0a18368759 Merge pull request #212 from kkigomi/feature/sql_query
debugbar 쿼리 오류 표시 추가 및 G5_COLLECT_QUERY 설정 추가
2022-11-28 09:43:01 +09:00
kkigomi 6d9db83789 debugbar 쿼리 오류 표시 추가 및 G5_COLLECT_QUERY 설정 추가
- 210 이슈에서 제안했던 개선안
- debugbar에 오류 등으로 실패한 쿼리가 나오지 않는 문제 수정
- 실패한 쿼리에 오류 메시지 출력
- 쿼리가 실행된 파일, 라인 함수 표시
- G5_COLLECT_QUERY 상수 설정 추가로 디버그 모드(G5_DEBUG)를 켜지 않아도 서드파티 플러그인에서 쿼리 목록을 수집할 수 있도록 개선
2022-11-28 07:20:30 +09:00
thisgun 3e53cd8ff6 회원 탈퇴파일 오타 수정 및 이벤트 추가 #209 2022-11-22 19:36:35 +09:00
thisgun 816a32d5c9 set_cookie 함수의 httponly 인자의 기본값을 true로 수정 #208 2022-11-22 19:27:13 +09:00
thisgun 529b8a1004 html_process 에서 title link 태그가 없을경우 css 파일을 로드 못하는 문제 수정 #207 2022-11-22 17:25:10 +09:00
thisgun 62d0bf5c4e html_process 클래스 싱글톤 적용 #206 2022-11-22 16:29:43 +09:00
thisgun 4c6b833f73 새로운 인증 수단을 위한 패스워드 확인 없는 로그인 처리 지원 #205 2022-11-22 15:08:22 +09:00
thisgun 21532eb9bf Merge branch 'master' of github.com:gnuboard/g5-update into next_55825 2022-11-22 11:56:29 +09:00
kjh cd50af93fd 버전 5.5.8.2.4 수정 2022-11-22 11:30:07 +09:00
thisgun 589b7f4e39 테마설정에서 이미지가 영역을 벗어나는 문제 수정#204 2022-11-21 14:07:06 +09:00
thisgun 9c8f7128f2 css 코드중 오타 수정 2022-11-21 11:54:52 +09:00
thisgun a93008d392 set_http 함수 코드 수정 2022-11-21 11:47:32 +09:00
thisgun d3561623aa 휴대폰번호 입력 필수 입력 오류 수정 2022-11-21 11:41:18 +09:00
thisgun 311e879563 [KVE-2022-1984]관리자 개인결제 Stored XSS 취약점 수정 2022-11-21 10:35:49 +09:00
thisgun 9932b99a51 KG이니시스 가상계좌 노티 전송 IP 추가 2022-10-21 10:04:07 +09:00
thisgun 5c9ed36bf2 kakao cdn에 async 속성 추가 2022-10-17 11:56:41 +09:00
thisgun dbc8e1676a 버전 5.5.8.2.3 수정 2022-10-17 10:59:59 +09:00
thisgun 749345e502 Merge branch 'master' of github.com:gnuboard/g5-update 2022-10-17 10:57:35 +09:00
thisgun 7c8a21ecc0 카카오 우편번호 서비스 url 수정 및 속성에 async 추가 2022-10-17 10:57:00 +09:00
KimTom89andGitHub 8751ab122a Merge pull request #10 from gnuboard/G5-154/search-keyword-trim
[fix] 사이트 내 전체검색 > 검색어 양 끝의 공백 제거
2022-10-05 12:20:50 +09:00
kjh 0f3e6125b5 [fix] 사이트 내 전체검색 > 검색어 양 끝의 공백 제거 2022-10-05 11:50:08 +09:00
kjh a21d02f4c5 버전 5.5.8.2.2 수정 2022-10-04 15:14:35 +09:00
thisgun 2f9fb355e3 [KVE-2022-0992] 취약점 다시 재수정 2022-09-27 17:15:46 +09:00
thisgun 8074bce274 Merge branch 'master' of github.com:gnuboard/g5-update 2022-09-27 10:13:35 +09:00
thisgun 85dbbe946a 비번찾기 후 빈 페이지가 나오는 문제 수정 2022-09-27 10:12:18 +09:00
kjh 1f2e79b188 Merge branch 'master' of github.com:gnuboard/g5-update 2022-09-16 16:59:50 +09:00
thisgun 27434107e8 [KVE-2022-0992] 그누보드5 스크립트 실행 취약점 수정 2022-09-15 11:30:10 +09:00
thisgun f1a303e445 버전 5.5.8.2.1 수정 2022-09-13 10:38:05 +09:00
thisgun ba062ca5b6 [KVE-2022-0981] 그누보드 Reflected XSS 취약점 2022-09-01 16:08:08 +09:00
thisgun 34774f0fc3 Merge branch 'master' of github.com:gnuboard/gnuboard5 2022-09-01 15:15:00 +09:00
thisgunandGitHub 26b22ac9ca Merge pull request #199 from 39hn/fix/delivery-company-url
fix: 택배사 배송조회 주소 수정
2022-09-01 15:10:03 +09:00
thisgunandGitHub 9e4a8a95b0 Merge pull request #201 from KimTom89/fix/samesite-condition
Fix gnuboard/gnuboard5#200 HTTP_X_FORWARDED_PROTO 조건 추가
2022-09-01 15:07:29 +09:00
thisgun 1bca642b33 모바일 쿠폰적용 후 취소 오류 수정 2022-09-01 15:05:41 +09:00
thisgun 3a59bca369 관리자 회원 수정에서 관리자는 탈퇴일자 또는 접근차단일자를 적용못하게 수정 2022-08-25 10:29:11 +09:00
thisgun 5ad2307175 메일보내기 메일주소를 도메인과 동일하게 권장하는 문구 추가 2022-08-25 10:10:29 +09:00
kjh 25b3d8f6ed Fix gnuboard/gnuboard5#200 HTTP_X_FORWARDED_PROTO 조건 추가 2022-08-22 15:57:20 +09:00
thisgun 0d02afd712 장바구니 레이어 z-index 속성 수정 2022-08-19 09:55:22 +09:00
39hn 78d5dce761 fix: 택배사 배송조회 주소 수정
대신택배, 우체국, 한진택배, CVSnet편의점택배, 건영택배 주소 수정
2022-08-10 13:05:17 +09:00
kjh 45d5404520 Merge branch 'master' of github.com:gnuboard/g5-update 2022-08-05 14:50:01 +09:00
thisgun 1e6710a55b 투표에 사용, 미사용 기능 추가 (크레이티브님,210910) merge 2022-07-28 11:51:33 +09:00
thisgun 463ca06a21 버전 5.5.8.2 수정 2022-07-26 14:03:46 +09:00
thisgun 71f58f3108 KVE-2021-1116 그누보드 XSS 취약점 수정 2022-07-26 13:38:20 +09:00
thisgun a6e302ff84 KCAPTCHA php5.3 버전 이하에서 나는 오류 수정 2022-07-26 11:35:33 +09:00
thisgun 0c275d0907 본인인증 업데이트시 hook 이벤트 추가 2022-07-25 10:34:51 +09:00
thisgun fa7d0bc717 로그인시 쓰기권한 fclose전에 is_resource로 검사 2022-07-25 10:30:28 +09:00
thisgun 95492a5cd8 G5-82 <사용하지 않는 구글플러스 관련 코드 삭제> 2022-07-11 11:02:46 +09:00
thisgun 58dc48d3ea 영카트 상품리스트 sort 키에 it_name 추가 2022-07-11 10:32:49 +09:00
thisgun 281bb5427c 영카트 상품리스트 sort 키에 it_name 추가 2022-07-07 10:04:40 +09:00
thisgunandGitHub 0577882c6c Merge pull request #185 from seeoya/master
프론트 버그 신고 내역 처리
2022-07-04 17:37:40 +09:00
thisgun be758d57a5 버전 5.5.8.1.2 수정 2022-07-01 09:56:11 +09:00
thisgun 3cee6ede91 토큰 오류로 상품복사가 안되는 오류 수정 2022-07-01 09:55:11 +09:00
thisgun 5d86287069 영카트 주문내역에서 기타선택->반품,품절 검색이 안되는 오류 수정 2022-06-28 09:52:12 +09:00
thisgun 1a12b3e52b 버전 5.5.8.1.1 수정 2022-06-23 16:28:21 +09:00
thisgun 929183b3e3 [KVE-2022-0175] 그누보드 sql 취약점 수정 2022-06-23 14:29:14 +09:00
seeoya c1a45a1bec G5-137 모바일 쇼핑몰 장바구니 닫힘 태그 누락 (eyoom님, 220621) 2022-06-21 18:42:06 +09:00
Hailey KimandGitHub 444c6d88c2 Merge branch 'gnuboard:master' into master 2022-06-21 18:06:23 +09:00
thisgun 2366e8ebfb 버전 5.5.8.1 수정 2022-06-20 14:16:28 +09:00
thisgun a0bfc2cf6a sql_query 함수내 불필요한 코드 삭제 2022-06-20 11:32:35 +09:00
thisgun 22ea3d39c1 [KVE-2022-0193] 그누보드(영카트) SSRF & Business Logic Bug 취약점 수정 2022-06-17 17:11:05 +09:00
thisgun d4f4612b22 안전하지 않는 변수에 필터링 추가 2022-06-17 12:23:21 +09:00
thisgun e061ad852b [KVE-2022-0158] 그누보드(영카트)5 Reflected XSS 및 SQL Injection 취약점 수정 2022-06-17 12:13:54 +09:00
thisgun 4883fb18ae [KVE-2022-0133] 그누보드 XSS, CSRF 취약점 수정 2022-06-16 16:06:33 +09:00
thisgun 32e9797fef [KVE-2022-0143] 그누보드 Open Redirect, Reflected XSS 취약점 수정 2022-06-16 14:15:07 +09:00
thisgun bafa1c43bf [KVE-2022-0120]그누보드_부적절한_권한_검증_취약점_수정 2022-06-15 16:11:06 +09:00
thisgun d8b6297579 check_url_host 함수에 hook 적용 2022-06-15 13:40:18 +09:00
thisgun 251dfc26e8 [KVE-2022-0137] 그누보드 XSS, SQL Injection 취약점 수정 2022-06-14 18:18:05 +09:00
thisgun 4743ec91d8 버전 5.5.8 수정 2022-06-13 15:32:25 +09:00
thisgun bc56480db5 PHP5.2 호환성 문제 수정 2022-06-13 15:26:10 +09:00
thisgun 958abc9a91 Merge branch 'kjh_master' of github.com:gnuboard/g5-update into update_220613 2022-06-13 14:49:11 +09:00
thisgun 4b12ea8260 get_random_token_string 함수 코드 재수정 2022-06-13 14:47:50 +09:00
thisgun d4f554e653 clean_xss_tags 함수 수정으로 인해 일부 입력값에서 줄바꿈이 안되는 문제 수정 2022-06-13 14:46:08 +09:00
thisgun 30da5d6b22 PHP 8.1 mysqli_report 설정 수정 2022-06-13 14:37:21 +09:00
thisgun 9dd53a4efa PHP81버전 대응 충돌수정 2022-06-13 14:32:14 +09:00
jw2(kit rio)andthisgun bdb1ab852d 게시물 파일 업로드시 undefined variable 오류 수정
파일 테이블의 필드를 이름으로 하는 배열을 설정합니다.
2022-06-13 14:28:54 +09:00
kit rioandthisgun eba9401f89 ie6 지원 삭제 2022-06-13 14:28:50 +09:00
kit rioandthisgun 509b2c0be7 PHP 8.1 기본스킨, 테마에서 없는 글,댓글 조회시 undefined variable 수정 2022-06-13 14:28:45 +09:00
kit rioandthisgun 7950307173 PHP 8.1 설치 오류 수정 2022-06-13 14:28:40 +09:00
kit rioandthisgun fc43e26c14 불필요한 PHP 5.1 이하 코드 삭제
json_encode, json_decode 는 PHP 5.2 부터 PHP 코어에 내장되어있습니다.
https://php-legacy-docs.zend.com/manual/php5/en/json.requirements
https://php-legacy-docs.zend.com/manual/php5/en/book.json
2022-06-13 14:28:35 +09:00
kjh 564723c648 탈퇴된 회원도 세션이 만료되도록 조건 추가 #191 2022-06-10 05:18:04 +00:00
kjh 4724cc4c05 이니시스 host check 정규표현식 패턴 수정 #186 2022-06-10 03:26:52 +00:00
수영andGitHub 958b9342b5 Merge branch 'gnuboard:master' into master 2022-06-07 17:24:23 +09:00
KimTom89andGitHub 068c8818f8 Merge pull request #2 from gnuboard/php81-jw
Php81 jw
2022-05-31 18:08:37 +09:00
kit rio cedb732c7a Merge remote-tracking branch 'g5-update/php81' into php81-jw 2022-05-31 17:20:53 +09:00
KimTom89andGitHub 477001608e Merge pull request #1 from gnuboard/php81-jh
Php81 jh
2022-05-31 17:06:06 +09:00
kjh d9471833fe Merge branch 'php81-jw' 2022-05-31 07:38:17 +00:00
kit rio 3936a2d393 DB 설정 상수 주석 추가 2022-05-31 15:15:12 +09:00
kit rio 5465e073a2 PHP 8.1 deprecated openssl_pkey_free 함수 수정
8.1부터는 자동으로 메모리에서 해제가 되게 바뀌어서
8이하에서만 작동되게 수정.
2022-05-31 15:02:53 +09:00
kit rio df295bfe59 PHP 8.1 클래스 var -> public 수정 2022-05-31 14:56:08 +09:00
kjh 1fb9b5051c Checked PSR-1 / PHP 8.1 Undefiend Varialbe, Type error 2022-05-31 05:53:49 +00:00
kit rio 2371eecd13 테마와 중복되는 IE6 지원 삭제 2022-05-31 14:53:24 +09:00
kjh 993e689800 Checked PSR-1 / PHP 8.1 Undefiend Varialbe, type error 2022-05-30 08:30:08 +00:00
kit rio 0d414e3ed2 포인트관리 > 회원정보가 없는경우 오류수정 2022-05-30 11:06:31 +09:00
kjh b1640d7b76 Checked PSR-1: Basic Coding Standard 2022-05-27 09:20:20 +00:00
kjh 9199b7c986 Checked PSR-1: Basic Coding Standard & type error 2022-05-27 06:50:13 +00:00
kjh 44650b31f6 Checked PSR-1: Basic Coding Standard & Undefined Variable 2022-05-27 04:47:53 +00:00
kit rio d12c1c84e4 불필요한 PHP 5.2 미만 삭제 2022-05-27 10:20:36 +09:00
kit rio aaf5454144 PHP 문자열 내 변수 사용 중 Deprecated 사항 수정
PHP 8.2 문자열내 변수 ${var} -> {$var}
https://wiki.php.net/rfc/deprecate_dollar_brace_string_interpolation
2022-05-26 16:58:07 +09:00
kjh 0031b20597 bo_table 선언 및 예외처리 추가 2022-05-26 06:09:45 +00:00
kit rio b5a8ce065f 삭제된 each 함수 foreach 로 수정 2022-05-26 11:47:27 +09:00
kit rio 30c9a54b4f PHP 8.0 PHP 엑셀 삭제된 split() 함수 대체
lib/Excel/php_writeexcel 는
영카트에서는 PHP 5.2 이하일 때만 쓰고 있으나
유저들이 씁니다.
2022-05-26 11:47:27 +09:00
thisgun c5395a7f44 버전 5.5.7.5 수정 2022-05-25 19:53:43 +09:00
thisgun 238f8c042c 불필요한 코드 수정 및 불필요한 파일 삭제 2022-05-25 19:44:00 +09:00
thisgun e3016b7a77 object cache를 삭제하지 못할수있는 버그수정 #190 2022-05-25 19:36:44 +09:00
thisgun 096f744f61 get_token_encryption_key함수에서 불필요한 코드 삭제 2022-05-25 19:36:40 +09:00
thisgun 62ebce3d9c 이전 보안패치중 random_bytes 함수를 잘못 적용할 것을 다시 수정 2022-05-25 19:36:35 +09:00
kit rio 767c3c5562 PHP 8.0 undefined variable 오류 수정
uri.lib.php 에서 uri.class.php 사용하지않고 있음.
2022-05-25 18:34:52 +09:00
kjh 3aee9326d7 fixed Undefined variable 2022-05-24 08:48:51 +00:00
kjh b591c91c99 투표 > 기타의견 작성 시 비회원만 capcha 표시하도록 수정 2022-05-24 08:47:17 +00:00
kjh 0edbdab1d8 PHP8.1 Syntax/Functionality Changes & Deprecations List Check 2022-05-24 08:44:52 +00:00
kjh 0b90f9d631 htmlpurifier 4.14.0 ver 적용 2022-05-24 08:42:01 +00:00
kit rio d3d7b9aadc PHP 8.0에서 변경된 implode() 매개변수 순서 수정 2022-05-24 17:10:17 +09:00
kit rio 66d9ae44da PHP 8.0에서 삭제된 배열 인덱스 표기 {} -> [] 수정 2022-05-24 17:09:13 +09:00
kit rio a19282b58e PHP 8.1 지원 클래스 맴버변수 var -> public 수정
클래스에서 var 와 public 은 동일한역할이며
PHP 5.2부터 지원됩니다.
2022-05-24 17:03:23 +09:00
thisgun 09ec2ac8cb 버전 5.5.7.4 수정 2022-05-24 16:00:17 +09:00
thisgun da2b6dafb3 세션고정취약점(버그게시판 글번호12095) 수정 2022-05-24 15:29:27 +09:00
thisgun 0a9f580c5b 버전 5.5.7.3 수정 2022-05-23 18:39:18 +09:00
thisgun f4aa0d0cd8 세션 폴더에 접근할수 문제 수정 및 세션 저장경로 수정#175 2022-05-23 18:37:23 +09:00
kit rio a73cdef008 PHP 8.1 지원 HTMLPurifier 패치 2022-05-23 14:13:41 +09:00
kit rio 0dbdef7543 PHP 8.0 지원 HTMLPurifier 4.14 업데이트 2022-05-20 10:11:45 +09:00
kit rio ea2187e1a8 PHP 8.1 부터 deprecate 되는 해시함수 수정
그누보드5는 PHP 5.2.17 부터 지원이라 무관합니다
2022-05-19 17:38:49 +09:00
jw2(kit rio)andGitHub b3d5345b45 Merge branch 'gnuboard:master' into master 2022-05-18 15:34:43 +09:00
seeoya adc8e94774 G5-88 관리자 : 미사용 CSS 제거 (묵혼님, 220503) 2022-05-03 17:29:20 +09:00
seeoya 26857a8d50 G5-87 쇼핑몰 : KCP 결제창 표시될 때 화면이 스크롤되지 않도록 수정 (HSCOMM님, 220503) 2022-05-03 16:12:34 +09:00
kagla 5a4ddbc455 버전 5.5.7.2 수정 2022-05-03 12:10:26 +09:00
kagla e2e06d4a23 게시판분류에서 '팅' 글자를 인식하지 못하여 패턴을 쌍따옴표로 수정 2022-05-03 12:10:02 +09:00
kagla b97565e387 버전 5.5.7.1 수정 2022-04-28 17:17:06 +09:00
kagla 7e3ad29696 form 입력값에서 space를 포함한 값이 넘어오는 경우가 있어 space 는 제외하고 replace 함 2022-04-28 17:14:59 +09:00
kagla 5981fd11bf Merge branch 'develop' 2022-04-28 16:41:11 +09:00
kagla 0645b8b2f4 버전 5.5.7 수정 2022-04-25 15:11:24 +09:00
kagla 3197f43be6 Merge branch 'develop' 2022-04-25 15:00:40 +09:00
seeoya 4bbaef4162 G5-20 주소 검색 중 화면 확대되지 않도록 수정 2022-04-21 14:43:47 +09:00
수영andGitHub d08fc856df Merge branch 'gnuboard:master' into master 2022-04-21 13:48:55 +09:00
kagla 3f840d9140 Merge branch 'php81' of https://github.com/gnuboard/gnuboard5 into php81 2022-04-20 06:23:03 +00:00
kagla ecb10436e5 PHP8.1 Deprecated: addslashes(): Passing null to parameter #1 ($string) of type string is deprecated. addslashes 함수의 문자타입의 첫번째 파라미터에 null을 전달하는 것은 더 이상 사용되지 않습니다. 해결 2022-04-20 06:20:24 +00:00
kagla 97baa9d0db 버전 5.5.6 수정 2022-04-18 16:52:22 +09:00
projectSylasandkagla 11718eb4c0 [G5-80] 본인인증 비밀번호 찾기 후 비밀번호 변경 관련 수정 2022-04-18 16:51:53 +09:00
kagla 41e3c23f9e Merge branch '220418' into develop 2022-04-18 16:31:31 +09:00
kagla fdd2d30f4e $desc_name, $desc_phone Undefined variable 문제 해결 2022-04-18 12:04:00 +09:00
kagla 13bc72def7 ip2long으로 변환된 REMOTE_ADDR을 유추할수 없도록 md5(sha1(REMOTE_ADDR))로 처리함 (kjsman님,220418) 2022-04-18 11:47:22 +09:00
kagla 2457055514 $url 파라미터에 HTML Entity Number 형식으로 값이 넘어오는 경우의 XSS 취약점 해결 (woonge님,220415) 2022-04-15 10:16:44 +09:00
kagla 6449af2b57 모바일에서는 모바일 페이지당 라인수로 적용하도록 수정 (coDribble님,220414) 2022-04-14 16:01:25 +09:00
kagla 258f94e597 Reflected XSS 취약점 해결, Fixed Reflected XSS vulnerability (220408,hunter.dev/9o3) 2022-04-08 11:17:24 +09:00
kagla 6660a4adc1 admin_common 기본 훅 추가 (220408,티로그님) 2022-04-08 10:31:50 +09:00
kagla de72f42216 버전 5.5.5 수정 2022-04-07 15:49:13 +09:00
kagla 162ce82da0 Merge branch 'develop' 2022-04-07 15:48:11 +09:00
kagla 9ac9e01a51 [KVE-2022-0184] XSS 및 SQLInjection 취약점 해결을 위해 사용하지 않고 있던 "코드 중복검사" 기능 제거 2022-04-07 15:43:43 +09:00
seeoya eef8f32efe G5-77 shop.override.js 총 금액 표시 통일 작업 2022-04-07 15:32:21 +09:00
seeoya fd7121a215 G5-67 상품 목록 갤러리 스킨(40) 수정 2022-04-07 15:30:02 +09:00
seeoya 3999b86f9f G5-67 상품 목록 갤러리 스킨 복구, 리스트 스킨에서 사진 클릭 되도록 수정 2022-04-07 14:28:50 +09:00
kagla 38e732e71e KVE-2021-1277 Open Redirect 취약점 해결 2022-04-06 14:08:20 +09:00
kagla 66130b3fe1 PHP8.1 Deprecated: addslashes(): Passing null to parameter #1 ($string) of type string is deprecated. addslashes 함수의 문자타입의 첫번째 파라미터에 null을 전달하는 것은 더 이상 사용되지 않습니다. 해결 2022-03-31 08:00:49 +00:00
kagla 767af99ba8 PHP8.1 number_format(): Passing null to parameter #1 ($num) of type float is deprecated. 부동소수점 타입의 파라미터 #1($num)에 null을 전달하는 것은 더 이상 사용되지 않습니다. 해결 2022-03-31 05:41:23 +00:00
수영andGitHub 7ab46223b5 Merge branch 'gnuboard:master' into master 2022-03-30 15:53:20 +09:00
kagla 7144c4f4be 모바일페이지에서의 직접 접근을 막아 KVE-2021-1888_Reflected XSS 취약점 해결 2022-03-22 12:52:36 +09:00
kagla 15d13e2fbc Merge branch 'develop' of github.com:gnuboard/gnuboard5 into develop 2022-03-22 12:51:28 +09:00
kagla 05035d6f6c 버전 5.5.4 수정 2022-03-21 10:43:23 +09:00
seeoya b4891ab773 G5-57 쇼핑몰 주문서 - 배송지 목록 버튼 padding 제거 2022-03-17 12:16:33 +09:00
kagla 84a065c31b host 가 inicis.com 의 주소가 아니라면 false 반환, XSS 취약점 해결 (03sunf님,220317) 2022-03-17 11:17:22 +09:00
kagla ae6190116f height 중복선언 해결 (냠냠이님,220316) 2022-03-16 17:20:31 +09:00
kagla 8021ebadf9 Proxy 서버나 로드밸런서 등에서는 HTTPS 접속시 HTTP_X_FORWARDED_PROTO 로 체크해야 하는 경우가 있음 2022-03-16 16:39:14 +09:00
kagla d79c3be7ba SQL 구문 오류 해결 2022-03-16 16:07:13 +09:00
kagla af3b1b69d3 Proxy 서버나 로드밸런서 등에서는 사용자의 IP가 REMOTE_ADDR 이 아닌 HTTP_X_FORWARDED_FOR 에 저장된 경우가 있음 2022-03-16 16:04:56 +09:00
kagla bdcf17dfc2 Warning: Trying to access array offset on value of type null 오류 수정 2022-03-15 15:19:59 +09:00
수영andGitHub 480fb98b32 Merge branch 'gnuboard:master' into master 2022-03-15 09:53:44 +09:00
kagla 99f7cd4d19 base_convert(): Passing null to parameter #1 ($num) of type string is deprecated. 문자열 유형의 매개변수 #1($num)에 null을 전달하는 것은 더 이상 사용되지 않습니다. 해결 2022-03-14 04:38:15 +00:00
EC2 Default User 2e7953daba PHP8.1 에 대응하기 위해 deprecated 되는 오류 등 수정 2022-03-14 00:53:09 +00:00
kagla 30a2481145 Cross-site Scripting (XSS) 해결 (SeungHyunKim님,220311) 2022-03-11 11:08:13 +09:00
kagla cb61fa3045 #167 Security Report : Cross-Site Scripting 오류 해결 (P0cas님,220311) 2022-03-11 11:01:15 +09:00
EC2 Default User 26dfe6379f PHP8.1에서 DB Table 존재유무 검사시 오류가 나는 describe 대신 show tables like 로 수정, PHP message: PHP Fatal error: Uncaught mysqli_sql_exception: Table 2022-03-10 05:31:54 +00:00
kagla 4ad2f60c34 [보안패치] KVE-2021-1987_그누보드(영카트)preauth SQL Injection 취약점 해결, shop/event.php 를 거쳐서 접근하도록 수정 2022-03-07 16:45:23 +09:00
kagla 1a12ee8d2c Merge branch 'v554' into develop 2022-03-07 15:42:42 +09:00
kaglaandGitHub 0253508cd0 Merge pull request #81 from whitedot/ui-fix
UI 수정사항 반영
2022-03-07 14:56:43 +09:00
kaglaandGitHub d602b5e0c6 Merge pull request #150 from loves2tu/google-feed
구글 판매자센터 피드
2022-03-07 14:46:38 +09:00
kaglaandGitHub fff191fc60 Merge pull request #156 from seeoya/inicert
#155 버튼 스타일 변경
2022-03-07 14:41:14 +09:00
kaglaandGitHub b1d22acba8 Merge pull request #158 from 39hn/master
일부 모바일 페이지에서 테마 파일 체크 오류 수정
2022-03-07 14:34:52 +09:00
kaglaandGitHub eba2f45b6c Merge pull request #166 from seeoya/master
다음 쇼핑하우 URL 수정
2022-03-07 14:29:35 +09:00
kagla 1174193b43 버전 5.5.3.1 수정 2022-03-07 09:26:07 +09:00
kagla 07631e70d8 Fatal error: Uncaught Error: Undefined constant "get_session" 아이핀 사용시에 발생하는 치명적인 오류 수정 (미뜨아님,220307) 2022-03-07 09:24:35 +09:00
kagla 203ca4a8a2 버전 5.5.3 2022-03-04 11:15:36 +09:00
kagla 7d7c90bd84 Merge branch 'v5.5.3' 2022-03-04 10:59:05 +09:00
kagla 3e31ce3084 Merge branch 'toss' into v5.5.3 2022-03-04 10:58:27 +09:00
kagla 1123b667af Merge branch 'google_price' into v5.5.3 2022-03-04 10:57:12 +09:00
kagla 694e039b03 1:1문의 등에서 url 오류가 발생하여 사용하지 않는 것으로 추정되는 코드 주석 처리 (작은별님,220304) 2022-03-04 10:47:51 +09:00
kagla 432bf47757 영카트 쇼핑몰 설정 업데이트시 누락되었다고 추정되는 곳에 HOOK 코드 추가 (드렁크수달님,220303 2022-03-03 16:56:46 +09:00
kagla 430586e490 주문내역수정의 결제대행사 링크에 표시되는 LG유플러스를 토스페이먼츠로 수정 (해피정님,220303) 2022-03-03 16:27:42 +09:00
seeoya 95964e3aec G5-40 다음 쇼핑하우 URL 수정 2022-03-02 14:08:48 +09:00
kagla 40cd0362c1 Merge remote-tracking branch 'origin/google_price' into google_price 2022-02-28 16:21:02 +09:00
kagla 53b3308019 코리아크레딧뷰로 KCB 서비스 신청 중단, 기존 사용자님들을 위해 회원사ID 입력 박스만 유지 2022-02-28 16:02:13 +09:00
kagla e0bc3cce81 토스페이먼츠 휴대폰 본인확인 서비스 종료에 따른 설정 수정 2022-02-28 12:25:58 +09:00
kagla 3d57480fef 설치시 누락되어 있던 필수 필드 추가 2022-02-28 11:40:27 +09:00
kagla ff2421df5b 메뉴 삭제시 메뉴설정의 확인 버튼을 눌러 저장해야 한다는 메세지 추가 2022-02-23 16:50:00 +09:00
kagla 3247ae2388 mysqli_connect 오류시 "MySQL Host, User, Password, DB 정보에 오류가 있습니다." 메시지 출력 2022-02-23 16:48:41 +09:00
kagla 36baa2a6ab PHP8에서 Undefined array key "code" 오류 해결 2022-02-23 16:47:33 +09:00
kagla c1259af317 버전 5.5.2 수정 (이니시스 통합인증[간편인증] 추가) 2022-02-22 12:07:39 +09:00
kagla e9c4eda1d7 통합인증과 간편인증 용어의 혼란을 방지하기 위하여 통합인증(간편인증)으로
문구 변경
2022-02-22 12:03:20 +09:00
kagla ce8110a2c1 PHP8 에서 설치시 Undefined variable $tmp_bo_table 오류 해결 (주민님,220221) 2022-02-21 17:35:47 +09:00
kagla e70e4b6cd2 PHP8 회원아이디($mb_id) 정의되지 않은 변수 오류 해결 2022-02-17 17:09:09 +09:00
kagla 1e7a71cdbc PHP8에서 정의되지 않은 오류 해결 (무와보님,220216) 2022-02-16 15:35:42 +09:00
kagla cf08961f63 (KVE-2021-1250) SQL 취약점 및 PHP8 정의되지 않은 변수 오류 해결 2022-02-16 15:13:53 +09:00
kagla 725c88c449 통합인증에서 혼란을 방지하기 위하여 간편인증에 대한 안내문구 추가 2022-02-15 18:17:20 +09:00
jeonghs2015 ecd2b1c72a 버전 5.5.1 수정 (이니시스 간편인증 추가) 2022-02-15 16:54:47 +09:00
39hn 967b7cca18 일부 모바일 페이지에서 테마 파일 체크 오류 수정 2022-01-28 09:50:00 +09:00
seeoya ff74503bac #155 버튼 스타일 변경 2022-01-24 14:16:30 +09:00
kagla 524deac54a 버전 5.5.1-beta 수정 2022-01-19 15:47:15 +09:00
kagla 1440e6a790 Merge branch 'inicert' of github.com:gnuboard/gnuboard5 into inicert 2022-01-19 15:39:43 +09:00
형진andGitHub 7a6b0a3576 Merge pull request #151 from projectSylas/inicert
간편인증 : sa -> simple로 변경
2022-01-19 15:20:09 +09:00
projectSylas 1870a7d131 간편인증 : sa -> simple로 변경 2022-01-19 06:19:04 +00:00
loves2tu b8223d4409 구글 판매자센터 피드
- 상품 adult 관련 추가 수정
2022-01-19 06:16:31 +00:00
kaglaandGitHub 352f77d1d7 Merge pull request #135 from loves2tu/google-feed
구글 판매자센터 피드 xml 생성코드입니다.
2022-01-19 14:10:54 +09:00
형진andGitHub 6182fce3a0 Merge pull request #149 from projectSylas/inicert
통합인증 : hot-fix
2022-01-17 16:48:22 +09:00
projectSylas 4cc9e6b001 통합인증 : 비밀번호 찾기 alert 문구 수정 2022-01-17 06:52:03 +00:00
projectSylas c58122c573 Merge branch 'inicert' of https://github.com/gnuboard/gnuboard5 into inicert 2022-01-17 06:44:09 +00:00
projectSylas 8fd390c46c 통합인증 : 관련 이슈 수정
- 회원 직접 탈퇴 시 dupinfo 제거
- 본인인증 갱신 시 이전페이지로 이동하게 수정
- 본인인증 내역 기록 조건 수정
2022-01-17 06:43:55 +00:00
kagla ad48b6ba00 버전 5.4.22 수정 2022-01-17 14:53:39 +09:00
민섭andGitHub b1930b9ede Merge pull request #148 from seeoya/inicert
inicert 프론트 변경사항
2022-01-17 11:59:08 +09:00
seeoya 75174615c7 관리자 : 본인확인설정 - 회원정보찾기 항목 안내문구 추가, confirm 제거 2022-01-17 11:52:53 +09:00
민섭andGitHub f29d32a86c Merge pull request #147 from seeoya/inicert
Inicert 프론트 변경사항
2022-01-17 11:34:18 +09:00
seeoya 1044bb9d37 모바일 회원가입 - placeholder 문구 변경 2022-01-17 11:29:13 +09:00
seeoya 92529d9c1e 회원정보찾기/추가본인인증 페이지 버튼 스타일 변경 2022-01-17 11:27:54 +09:00
민섭andGitHub fa02b84889 Merge pull request #146 from seeoya/inicert
통합인증 : 추가 개인정보처리방침 안내에 필수 표시 추가, 체크박스 색상 변경
2022-01-13 17:57:44 +09:00
seeoya fefe11f321 통합인증 : 추가 개인정보처리방침 안내에 필수 표시 추가, 체크박스 색상 변경 2022-01-13 17:53:03 +09:00
민섭andGitHub cf156f5d9e Merge pull request #144 from seeoya/inicert
Inicert 프론트 변경사항
2022-01-11 18:04:44 +09:00
수영andGitHub 4f00321bcf Merge branch 'inicert' into inicert 2022-01-11 18:04:36 +09:00
seeoya 0898268692 새창 기본 스타일 - 버튼 가운데정렬 추가 2022-01-11 16:07:52 +09:00
seeoya 830cffefb0 통합인증 > 간편인증 문구 변경 2022-01-11 15:14:09 +09:00
seeoya 78f95c3182 ID/PW 찾기 박스 배경색 추가, 간격 추가 2022-01-11 15:03:01 +09:00
seeoya 7a8280af93 회원가입/정보수정 필수 항목 병기, 본인확인 시 자동입력 문구 추가, 체크박스 색상 변경 2022-01-11 14:50:26 +09:00
seeoya 7fe8d391d9 관리자 admin.css 파일의 오타 제거 (FreeMax님, 220106) 2022-01-10 14:30:46 +09:00
seeoya 21f4cf82a7 #133 쇼핑몰 상품문의, 사용후기 이동 시 해당 탭 활성화 (작은별님, 211229) 2022-01-10 14:29:58 +09:00
seeoya 7783027b58 #139 관리자 input에 좌우 여백 추가 2022-01-10 14:23:43 +09:00
seeoya 6e72dc7af4 사용후기 전체보기에서 관리자 답변이 보이지 않는 오류 수정 (작은별님, 220108) 2022-01-10 14:21:49 +09:00
seeoya 2f017e81a4 통합인증 : 버튼 클래스 추가 2022-01-10 13:37:27 +09:00
kagla 80a1c9ac48 버전 5.4.21 수정 2022-01-10 12:28:12 +09:00
kagla 6667adbef9 Merge branch 'thumbnail_file_delete' 2022-01-10 12:26:57 +09:00
kagla c0b790e7f9 Merge branch 'board_headtail' 2022-01-10 11:56:09 +09:00
형진andGitHub 71a908ebac Merge pull request #141 from projectSylas/inicert
통합인증 : 브라우저로 접근한 모바일에서도 정상적으로 작동하게끔 스크립트 수정
2022-01-07 14:06:06 +09:00
projectSylas ce7e5b2c3d 통합인증 : 브라우저로 접근한 모바일에서도 정상적으로 작동하게끔 스크립트 수정 2022-01-07 04:49:26 +00:00
kagla 27216e2135 KG이니시스 통합인증 UI 변경 및 PHP8 에서 나오는 오류 수정 2022-01-07 12:15:28 +09:00
형진andGitHub b2c930c547 Merge pull request #138 from projectSylas/inicert
본인인증갱신 : 갱신 쿼리 오류 수정
2022-01-06 10:57:52 +09:00
projectSylas 2f6096f6a8 본인인증갱신 : 갱신 쿼리 오류 수정 2022-01-06 01:56:46 +00:00
projectSylas f56b577c25 게시판관리에서 상단, 하단 파일 경로를 입력하지 않았다면 기본 상단, 하단
파일을 include 하지 않도록 수정 (작은별님,220105)
2022-01-05 16:29:56 +09:00
형진andGitHub 54103ddfe4 Merge pull request #137 from projectSylas/inicert
통합인증 이슈 수정
2022-01-05 11:12:53 +09:00
projectSylas c64fbaeb8e Merge branch 'master' of https://github.com/gnuboard/gnuboard5 into inicert 2022-01-05 02:07:17 +00:00
projectSylas 8bdf80e38c 본인인증 : 본인이아닌 타인이 인증할때 명의가 변경되지 못하게 수정 2022-01-05 01:50:57 +00:00
loves2tu d930791504 구글 판매자센터 피드
- 구글 쇼핑 파일이름, 파일 URL 관련 수정
2022-01-04 07:41:39 +00:00
loves2tu 57fc5353f1 구글 판매자센터 피드
- 테스트용 피드 삭제
2022-01-04 06:12:21 +00:00
projectSylas 9aa5d237a7 회원관리 : 회원 삭제시 본인인증 관련 정보 제거 2022-01-04 05:38:25 +00:00
projectSylas 033924f011 BBS : 게시판에서 본인확인 미사용시 비회원으로 접근하면 접근 불가능하던 이슈 수정 2022-01-04 05:37:31 +00:00
projectSylas ae29c976e6 통합인증 : 이름/핸드폰 인풋 밸류 조작시 해쉬값 체크 로직 추가 2022-01-04 05:36:16 +00:00
seeoya 2fc24b0746 구글 판매자센터 피드 항목 추가 2022-01-03 03:16:32 +00:00
loves2tu ebdd3b4390 구글 판매자센터 피드
- availability, adult 네임스페이스(g) 추가
2021-12-31 06:44:44 +00:00
loves2tu 4227039811 구글 판매자센터 피드
- 모든 옵션재고 중 1이상의 재고가 존재하는 경우 : in_stock
2021-12-31 06:32:14 +00:00
loves2tu 754b25191f Revert "구글 판매자센터 피드"
This reverts commit 8fbbae488b.
2021-12-31 06:18:08 +00:00
loves2tu 8fbbae488b 구글 판매자센터 피드
- 상품의 재고 & 상품옵션의 재고에 따른 재고값 수정
2021-12-31 06:03:15 +00:00
projectSylas 69b322144a 공지글 이동시 bo_notice 에서 글번호가 사라지지 않는 오류 수정 (ifelse님,211231) 2021-12-31 11:40:06 +09:00
loves2tu d97f27f2fa 구글 판매자센터 피드
- 상품 재고에 따른 out_of_stock 변경
2021-12-30 08:37:12 +00:00
loves2tu bddbcd5cdd 구글 판매자센터 피드
- query 수정 (table 조회 오류)
2021-12-30 05:42:30 +00:00
loves2tu 4c297a1e53 구글 판매자센터 피드
- 반복문 변수 오류 수정
2021-12-30 05:04:36 +00:00
loves2tu c82c33fc59 구글 판매자센터 피드
- 이미지 img1~10 존재여부 확인 후  image_link 생성
2021-12-29 06:29:16 +00:00
projectSylas 52f7eef288 공지글이 없을때 나오는 오류 Trying to access array offset on value of type null 수정 2021-12-29 11:37:29 +09:00
kaglaandprojectSylas 7d22399eac 버전 5.4.20 수정 2021-12-29 11:37:03 +09:00
loves2tu f25354b1b2 구글 판매자센터 피드
- 예외처리 추가 (it_id, it_name)
2021-12-28 05:46:48 +00:00
loves2tu daffdcbfce 구글 판매자센터 피드
- 다중카테도리 관련 성인인증 처리 수정
2021-12-28 05:16:19 +00:00
loves2tu 322e5cf83a 구글 판매자센터 피드
- 성인인증관련 category 조회 query 추가
2021-12-28 03:08:28 +00:00
loves2tu 7a2c29f192 구글 판매자센터 피드
- query 수정
 - 예외처리 추가
2021-12-27 05:56:08 +00:00
projectSylas 9af6991edd 그누보드만 사용하는 경우 썸네일 일괄삭제시 나오는 오류 수정 (МишаЧжан님,121227) 2021-12-27 09:50:55 +09:00
projectSylas 0ba6f3d861 통합인증 : die코드 제거 2021-12-24 08:01:20 +00:00
loves2tu 98b085e73e 구글 판매자센터 피드
- query 수정중
2021-12-23 02:09:11 +00:00
projectSylas 4305e6c8cc 통합인증 : kgcert를 inicert로 수정, 문구 kg -> ini로 수정 기존 인증버튼 여러개 -> 통합인증 하나로 통합 2021-12-22 05:51:24 +00:00
kagla a73967dd9a 버전 5.4.20 수정 2021-12-22 11:05:18 +09:00
kagla d941742b67 Merge branch 'total_cnt' of github.com:gnuboard/gnuboard5 into total_cnt 2021-12-22 10:59:30 +09:00
kagla 73a0f6ea80 Merge branch 'xss-pocas' 2021-12-22 10:57:49 +09:00
kagla 66d440f75e Merge branch 'xss-pocas' of github.com:gnuboard/gnuboard5 into xss-pocas 2021-12-22 10:57:19 +09:00
kagla 20c94e5b0a [보안패치] $kind 변수를 이용한 XSS 취약점 수정 (Pocas님,211214) 2021-12-22 10:56:51 +09:00
kagla f8480a41c8 중복된 </i> 태그 한개 삭제 (김철용님,211222) 2021-12-22 10:52:33 +09:00
kagla 26f6b802b7 SMS5 솔루션 설치시 불필요한 변수 삭제 (작은별님,211222) 2021-12-22 10:37:15 +09:00
loves2tu 8faa9ba9a2 구글 판매자센터 피드
- echo xml 생성 관련 코드 적용 중
2021-12-21 07:58:42 +00:00
projectSylas 72e041db10 dlab : kgcert를 inicert로 수정, 문구 kg -> ini로 수정 2021-12-21 07:41:14 +00:00
projectSylas bc8162f7fe Merge remote-tracking branch 'origin/master' into inicert 2021-12-21 04:59:20 +00:00
loves2tu f7aac7c467 구글 판매자센터 피드
- 상품 관련 query 작업중
2021-12-21 04:40:23 +00:00
projectSylas dfa677aadb 쇼핑몰 검색시 PC의 '전체분류'가 0으로 표시되는 오류 수정 (콜라시러님,211215)
전체분류가 앞에 나오도록 수정
2021-12-16 16:01:22 +09:00
kagla 2e81619ea8 $kind 변수를 이용한 XSS 취약점 수정 (Pocas님,211214) 2021-12-14 16:10:41 +09:00
kagla 796b6d9ab1 버전 5.4.19 수정 2021-12-09 10:48:40 +09:00
kagla d28c165fdf url에 타도메인을 지정할 수 있는 오류 수정 (Pocas님,211208) 2021-12-09 10:45:48 +09:00
kagla 80a71fef56 설치시 data/file/ 디렉토리에 기본게시판 디렉토리(free, gallery, notice, qa)가 만들어지지 않는 오류 수정 (작은별님,211206) 2021-12-08 12:28:56 +09:00
kagla 2144538f7e Merge branch 'visit_delete' 2021-12-08 11:03:57 +09:00
kagla d87802eb94 (KVE-2021-1846) url 값에 Line feed인 "%0A" 값을 삽입하여 전송하는 경우 check_url_host 함수 우회 취약점 수정 (Pocas님) 2021-12-08 10:38:18 +09:00
kagla 8c8bb94d68 접속자로그가 없을때 년도가 0부터 시작하는 것을 현재년도가 나오도록 수정 (다온테마님,211115) 2021-11-24 15:26:47 +09:00
projectSylas 7a054e1dbb .gitignore 에 pma 추가 2021-11-11 04:09:01 +00:00
kagla edb0b849d9 버전 5.4.18 수정 2021-10-25 11:15:26 +09:00
projectSylasandkagla 6ee9b1fbf2 PHP8에서 상단 파일 경로, 하단 파일 경로가 없을때 나오는 오류 수정 (루미집사님,211025) 2021-10-25 11:11:51 +09:00
kagla 413044ab06 이후 버전의 PHP에서는 class 에 속한 method(함수) 이름을 class 이름과 동일하게 만들 수 없습니다. 2021-10-25 11:11:51 +09:00
kagla 6148da1add $BANK_CODE 에 토스뱅크(92) 추가 2021-10-25 11:11:51 +09:00
kagla 9020d246b7 비밀 댓글 수정시 비밀글 해제가 되지 않는 오류를 수정 (한별아빠님,211022) 2021-10-25 11:11:50 +09:00
kagla de73f54959 신용카드 결제창에서 네이버페이를 지원하므로 상품상세페이지, 장바구니에서 더이상 네이버페이 직접결제를 지원하지 않음 2021-10-19 11:44:19 +09:00
kagla 9ada18ae56 버전 5.4.17 수정 2021-10-18 12:15:07 +09:00
kagla ddaf4f9794 Merge branch 'KVE-2021-0755' 2021-10-18 12:13:35 +09:00
kagla 920d5fc34c Merge branch 'KVE-2021-0849' 2021-10-18 12:13:00 +09:00
kagla 3a3434104c (KVE-2021-0755) 메뉴의 링크 기능을 이용한 XSS 취약점 수정 2021-10-15 16:40:04 +09:00
kagla 6dc462d784 (KVE-2021-0849) 확장자 .phar 파일 업로드 취약점 수정 2021-10-15 16:04:17 +09:00
kagla 24ba84d6f0 KG이니시스 가상계좌 사용시 안내문구 중 거래조회를 거래내역으로 수정 2021-10-14 14:49:20 +09:00
kagla 650ea16523 shop_is_taxsave 함수에 $od_pay_type 변수의 vbank, transfer 가 바뀌어 있는 것을 수정 (moons님,211014) 2021-10-14 14:47:32 +09:00
projectSylas 7be96449b8 버전 5.5.0.2-beta 수정 2021-10-12 04:39:05 +00:00
민섭andGitHub 3d7145c947 Merge pull request #124 from whitedot/inicert
관리자 : 회원 상세보기에서 본인인증 내역 확인 정리
2021-10-07 16:50:20 +09:00
whitedot eb812f32fb 관리자 : 회원 상세보기에서 본인인증 내역 확인 정리 2021-10-07 16:46:01 +09:00
형진andGitHub f3ef7efa91 Merge pull request #123 from projectSylas/inicert
회원관리 : 본인인증 내역 추가, 코드정리, 이슈해결
2021-10-07 15:46:00 +09:00
형진andGitHub 95e6296af1 Merge branch 'gnuboard:inicert' into inicert 2021-10-07 15:33:54 +09:00
projectSylas 707fceb694 소셜, 회원가입, 비밀번호찾기 : 카카오 버튼 추가, 스크립트 정리 2021-10-07 06:31:46 +00:00
projectSylas 950e3ff6c6 재인증 : 조건 위치 변경, 이동페이지 지정 2021-10-07 06:08:38 +00:00
projectSylas 5eb294eaff 게시판, 쇼핑몰 : 본인인증 알림 관련 조건, 변수 수정 2021-10-07 06:08:06 +00:00
projectSylas fc01d803f3 본인인증 내역 : 본인 인증시 회원별 히스토리 기록 테이블 추가, 기능 추가 2021-10-07 05:44:00 +00:00
projectSylas cbd9fc4a86 통합인증 : 코드정리 2021-10-06 08:10:45 +00:00
projectSylas 1be4ef9397 버전 5.5.0.1-beta 수정 2021-10-05 06:29:47 +00:00
형진andGitHub 05cb595439 Merge pull request #120 from projectSylas/inicert
회원가입 : 스킨별 인증 안내 출력 수정사항 반영
2021-10-05 14:58:11 +09:00
projectSylas c7f19057e5 회원가입 : 스킨별 인증 안내 출력 수정사항 반영 2021-10-05 05:56:15 +00:00
형진andGitHub 00cf4e5b48 Merge pull request #118 from seeoya/inicert
통합인증 : 본인확인 사용 시에만 아이디/비밀번호 찾기에 이용할 수 있도록 수정
2021-10-05 14:17:18 +09:00
seeoya 31201ba451 통합인증 : 본인확인 사용 시에만 아이디/비밀번호 찾기에 이용할 수 있도록 수정 2021-10-05 14:14:57 +09:00
projectSylas 6fe49ff106 상수 G5_SEO_TITEL_WORD_CUT 을 G5_SEO_TITLE_WORD_CUT 로 수정 (sinbi님,211005) 2021-10-05 02:17:34 +00:00
형진andGitHub a92ff130d5 통합인증 : 인증 안내 출력 조건 추가
통합인증 : 인증 안내 출력 조건 추가
2021-10-01 16:55:07 +09:00
projectSylas e5d24941ec 통합인증 : 인증 안내 출력 조건 추가 2021-10-01 07:54:11 +00:00
형진andGitHub f016870a7c Merge pull request #116 from seeoya/inicert
통합인증 관련 안내 추가
2021-10-01 16:32:58 +09:00
seeoya 247bfab4c0 통합인증 : 모바일 - 회원가입/소셜 회원가입 안내 줄바꿈 추가 2021-10-01 16:24:50 +09:00
seeoya 06ad2e7df1 Merge branch 'inicert' of https://github.com/seeoya/gnuboard5 into inicert 2021-10-01 16:20:43 +09:00
seeoya 82e27485fe 통합인증 : 회원가입/소셜 회원가입 본인인증 관련 안내 추가 2021-10-01 16:20:15 +09:00
seeoya 0b19dcecd1 통합인증 : 기존 회원 본인인증 페이지 섹션 스타일 변경 2021-10-01 16:01:37 +09:00
형진andGitHub b51e361e2a Merge pull request #115 from projectSylas/inicert
통합인증 : 특정사용자 구분코드 해제
2021-10-01 15:40:48 +09:00
형진andGitHub 3f9bc7367f Merge branch 'gnuboard:inicert' into inicert 2021-10-01 15:39:39 +09:00
projectSylas 7457a2e4ac 통합인증 : 특정사용자 구분코드 해제 2021-10-01 06:38:55 +00:00
형진andGitHub 44603fd145 Merge pull request #114 from projectSylas/inicert
본인확인 : submit form name 변경
2021-10-01 15:28:55 +09:00
projectSylas 5b3a895547 본인확인 : submit form name 변경 2021-10-01 06:24:28 +00:00
형진andGitHub 72382caafe Merge pull request #113 from seeoya/inicert
통합인증 관련 알림 문구 변경
2021-10-01 15:23:59 +09:00
seeoya 80716c838a 통합인증 : 비밀번호 재설정 페이지 알림 문구 변경 2021-10-01 15:22:35 +09:00
seeoya a82c43c31d 통합인증 : 기존 회원 본인인증 페이지 알림 문구 변경 2021-10-01 15:22:19 +09:00
kagla 5b4bb06d74 버전 5.5.0-beta 수정 2021-10-01 03:31:27 +00:00
kagla 1e515ab177 Merge branch 'inicert' of github.com:gnuboard/gnuboard5 into inicert 2021-10-01 03:11:09 +00:00
형진andGitHub cacaf29ff6 Merge pull request #112 from projectSylas/inicert
통합인증 branch name inicert로 변경 master 최신 내용 merge
2021-10-01 11:42:40 +09:00
kagla 105ac603bb Merge branch 'inicert' of github.com:gnuboard/gnuboard5 into inicert 2021-10-01 02:39:59 +00:00
projectSylas 8815c4527c Merge remote-tracking branch 'origin/master' into inicert 2021-10-01 02:37:43 +00:00
형진andGitHub 70173fbccb Merge pull request #111 from projectSylas/inicis-cert-sa
회원가입 : 본인인증을 사용하는지 체크하는 조건 추가
2021-09-30 16:17:40 +09:00
projectSylas 81a0537f66 회원가입 : 본인인증을 사용하는지 체크하는 조건 추가 2021-09-30 07:16:43 +00:00
형진andGitHub dc2dc8bce2 Merge pull request #110 from seeoya/inicis-cert-sa
통합인증 검수
2021-09-30 16:15:00 +09:00
seeoya b654fbd186 통합인증 : 로그인 상태로 비밀번호 찾기 페이지 접근 시 홈으로 이동하도록 추가 2021-09-30 16:07:55 +09:00
seeoya 1eabc482f2 통합인증 : 기존 회원 본인인증 안내 문구 변경 2021-09-30 16:07:48 +09:00
형진andGitHub 3681c64132 Merge pull request #109 from projectSylas/inicis-cert-sa
통합인증 검수
2021-09-30 16:06:15 +09:00
projectSylas 8f3acd13e1 회원가입, 정보수정 : 본인인증이 필수일때 readonly 처리 조건 수정 및 로직 변경 2021-09-30 07:04:23 +00:00
projectSylas d2310221cc 소셜로그인 : 이메일 readonly 처리조건 추가, 코드 정리 2021-09-30 05:30:41 +00:00
projectSylas 0ddb2a97be 재인증 : 폼네임변경, 파일명 변경 2021-09-30 05:29:31 +00:00
projectSylas 779623b4e3 재인증 : 직접접근 불가 코드 추가 2021-09-30 05:27:28 +00:00
projectSylas 1f0a2dfc2f Merge branch 'inicis-cert-sa' of https://github.com/gnuboard/gnuboard5 into inicis-cert-sa 2021-09-29 07:47:58 +00:00
형진andGitHub ab0824e5d5 Merge pull request #108 from seeoya/inicis-cert-sa
통합인증 : 기존 회원 본인인증 페이지 id/class명 변경, 주석 제거
2021-09-29 16:34:28 +09:00
seeoya 3841cbd2ec 통합인증 : 기존 회원 본인인증 페이지 id/class명 변경, 주석 제거 2021-09-29 16:32:16 +09:00
projectSylas 0d226ef6fb 재인증 : 스킨파일명 수정 2021-09-29 03:26:39 +00:00
projectSylas 80639b4fff Merge branch 'inicis-cert-sa' of https://github.com/projectSylas/gnuboard5 into inicis-cert-sa 2021-09-29 03:18:22 +00:00
projectSylas 6ab674b475 TODO 제거, 미사용 파일제거 2021-09-29 03:17:51 +00:00
형진andGitHub 68153d4afa Merge pull request #107 from projectSylas/inicis-cert-sa
소셜 회원가입 : 누락된 조건 추가
2021-09-29 12:11:51 +09:00
형진andGitHub f038dc98bf Merge branch 'gnuboard:inicis-cert-sa' into inicis-cert-sa 2021-09-29 12:10:27 +09:00
projectSylas d689d10ada 소셜회원가입 : 누락된 조건 추가 2021-09-29 03:08:33 +00:00
형진andGitHub ab9f980aea Merge pull request #106 from projectSylas/inicis-cert-sa
회원가입 : 휴대폰 번호 필수입력, 읽기전용 조건 수정
2021-09-29 12:03:41 +09:00
projectSylas 736aa92769 통합인증 : 코드 정리 2021-09-29 03:02:00 +00:00
projectSylas 40694f2b75 회원가입 : 휴대폰번호 readonly required 조건수정 2021-09-29 03:00:26 +00:00
형진andGitHub 1eee9e46a4 Merge pull request #105 from projectSylas/inicis-cert-sa
php8 버전 관련 호환코드 추가
2021-09-28 17:35:57 +09:00
projectSylas cce78676c0 관리자 : 이니시스 mid 값 공백제거 추가 2021-09-28 08:29:15 +00:00
projectSylas f600cc65da 회원 가입 : 휴대폰번호 읽기전용 처리 조건 추가 2021-09-28 08:23:07 +00:00
projectSylas c69090fc4d 회원 가입 : php8 호환 코드 수정 2021-09-28 07:57:10 +00:00
projectSylas e3aa70a886 본인인증 : die 제거 2021-09-28 07:46:17 +00:00
projectSylas 21269e632b 본인인증 : 전체 모듈 php8 호환 코드 추가, 스위치문 개선 2021-09-28 07:45:25 +00:00
projectSylas 166c5e92bd 통합인증 : php8버전 관련 에러 수정, 재인증시 성명도 갱신되게 쿼리 추가 2021-09-28 06:56:02 +00:00
projectSylas 497ac75031 통합인증 : php8버전 관련 에러 수정 2021-09-28 06:12:21 +00:00
projectSylas 8eadd8b33f 통합인증 : 재인증페이지 조건 누락된것 추가 2021-09-28 06:11:41 +00:00
형진andGitHub 1b2729c2ff Merge pull request #104 from seeoya/inicis-cert-sa
통합인증 : 관리자 부가서비스 높이 지정
2021-09-27 11:48:20 +09:00
seeoya 4938bd75f4 통합인증 : 관리자 부가서비스 높이 지정 2021-09-27 11:46:23 +09:00
형진andGitHub 4e52b8c047 Merge pull request #103 from seeoya/inicis-cert-sa
통합인증 모바일 스타일 추가
2021-09-27 10:02:12 +09:00
seeoya facdeb2f00 통합인증 : 버튼 중복 id 제거 2021-09-24 15:37:52 +09:00
seeoya c6265aee2a 통합인증 : 모바일 공통 스타일 재지정 2021-09-24 15:23:29 +09:00
형진andGitHub 781c99b35d Merge pull request #102 from projectSylas/inicis-cert-sa
기존회원 인증 갱신 관련 수정
2021-09-24 12:08:27 +09:00
projectSylas 8f7f468910 통합인증 : 인증 갱신 관련 조건 추가 bbs/영카트 2021-09-24 02:56:12 +00:00
projectSylas 49283792d2 통합인증 : 인증 갱신 관련 추가 작업 2021-09-24 02:55:23 +00:00
projectSylas 15821991f2 본인인증 : 결과페이지 재인증페이지 서브밋 스크립트 추가 2021-09-24 02:47:42 +00:00
kagla c74c04bf16 버전 5.4.16 수정 2021-09-23 05:29:22 +00:00
kagla 816b658252 Merge branch 'master' of github.com:gnuboard/gnuboard5 2021-09-23 12:24:35 +09:00
kagla 3d668f1a1d Merge branch 'qa' 2021-09-23 03:10:52 +00:00
kagla fa780a5aa3 Merge branch 'cheditor' 2021-09-23 03:09:22 +00:00
kagla f029210122 Merge branch 'php8' 2021-09-23 03:07:29 +00:00
kagla 54080f516a Merge branch 'naverpay' 2021-09-23 03:04:17 +00:00
kagla a42041a645 Merge branch 'qa' 2021-09-23 11:52:41 +09:00
kagla 0b74f2ec32 Merge branch 'sns' 2021-09-23 11:43:38 +09:00
kagla b2041758f4 PHP8에서 나오는 Undefined array key "HTTP_USER_AGENT" 오류 수정 2021-09-16 06:07:41 +00:00
kagla 469e1ff890 PHP8에서 나오는 PHP Warning: Undefined array key "HTTP_USER_AGENT" 오류 수정 2021-09-16 06:05:59 +00:00
kagla abe801a7ac PHP8에서 나오는 PHP Warning: Undefined array key "HTTP_USER_AGENT" 오류 수정 2021-09-16 06:05:07 +00:00
kagla f283e6c3d9 이미지 확장자에 .webp 추가 2021-09-16 04:56:06 +00:00
kagla 50612db75a 경로가 잘못 반환되어 thumb-이미지 파일이 삭제되지 않던 오류 수정 2021-09-16 04:55:11 +00:00
kagla 63217a6a67 ['HTTP_HOST'] 가 선언되지 않아 PHP8 에서 발생하던 오류 수정 2021-09-16 04:54:33 +00:00
kagla 688440eb18 JavaScript 불가일 때 Undefined variable $js 오류 나오지 않도록 수정 (조안님,210916) 2021-09-16 02:09:09 +00:00
형진andGitHub 6724b2d59f Merge pull request #99 from seeoya/inicis-cert-sa
소셜 회원가입 스타일 변경
2021-09-15 17:44:16 +09:00
seeoya 8a355b2b98 회원 : 소셜회원가입 - 이름/휴대폰번호 폼체크 제거 2021-09-15 17:37:39 +09:00
seeoya 2e10febd85 Merge branch 'inicis-cert-sa' of https://github.com/seeoya/gnuboard5 into inicis-cert-sa 2021-09-15 17:34:02 +09:00
seeoya 88b781e631 회원 : 소셜회원가입 페이지 스타일 변경, 모바일 스타일 적용 2021-09-15 17:26:09 +09:00
seeoya 7a8eca575c 모바일 : 회원가입 폼 버튼 너비 스타일 변경, 주소 검색 버튼 위치 변경 2021-09-15 17:22:16 +09:00
형진andGitHub df62e80d0a Merge pull request #98 from seeoya/inicis-cert-sa
기존 회원 본인인증 페이지 추가
2021-09-15 14:54:17 +09:00
seeoya 6f30fed6fa Merge branch 'inicis-cert-sa' of https://github.com/seeoya/gnuboard5 into inicis-cert-sa
Conflicts:
	adm/config_form.php
2021-09-15 12:21:46 +09:00
seeoya 20bb92025f 미사용 스타일 코드 제거 2021-09-15 12:19:54 +09:00
seeoya d2efd07536 회원 : 모바일 회원가입 - 소셜 로그인 버튼 스타일 오류 수정 2021-09-15 12:12:21 +09:00
seeoya 1c7b4d5501 관리자 : 아이디/비밀번호 찾기에 본인확인을 사용할 때 확인 안내창 추가 2021-09-15 12:09:33 +09:00
seeoya 6dc37c2162 회원 : 기존 회원 본인인증 페이지 추가 2021-09-15 12:06:31 +09:00
kagla a3e8c97ef5 이미지 파일 업로드 기능을 이용한 웹변조 방지 코드 적용 (나창호님,레이딘님,210915) 2021-09-15 02:30:19 +00:00
형진andGitHub 7a9e66542b Merge pull request #97 from projectSylas/inicis-cert-sa
이니시스 통합인증 모듈 추가
2021-09-15 11:22:18 +09:00
projectSylas a034428b25 통합인증 : 이니시스 통합인증 관련 수정 2021-09-15 02:17:28 +00:00
projectSylas 0f527be72e 소셜로그인 : 소셜로그인 가입 시 본인인증 로직 추가 2021-09-15 02:15:15 +00:00
projectSylas 28dbc78cdc 통합인증 : 통합인증 관련 공통 자바스크립트 추가 2021-09-15 02:12:47 +00:00
projectSylas 20842daa0d 회원정보찾기 : 비밀번호 재설정 페이지 테마 기본스킨에도 추가 2021-09-15 02:11:58 +00:00
projectSylas 24467e69ae 회원정보찾기 : 비밀번호 재설정 페이지 추가 2021-09-15 02:11:11 +00:00
projectSylas 3c7439fc0a 회원정보찾기 : KGB 휴대폰/아이핀 인증 관련 수정 2021-09-15 02:10:09 +00:00
projectSylas 1d32545552 회원정보찾기 : 토스 휴대폰 인증 관련 수정 2021-09-15 02:09:41 +00:00
projectSylas d48ff6cffe 회원정보찾기 : 이니시스통합인증 관련 수정 2021-09-15 02:09:17 +00:00
projectSylas 430e6d29e7 회원정보찾기 : kcp 휴대폰 인증 관련 수정 2021-09-15 02:08:50 +00:00
kagla 7dea8e6866 PHP8 에서 발생하는 오류 수정 2021-09-15 01:14:45 +00:00
projectSylas 353a1ad784 통합인증 : 이니시스 모듈 추가 2021-09-13 06:08:11 +00:00
projectSylas 5fc6fcd4ac 통합인증 : 관리자 비밀번호 찾기 관련 수정 2021-09-13 06:07:26 +00:00
projectSylas 84a9f8eb3d 통합인증 : 세션관련 오류 해결 2021-09-13 06:07:04 +00:00
projectSylas 41057b9f2e 관리자 : 통합인증 관련 인풋 네임변경 2021-09-10 05:28:42 +00:00
projectSylas d9617a8c1e Merge remote-tracking branch 'origin/inicis-cert-sa' into inicis-cert-sa 2021-09-10 05:27:53 +00:00
projectSylas 2818da8bc6 통합인증 : 백엔드 선행 작업 2021-09-10 05:26:32 +00:00
형진andGitHub d2eb7a9c6a Merge pull request #96 from seeoya/inicis-cert-sa
소셜 회원가입 페이지 수정
2021-09-10 14:24:22 +09:00
seeoya a18b7b7d30 Merge branch 'inicis-cert-sa' of https://github.com/seeoya/gnuboard5 into inicis-cert-sa 2021-09-10 14:15:35 +09:00
seeoya eeff1e7181 통합인증 관리자 설정 - MID 입력 수정 2021-09-10 14:15:18 +09:00
seeoya f2f8c01293 #92 소셜 회원가입 페이지 수정 2021-09-10 14:14:15 +09:00
projectSylas 96d37a8ef6 Merge branch 'inicis-cert-sa' of https://github.com/projectSylas/gnuboard5 into inicis-cert-sa 2021-09-10 01:14:04 +00:00
kagla ebf00b6834 배너의 링크를 입력하지 않으면 PHP8에서 Warning: Uninitialized string offset 0 in ... 와 같은 오류가 나는것을 수정 (다온테마님,210908) 2021-09-09 03:24:40 +00:00
kaglaandGitHub 6090b0de18 Merge pull request #94 from whitedot/master
게시판 : 갤러리 스킨에서 selector 선언 오류 수정
2021-09-08 15:33:26 +09:00
whitedot 0b11cee221 게시판: 갤러리 스킨에서 selector 선언 오류 수정 (작은별님,11437) 2021-09-08 15:28:24 +09:00
whitedot ce7de94486 스타일시트: 사용하지 않는 코드 삭제 2021-09-08 15:25:49 +09:00
kagla fc0f67d4c2 $i 값이 증가하지 않아 같은 id 값이 생성되는 오류 수정 2021-09-08 13:58:58 +09:00
형진andGitHub d713fbd1e3 Merge pull request #93 from seeoya/inicis-cert-sa
통합인증 프론트 2차 작업, #91 개인정보처리방침 문구 변경
2021-09-07 17:59:24 +09:00
kagla f75202786e <div></div> 쌍이 맞지 않는 버그 수정. </div> 한개 제거 (웹학교님,210906) 2021-09-07 16:03:01 +09:00
kagla 5c73de46a9 Merge branch 'master' of github.com:gnuboard/gnuboard5 2021-09-07 15:53:24 +09:00
kagla e14e392488 Scripts may close only the windows that were opened by them. 자신이 연 창만 닫을 수 있는 오류 수정. (ifelse님,210907) 2021-09-07 15:52:59 +09:00
seeoya 53e5d179d4 회원: #91 회원가입 페이지 개인정보처리방침 > 개인정보 수집 및 이용으로 문구 변경 2021-09-07 14:46:13 +09:00
seeoya d97f0d87c3 통합인증 : 프론트 2차 작업 2021-09-07 14:19:25 +09:00
EC2 Default User 9d0ead3140 방문자분석 스크립트를 출력하는 코드가 두번 작성되어 있어 하나를 삭제함 (웹학교님,210902) 2021-09-03 02:11:46 +00:00
kaglaandGitHub 02fac2bfa5 Merge pull request #90 from seeoya/inicis-cert-sa
통합인증 프론트 선행작업
2021-09-01 09:32:13 +09:00
seeoya f133acda17 통합인증 : 프론트 선행 작업 2021-09-01 09:27:12 +09:00
seeoya 543ed66fc4 관리자 : 본인확인 항목 미선택 알림창 오타 수정 2021-08-30 17:31:16 +09:00
민섭andGitHub 2e3ef9cf43 Merge pull request #89 from whitedot/inicis-cert-sa
통합인증 : 기초 작업
- 정보찾기를 ID/PW 찾기 혹은 아이디/비밀번호 찾기로 용어 변경하고 현재창에 뜨도록
- 본인인증을 이용한 아이디/비밀번호 재설정 페이지(only url) 추가
2021-08-30 11:15:15 +09:00
whitedot e333412be6 통합인증 : 기초 작업
- 정보찾기를 ID/PW 찾기 혹은 아이디/비밀번호 찾기로 용어 변경하고 현재창에 뜨도록
    - 본인인증을 이용한 아이디/비밀번호 재설정 페이지(only url) 추가
2021-08-30 11:13:28 +09:00
whitedot 007389b299 회원 : 본인확인 중복체크 결과에서, 기가입된 회원아이디를 알려주지 않도록 변경 2021-08-27 18:29:18 +09:00
kagla c4544671a2 모바일 결제시 카드사명이 제대로 들어가지 않던 오류 수정 (chewry님,210817) 2021-08-24 13:55:22 +09:00
kagla 38308f887b 트위터 소셜 댓글 사용시 Could not connect to Twitter. Refresh the page or try again later. 이전에 나오는 Warning: Undefined array key 오류 수정 2021-08-23 07:24:24 +00:00
kagla bdd52dae6f 버전 5.4.15.1 수정 2021-08-19 11:29:47 +09:00
kagla ae515803f6 version.php 분리로 인해 ['path']가 선언되지 않아 설치가 되지 않던 오류 수정 2021-08-19 11:27:41 +09:00
kagla 5d31a5505d 버전 5.4.15 수정 2021-08-18 17:06:04 +09:00
kagla 99087027a2 config.php 에서 버전 관리 부분을 따로 떼어냄 2021-08-18 16:59:28 +09:00
kagla 6b5ca5c5e6 회원삭제시 빈값으로 수정되지 않던 필드 mb_addr3, mb_point, mb_profile 추가 (작은별님,210814) 2021-08-18 15:37:59 +09:00
kagla 0731b57c80 1:1문의에 제목, 내용, 글쓴이, 회원아이디 선택후 검색이 가능하도록 수정 (북마크스님,210812) 2021-08-13 02:02:21 +00:00
kagla 8d7bdb331d Merge branch 'qa' of github.com:gnuboard/gnuboard5 into qa 2021-08-13 00:26:54 +00:00
kaglaandGitHub 1accc143ec Merge pull request #85 from whitedot/qa
UI : 1:1문의 검색에서 검색 대상 지정 마크업 및 스타일링
2021-08-12 16:55:13 +09:00
whitedot 8e87434e99 UI : 1:1문의 검색에서 검색 대상 지정 마크업 및 스타일링 2021-08-12 16:52:29 +09:00
kagla b3e53e3c78 PHP8, Fatal error: Uncaught TypeError: count(): Argument #1 ($var) must be of type Countable|array, null given 및 Warning 오류 해결 (Jay-flow님,210806) 2021-08-12 04:50:03 +00:00
kagla 8e20e39e3f PHP8, 1:1문의 설정에서 DHTML 사용안함으로 사용시 Warning: Undefined variable $html_checked 나오는 오류 수정 (다온테마님,210811) 2021-08-12 01:27:33 +00:00
kagla c7de15f7f5 버전 5.4.14 수정 2021-08-10 11:28:17 +09:00
kagla 4595fefe7d 주석 오타 수정 (작은앙심님,210808) 2021-08-09 07:20:13 +00:00
kagla e3bfefab55 PHP8에서 Warning: Undefined variable $extensions 오류 나오지 않도록 수정 (다온테마님,210806) 2021-08-09 07:15:28 +00:00
kagla c024c7552b 게시글 입력시에도 $wr_1 ~ $wr_10 변수 사용시 오류 나오지 않도록 가변변수 생성 (다온테마님,210806) 2021-08-09 07:13:44 +00:00
kagla 8ed56ec293 네이버 소셜회원가입시 월/일 처리가 반대로 되는 현상 수정 (arrtres님,210727) 2021-07-28 11:19:45 +09:00
kagla ed3143b6fd 버전 5.4.13.1 수정중 2021-07-27 05:28:16 +00:00
kagla 1491ae6e17 잘못된 webp 검사 함수명 file_exists를 function_exists로 수정 2021-07-27 05:27:06 +00:00
EC2 Default User b29ced4553 버전 5.4.13 수정 2021-07-27 00:46:51 +00:00
EC2 Default User 77064a40c6 쇼핑몰을 사용하지 않을 경우 나오는 오류 수정 (열공중님,210723) 2021-07-26 03:17:22 +00:00
kagla 52ed0f3d64 움직이는 webp 이미지는 업로드 불가합니다. 문구를 삭제함 2021-07-24 06:18:56 +00:00
kagla d0e101b3e8 webp를 지원하는 서버에서만 이미지 업로드 확장자에 webp를 추가함 2021-07-24 06:18:20 +00:00
Cloud User 3f97138715 webp를 지원하지 않는 서버에서 경고 문구를 출력함 2021-07-24 06:16:22 +00:00
Cloud User d76b371a58 Merge branch '5.4.13' of github.com:gnuboard/gnuboard5 into 5.4.13 2021-07-21 04:54:28 +00:00
kagla 42bf3d6044 잘못된 주석 문구 수정 (해피정님,210720) 2021-07-20 14:49:01 +09:00
kagla 1d89af99b0 버전 5.4.12 수정 2021-07-20 01:23:06 +00:00
EC2 Default User 81635f7737 PHP 5 하위버전에서 상수 배열이 지원되지 않아 나오던 오류 수정 (한별아빠님,210719) 2021-07-20 01:20:35 +00:00
EC2 Default User e1e20f2dc2 skin 디렉토리가 없거나 경로가 잘못 된 경우 나오는 나오는 오류 수정 PHP Warning: array_merge(): Argument #2 is not an array (엑스엠엘님,210716) 2021-07-20 01:07:56 +00:00
whitedot c9fb4ff9d1 UI : 옵션 없는 상품에서 수량 변경할 때 UI 일관되게 표시되도록 수정 2021-07-07 16:46:06 +09:00
whitedot 6b52f0570d UI : 최신글 스킨 스타일시트에서 중복되는 속성값 제거 2021-07-07 16:34:10 +09:00
kit rio 74ecb1aa55 PHP 4지원 함수 삭제 2021-03-26 02:23:23 +09:00
kit rio fdc8faf6d0 Merge remote-tracking branch 'upstream/main' 2021-03-26 02:12:49 +09:00
thisgun c223847301 Merge branch 'master' of github.com:gnuboard/g5 2021-03-22 15:06:41 +09:00
thisgun 2ede89f338 Merge branch 'master' of github.com:gnuboard/g5 2021-03-16 15:02:05 +09:00
thisgun 12132598b4 Merge branch 'master' of github.com:gnuboard/g5 2021-02-05 17:17:51 +09:00
thisgun 1c3cf4771a Merge branch 'master' of github.com:gnuboard/g5 2021-02-05 14:08:27 +09:00
thisgun 8523bb5747 Merge branch 'master' of github.com:gnuboard/g5 2021-01-26 10:51:12 +09:00
thisgun cde27ea510 Merge branch 'master' of github.com:gnuboard/g5 2021-01-26 10:13:06 +09:00
thisgun 9a61ea2d59 Merge branch 'master' of github.com:gnuboard/g5 2021-01-19 14:20:06 +09:00
thisgun dd2834167a Merge branch 'master' of github.com:gnuboard/g5 2021-01-14 10:23:28 +09:00
thisgun aa86ac0c30 Merge branch 'master' of github.com:gnuboard/g5 2021-01-13 15:35:54 +09:00
thisgun ddd7090801 Merge branch 'master' of github.com:gnuboard/g5 2021-01-11 14:52:19 +09:00
thisgun aceb0a2751 Merge branch 'master' of github.com:gnuboard/g5 2021-01-09 23:28:56 +09:00
thisgun 5c13b8c200 Merge branch 'master' of github.com:gnuboard/g5 2021-01-09 17:23:26 +09:00
thisgun ab7ba78fd2 Merge branch 'master' of github.com:gnuboard/g5 2021-01-08 15:54:28 +09:00
thisgun 18bc64ab0a Merge branch 'master' of github.com:gnuboard/g5 2021-01-06 14:24:51 +09:00
thisgun 24268f70b8 Merge branch 'master' of github.com:gnuboard/g5 2021-01-06 10:43:21 +09:00
thisgun 3eb07bdfa0 Merge branch 'master' of github.com:gnuboard/g5 2021-01-05 20:34:02 +09:00
lupin_latte e6764f4a7c Merge branch 'master' of github.com:gnuboard/g5 2021-01-05 16:04:40 +09:00
thisgun 5d37a15fb6 Merge branch 'master' of github.com:gnuboard/g5 2021-01-04 20:16:57 +09:00
thisgun 681499f8dd Merge branch 'master' of github.com:gnuboard/g5 2021-01-04 20:01:06 +09:00
thisgun 51355dffc5 Merge branch 'master' of github.com:gnuboard/g5 2021-01-04 20:00:42 +09:00
thisgun 389267bb65 버전 5.4.4 수정 2021-01-04 20:00:42 +09:00
thisgun 239b5d7a2c 매우중요 필수패치!!! 다음 우편번호 서비스 가이드에 따른 타URL 파라미터 붙이는 코드 삭제 2021-01-04 20:00:23 +09:00
thisgun de9ba8db5b Merge branch 'master' of github.com:gnuboard/g5 2020-11-24 14:30:06 +09:00
jw2(kit rio)andGitHub ccd463170f 불필요한 PHP버전 확인 삭제
그누보드가 작동하는 최소 PHP 버전인 5.2.17 이하를  확인하는것을 삭제합니다.
2020-10-31 01:44:35 +09:00
thisgun e9439c87d1 Merge branch 'master' of github.com:gnuboard/g5 2020-10-28 15:18:28 +09:00
thisgun 1971be3186 Merge branch 'master' of github.com:gnuboard/g5 2020-10-07 10:52:40 +09:00
thisgun 5353f75284 Merge branch 'master' of github.com:gnuboard/g5 2020-08-13 11:11:16 +09:00
thisgun 84dd9f0766 Merge branch 'master' of github.com:gnuboard/g5 2020-06-11 12:24:58 +09:00
thisgun a16926a4de Merge branch 'master' of github.com:gnuboard/g5 2020-06-05 11:21:29 +09:00
thisgun c875121931 Merge branch 'master' of github.com:gnuboard/g5 2020-05-08 16:02:40 +09:00
thisgun 6cc2bfdd50 Merge branch 'master' of github.com:gnuboard/g5 2020-04-13 16:18:49 +09:00
thisgun ff4ac1d626 Merge branch 'master' of github.com:gnuboard/g5 2020-03-13 11:27:57 +09:00
thisgun fff7e074ff Merge branch 'master' of github.com:gnuboard/g5 2020-03-03 18:48:19 +09:00
thisgun 8dd2fe58e6 Merge branch 'master' of github.com:gnuboard/g5 2020-03-03 12:01:16 +09:00
thisgun 1600f63dee Merge branch 'master' of github.com:gnuboard/g5 2020-02-18 15:24:01 +09:00
thisgun da29b6d0bb Merge branch 'master' of github.com:gnuboard/g5 2020-02-07 18:19:36 +09:00
thisgun cc5eb6e520 Merge branch 'master' of github.com:gnuboard/g5 2020-02-04 11:24:30 +09:00
thisgun 726863de44 Merge branch 'master' of github.com:gnuboard/g5 2020-01-31 16:03:22 +09:00
thisgun f2a1af5f46 Merge branch 'master' of github.com:gnuboard/g5 2020-01-07 16:34:04 +09:00
thisgun 4b0969d244 Merge branch 'master' of github.com:gnuboard/g5 2019-12-27 16:05:56 +09:00
thisgun b5152b62e8 Merge branch 'master' of github.com:gnuboard/g5 2019-12-23 10:12:10 +09:00
thisgun 7ccf17b479 Merge branch 'master' of github.com:gnuboard/g5 2019-12-09 14:59:18 +09:00
thisgun 312fc5daf3 Merge branch 'master' of github.com:gnuboard/g5 2019-12-02 17:01:34 +09:00
thisgun e3ed8a1af3 Merge branch 'master' of github.com:gnuboard/g5 2019-12-02 11:11:03 +09:00
thisgun f230dc3522 Merge branch 'master' of github.com:gnuboard/g5 2019-10-31 12:18:19 +09:00
thisgun 58878593dc Merge branch 'master' of github.com:gnuboard/g5 2019-09-16 16:04:23 +09:00
thisgun 863f6011ac Merge branch 'master' of github.com:gnuboard/g5 2019-08-12 10:37:25 +09:00
thisgun cee88a0f6f Merge branch 'master' of github.com:gnuboard/g5 2019-07-15 18:40:40 +09:00
thisgun 27b1a5d8f8 Merge branch 'master' of github.com:gnuboard/g5 2019-06-18 17:57:28 +09:00
thisgun 7d494115b3 Merge branch 'master' of github.com:gnuboard/g5 2019-06-14 09:44:03 +09:00
thisgun 0954beced9 Merge branch 'master' of github.com:gnuboard/g5 2019-05-30 11:01:48 +09:00
thisgun 2534921446 Merge branch 'master' of github.com:gnuboard/g5 2019-05-29 14:41:19 +09:00
thisgun 831219e2c2 Merge branch 'master' of github.com:gnuboard/g5 2019-03-19 11:45:30 +09:00
thisgun ae729f1525 Merge branch 'master' of github.com:gnuboard/g5 2019-03-04 13:59:42 +09:00
thisgun 4d4064c40d Merge branch 'master' of github.com:gnuboard/g5 2019-02-14 10:32:18 +09:00
thisgun e8abeb47e8 Merge branch 'master' of github.com:gnuboard/g5 2019-01-28 11:18:46 +09:00
thisgun 5fdd38e1ce Merge branch 'master' of github.com:gnuboard/g5 2019-01-07 14:48:37 +09:00
thisgun 82cdd90edc Merge branch 'master' of github.com:gnuboard/g5 2018-12-28 11:11:07 +09:00
thisgun 54b1356ab1 Merge branch 'master' of github.com:gnuboard/g5 2018-12-18 12:29:17 +09:00
thisgun 7ae3d6b00d Merge branch 'master' of github.com:gnuboard/g5 2018-12-17 18:49:03 +09:00
thisgun da963964a9 Merge branch 'master' of github.com:gnuboard/g5 2018-12-11 17:22:45 +09:00
thisgun 7e7d73d394 Merge branch 'master' of github.com:gnuboard/g5 2018-11-26 15:24:07 +09:00
thisgun 2549172969 Merge branch 'master' of github.com:gnuboard/g5 2018-11-21 15:59:33 +09:00
thisgun 3fb9c2c15f Merge branch 'master' of github.com:gnuboard/g5 2018-10-30 16:03:27 +09:00
thisgun 0329cc9f9c Merge branch 'master' of github.com:gnuboard/g5 2018-10-26 11:55:51 +09:00
thisgun a77a6ffafa Merge branch 'master' of github.com:gnuboard/g5 2018-10-18 18:45:11 +09:00
thisgun 15b2e73e73 Merge branch 'master' of github.com:gnuboard/g5 2018-10-17 19:41:16 +09:00
thisgun 0e00f05014 Merge branch 'master' of github.com:gnuboard/g5 2018-10-17 18:42:24 +09:00
thisgun b2858b65ee Merge branch 'master' of github.com:gnuboard/g5 2018-10-08 12:00:38 +09:00
thisgun a82f61ae2a Merge branch 'master' of github.com:gnuboard/g5 2018-09-17 10:34:00 +09:00
thisgun 5be739934b Merge branch 'master' of github.com:gnuboard/g5 2018-08-24 09:35:49 +09:00
thisgun 02d816154b Merge branch 'master' of github.com:gnuboard/g5 2018-07-03 16:02:20 +09:00
thisgun 0bae2cf182 Merge branch 'master' of github.com:gnuboard/g5 2018-06-05 11:42:10 +09:00
thisgun a196c91ed5 Merge branch 'master' of github.com:gnuboard/g5 2018-06-05 09:39:56 +09:00
thisgun c24f37421b Merge branch 'master' of github.com:gnuboard/g5 2018-05-23 14:09:13 +09:00
thisgun 74a8e668e5 Merge branch 'master' of github.com:gnuboard/g5 2018-04-23 10:45:56 +09:00
thisgun f6a8b1bacf Merge branch 'master' of github.com:gnuboard/g5 2018-04-20 16:01:37 +09:00
thisgun 8958f138f4 Merge branch 'master' of github.com:gnuboard/g5 2018-04-20 14:27:21 +09:00
thisgun af8494e18f Merge branch 'master' of github.com:gnuboard/g5 2018-04-04 12:13:10 +09:00
thisgun b0fd1e7486 Merge branch 'master' of github.com:gnuboard/g5 2018-03-30 19:15:40 +09:00
thisgun bf8efdf2ab Merge branch 'master' of github.com:gnuboard/g5 2018-03-26 09:52:13 +09:00
thisgun 632ca4c79a Merge branch 'master' of github.com:gnuboard/g5 2018-03-20 15:58:37 +09:00
thisgun ea9825be61 Merge branch 'master' of github.com:gnuboard/g5 2018-03-19 14:31:06 +09:00
thisgun fbe2021a38 Merge branch 'master' of github.com:gnuboard/g5 2017-12-27 18:16:32 +09:00
thisgun 5ba5836ecb Merge branch 'master' of github.com:gnuboard/g5 2017-12-27 09:59:37 +09:00
thisgun a90a38f096 Merge branch 'master' of github.com:gnuboard/g5 2017-12-20 12:05:17 +09:00
thisgun bc68c4bc70 Merge branch 'master' of github.com:gnuboard/g5 2017-12-07 11:18:09 +09:00
thisgun 7d8e2e4fdd Merge branch 'master' of github.com:gnuboard/g5 2017-11-07 10:11:55 +09:00
thisgun f9dd7644cc Merge branch 'master' of github.com:gnuboard/g5 2017-10-11 09:06:51 +09:00
thisgun 28d079e83f 5.2.9.3 버전 수정 2017-09-11 11:00:14 +09:00
thisgun 54401165e8 5.2.9.2 버전 정보 수정 2017-08-16 10:52:49 +09:00
thisgun b99efb8fc8 1:1 문의 및 내용관리 상단 하단 경로 수정 2017-08-16 10:43:24 +09:00
thisgun ad102421cb Stored XSS 취약점 수정 (17-557) 2017-08-16 10:43:21 +09:00
thisgun 9be00683d9 433 포트번호 처리 수정 2017-08-16 10:43:18 +09:00
thisgun e76f36a1be 최고관리자 정보수정 문제 ( 17-00465 취약점 관련 ) 2017-08-16 10:43:15 +09:00
thisgun 70b62a6c6a 패스워드 찾기 https url 처리 2017-08-16 10:43:12 +09:00
thisgun 61b3fe4ebd 쪽지 보낼때 차감 포인트도 표시하기 2017-08-16 10:43:08 +09:00
thisgun 30a93dbef7 아이코드 충전하기 버튼 링크 태그 수정 2017-08-16 10:43:05 +09:00
thisgun b6956bd6fd 모바일 댓글 https 미처리 수정 2017-08-16 10:43:03 +09:00
thisgun 7a4b7e23c5 include path 체크함수 수정 2017-08-16 10:42:47 +09:00
thisgun b34a7610f5 인스톨시 필터링 단어 수정 2017-08-16 10:42:40 +09:00
thisgun 0d19b01229 5.2.9 버전 변경 2017-07-03 19:58:40 +09:00
thisgun 2b2d558c87 게시판 본문의 url 자동 링크 소스 수정 2017-07-03 19:41:44 +09:00
thisgun 94f25f73fa 그누보드 글 수정 XSS 취약점 수정 ( 17-454 ) 2017-07-03 19:41:38 +09:00
thisgun 5bd16c0e77 kcaptcha https 적용이 안되는 오류 수정 2017-07-03 19:41:33 +09:00
thisgun 7bb40dd882 코멘트 폼 및 게시판 패스워드 action url에 https 처리 2017-07-03 19:41:26 +09:00
thisgun bb99c050b6 게시판 글쓰기시 버튼도 토큰 적용되도록 수정 2017-07-03 19:41:20 +09:00
thisgun 31cdf10011 스마트에디터 2.9.0 버전으로 수정 2017-07-03 19:41:13 +09:00
thisgun 02c29c137c cheditor js 업로드 수정 2017-07-03 19:41:09 +09:00
thisgun e9afe3fdae 1:1 문의 페이징 오류 수정 2017-07-03 19:41:05 +09:00
thisgun ce9517885b 그누보드 AND 검색을 이용한 취약점 수정 (17-455) 2017-07-03 19:40:57 +09:00
thisgun 6a41d655de 게시판에서 특수문자 일부 입력시 캐쉬 파일 생성 오류 수정 2017-07-03 19:40:50 +09:00
thisgun c2a4a39ea0 에디터 이미지 업로드 부분 정규식 수정 2017-06-14 11:22:05 +09:00
thisgun b8759e4acd 5.2.8 버젼변경 2017-06-14 10:35:04 +09:00
thisgun e6a3df6f08 그누보드 파일 삭제 취약점 17-282 수정 2017-06-14 10:32:43 +09:00
thisgun 617dfbf0e2 그누보드 원격 취약점 17-259 수정 2017-06-14 10:32:35 +09:00
thisgun e4c9bf5ba4 g5_path 함수 수정 2017-06-14 10:32:29 +09:00
thisgun 910091b6c6 모바일 크롬 브라우저에서 캡챠 조회수 버그 수정 2017-06-14 10:32:23 +09:00
thisgun 92b8ce3a89 게시판 검색시 필드 소문자로 변경 2017-06-14 10:32:13 +09:00
thisgun 8a276fc073 install 파일에 utf-8 헤더 추가 2017-06-14 10:32:08 +09:00
thisgun baa2e890ba 기타 오류 수정 2017-06-14 10:32:04 +09:00
thisgun a9f4aee93f 메뉴 추가 대상에서 게시판일 경우 게시판 그룹 표시하기 #73 2017-06-14 10:31:59 +09:00
thisgun 144926774d 이메일 복화화 문자열이 깨지는 현상 수정 2017-06-14 10:31:53 +09:00
thisgun 435da08a02 5.2.7 버전변경 2017-03-20 17:45:21 +09:00
thisgun 945c060b67 썸네일 파일 수정 2017-03-20 17:45:17 +09:00
thisgun 83fd4bf68a cheditor 소스 수정 2017-03-20 17:45:09 +09:00
thisgun f11c4531e9 원격코드 실행 취약점(17-00160) 수정 2017-03-20 17:45:05 +09:00
thisgun f36c24e5d0 오타 수정 (왕대인님 제보) 2017-03-20 17:45:00 +09:00
thisgun 23a91b346d LFI to RCE 취약점 수정 2017-03-20 17:44:56 +09:00
thisgun 8eb465d26f 5.2.6 버전변경 2017-01-18 19:59:42 +09:00
thisgun 6ff06d4609 글쓰기시 page 중복 소스 삭제 2017-01-18 19:58:35 +09:00
thisgun c817b1edb7 PHPMailer 5.2.22 버전 적용 2017-01-18 19:58:31 +09:00
thisgun f7c6a52f6d cheditor5 추가 2017-01-18 19:58:20 +09:00
thisgun 3e343bdf66 5.2.5 버전변경 2017-01-09 14:33:20 +09:00
thisgun e131563c8f XSS 취약점(16-1008) 수정 2017-01-09 14:30:47 +09:00
thisgun 0094cc9afe 스마트에디터 업로드 방식 수정 2017-01-09 14:30:39 +09:00
thisgun 5fde923aa0 PHPMailer 5.2.19 버전 적용 2017-01-09 14:30:33 +09:00
chicpro 1e3a4f2657 KCP 본인확인 모바일 관련 수정 2016-12-21 09:56:32 +09:00
chicpro 0693fde962 5.2.4 버전변경 2016-11-22 11:34:16 +09:00
chicpro 7fb5f92200 <?php 수정 2016-11-22 10:47:31 +09:00
chicpro 50c8207fed 컬럼 정렬 함수에 sca 변수 추가 (sir ko님 제안) 2016-10-20 09:30:42 +09:00
chicpro 6dbfa73461 5.2.3 버전변경 2016-10-19 10:26:05 +09:00
chicpro 76ecc6efe8 XSS 취약점(16-781) 수정 2016-10-17 16:57:04 +09:00
chicpro f4b0737178 개인정보처리방침 명칭 변경 2016-10-17 14:48:00 +09:00
chicpro e99c7a81db 게시글 CSRF 취약점(16-749 16-750) 수정 2016-10-17 14:47:45 +09:00
chicpro ce0a6dc3af js css 버전 상수 추가 2016-10-17 14:47:30 +09:00
chicpro f3e428ea1e 모바이 FAQ 하단 내용 출력 오류 수정 2016-09-21 11:41:04 +09:00
chicpro 9b422b38c5 5.2.2 버전변경 2016-09-20 09:59:04 +09:00
chicpro f6056b2d37 오픈 리다이렉트 취약점(16-603) 수정 2016-09-06 14:47:35 +09:00
chicpro a560fc353c htmlpurifier 4.8 업데이트 2016-08-29 13:48:02 +09:00
chicpro e2c67e854f 5.2.1 버전변경 2016-08-22 09:56:47 +09:00
thisgunandchicpro 3e7617e825 스마트에디터 2.8.2.3 보안패치 #63 2016-08-17 14:37:23 +09:00
chicpro 4515f11169 토큰 초기화 코드 추가 2016-08-10 10:02:04 +09:00
chicpro ec32f64bc4 댓글 수정 CSRF 취약점 수정 2016-08-10 10:01:49 +09:00
chicpro 15bd8b9632 파일경로 필터링 코드 추가 2016-08-10 10:01:35 +09:00
chicpro ef013e0827 wr_id_list 필터링 코드 추가 2016-08-10 09:56:03 +09:00
chicpro b3773217e9 5.2.0 버전변경 2016-07-25 10:44:58 +09:00
chicpro 70f6d92e87 XSS 취약점 수정 16-480 2016-07-21 10:25:46 +09:00
chicpro 042695af55 5.1.19 버전변경 2016-07-05 11:01:48 +09:00
chicpro 85f9523b30 댓글 삭제 토큰 코드 수정 2016-06-28 13:33:28 +09:00
chicpro 8c1d6266af 게시글 댓글 삭제 때 토큰 체크 추가 2016-06-24 17:22:29 +09:00
chicpro 30009dba6f 커맨드 인젝션 취약점(16-418 419) 수정 2016-06-24 17:22:14 +09:00
chicpro 24e7e8823e 가입축하 메일의 메일인증코드 수정 2016-05-24 17:46:02 +09:00
chicpro 42fb4b71a6 5.1.18 버전변경 2016-05-17 10:05:35 +09:00
chicpro f0134b610b 누락된 필드 추가 2016-05-17 10:05:06 +09:00
chicpro c2cf34392a 1:1문의 등록 오류 수정 2016-05-17 10:04:53 +09:00
chicpro 20dc859436 5.1.17 버전변경 2016-05-16 15:21:55 +09:00
chicpro f5ec4d60c0 기본환경설정 NHN KCP 사명변경 2016-05-13 12:03:02 +09:00
chicpro de00b4e9d3 1:1문의 파일업로드 분류 체크 추가 2016-05-04 13:36:31 +09:00
chicpro 8c67945c64 파일 업로드 개수 코드 수정 2016-05-04 13:36:20 +09:00
chicpro e5889df761 게시글 카테고리 체크 수정 2016-05-03 17:33:53 +09:00
chicpro 624e3d74a6 파일 업로드 개수 체크 추가 2016-05-03 17:33:37 +09:00
chicpro 30815f71e0 폼메일에서의 이메일주소 노출 수정 2016-05-03 14:16:38 +09:00
chicpro 949a73b468 1:1문의 이메일 체크 수정 2016-05-03 14:16:23 +09:00
chicpro 24d57cdd4b 스크랩 게시글 체크 추가 2016-05-03 14:16:09 +09:00
chicpro 191f3d2f97 1:1문의 삭제 오류 수정 2016-05-03 14:15:55 +09:00
chicpro 4973714e2f 이메일인증 프로세스 개선 2016-05-03 14:15:40 +09:00
chicpro 70bfeefb3b 댓글 등록 오류 수정 2016-04-28 09:49:14 +09:00
chicpro e8b83f3a33 비밀글 등록 버그 수정 2016-04-27 10:44:37 +09:00
chicpro c6bdc172ee 5.1.16 버전변경 2016-04-20 11:08:39 +09:00
sora90224andchicpro c3cf74f0c5 관리자 부가서비스 kcp 로고 변경 2016-04-20 11:07:58 +09:00
chicpro 52db203ecd 필터링 특수문자 추가 2016-04-20 11:07:23 +09:00
chicpro 6e05353f31 sst 변수 필터링 특수문자 추가 2016-04-20 11:07:12 +09:00
chicpro 7f6a9a090a 5.1.15 버전변경 2016-03-21 09:50:06 +09:00
sora90224andchicpro 1825830c3d 모바일 쪽지함 이름겹침수정 2016-03-09 15:03:14 +09:00
chicpro 3047e09f88 5.1.14 버전변경 2016-03-07 10:41:33 +09:00
chicpro 990af076af 커맨드 인젝션 취약점(16-164, 16-165) 수정 2016-02-29 15:14:15 +09:00
chicpro b1f0342921 5.1.13 버전변경 2016-02-22 09:48:17 +09:00
chicpro 63f9e4c8df SIR 도메인 변경 2016-02-19 11:22:17 +09:00
chicpro 6b43e67c40 비밀 댓글 노출 취약점(16-067) 수정 2016-02-11 11:01:04 +09:00
chicpro 9a870506ab Reflected XSS 취약점(16-036) 수정 2016-02-11 11:00:30 +09:00
chicpro 008ae978dd XSS 취약점(16-060) 수정 2016-02-11 10:58:45 +09:00
chicpro 20b1d8c7e5 XSS 취약점(16-059) 수정 2016-02-11 10:58:31 +09:00
thisgunandchicpro 1e011ba56d 스마트 에디터 2.8.2 에 추가된 파일 적용 2016-02-04 17:31:09 +09:00
thisgunandchicpro a73e48c3e2 스마트에디터 2.8.2 적용 및 에디터 업로드 보안 수정 2016-02-04 17:30:53 +09:00
chicpro e9fd9f03fd g5_admin_url 코드 수정 2016-02-03 10:42:50 +09:00
chicpro 4913da0a1d g5_admin_url 변수 설정 코드 변경 2016-02-01 11:56:15 +09:00
chicpro 18ef4b0767 메일인증 기능 수정 2016-02-01 11:55:57 +09:00
chicpro d0e368fe2a sca 필터링 코드 수정 2016-01-21 16:00:54 +09:00
chicpro 5185f0c12a 5.1.12 버전변경 2016-01-20 10:03:25 +09:00
chicpro f5f4925d4e sca 필터링 코드 추가 2016-01-12 11:08:58 +09:00
chicpro bd3fd20630 게시글 등록 메일 이미지 출력 오류 수정 2016-01-07 10:55:25 +09:00
chicpro 6797c85480 5.1.11 버전변경 2016-01-05 09:44:47 +09:00
chicpro 2c9ff2bb52 모바일 그룹 정렬 필드 수정 2015-12-23 16:43:20 +09:00
chicpro cc2b5c246d PHPMailer 5.2.14 버전 적용 2015-12-22 15:27:18 +09:00
chicpro c337bfdf88 5.1.10 버전변경 2015-12-21 11:00:46 +09:00
chicpro cb5603008a 분류 사용할 때 분류선택 여부 체크 추가 2015-12-14 11:08:39 +09:00
chicpro 9d147b5e6c 태그 오류 수정 2015-12-10 16:33:15 +09:00
chicpro aabc82ee6c 5.1.9 버전변경 2015-12-07 11:24:10 +09:00
chicpro 40aff270cd 캡챠 폰트 변경 2015-12-07 11:22:39 +09:00
thisgunandchicpro 851a21a3c1 엑셀 라이브러리 php7 버젼에서 난 오류 수정 2015-11-30 17:33:38 +09:00
chicpro d5b7dd165d new.php XSS 취약점 수정 2015-11-27 14:25:01 +09:00
chicpro beb7a86f2a 토큰 오류 알림 후 이동 url 지정 2015-11-27 14:24:48 +09:00
chicpro a6327afac4 5.1.8 버전변경 2015-11-25 09:55:20 +09:00
chicpro 30305d78dc 1:1문의 SMS 발신번호 사전등록제 관련 코드 수정 2015-11-25 09:48:17 +09:00
chicpro bb1fd4d3ab 관리자 CSRF 취약점 수정 2015-11-24 16:12:22 +09:00
chicpro a75e00f9e0 모바일 게시판 제목 적용되도록 수정 2015-11-19 15:50:27 +09:00
chicpro ad67fca323 파일면 변경으로인한 중복 파일 삭제 2015-11-17 16:39:16 +09:00
chicpro 614dce643c 캡챠 오류 수정 및 파일명 변경 2015-11-17 16:37:30 +09:00
chicpro c0cd45cc18 캡챠이미지 경로 오류수정 2015-11-17 09:07:12 +09:00
chicpro f3e7dbbb43 5.1.7 버전 변경 2015-11-16 16:45:37 +09:00
chicpro 5247359e39 오타 수정 2015-11-16 16:39:09 +09:00
chicpro 4ed4938cf1 캡챠 및 회원가입 값체크 개선 2015-11-16 16:36:04 +09:00
chicpro 158d9040d2 접속자 Browscap 적용 기능 개선 2015-11-13 11:23:14 +09:00
sora90224andchicpro aebfc70b10 불필요한 소스 삭제 2015-11-12 09:38:41 +09:00
chicpro 69ca119b10 업로드 파일명 코드 변경 2015-11-11 11:41:46 +09:00
chicpro be15f890c9 5.1.6 버전변경 2015-11-09 09:31:58 +09:00
chicproandchicpro bc71241846 php7 대응 코드 수정 2015-11-04 17:11:52 +09:00
chicpro 4bcce2696c sql_set_charset 함수 코드 수정 2015-11-04 10:20:42 +09:00
chicpro 7083bb0899 관리자 접속자 기능 개선 2015-11-03 15:35:31 +09:00
chicpro c7b1d0ee96 5.1.5 버전 변경 2015-11-02 09:54:40 +09:00
chicpro ba52e4ab6f 회원가입 개인정보취급방침 안내 수정 2015-10-29 09:59:29 +09:00
chicpro e47156ede6 게시판 복사 중 따옴표로 인한 오류 수정 2015-10-28 14:17:07 +09:00
chicpro 36ef8e6447 5.1.4 버전변경 2015-10-26 10:08:02 +09:00
chicpro eb154efa24 누락된 닫음태그 추가 2015-10-20 12:02:20 +09:00
chicpro 9bf15fdf32 htmlpurifier 4.7 버전 적용 2015-10-20 11:28:40 +09:00
chicpro 353a0d9409 XSS취약점관련 object 태그 허용설정 변경 2015-10-20 11:28:26 +09:00
chicpro 0535b6d26a post 값 필터링 코드 위치 변경 2015-10-20 11:26:30 +09:00
chicpro 1fe4684537 MySQLi 지원 추가 및 SMS5 수정 2015-10-16 10:12:06 +09:00
chicpro 0803de998b 반응형 대비 캡챠 코드 수정 2015-10-06 09:49:15 +09:00
chicpro 273983c87c 따옴표 관련 오류 수정 2015-10-02 17:57:46 +09:00
chicpro 94cc7639a9 XSS 취약점 수정 및 LMS 모듈 추가 2015-10-01 13:46:46 +09:00
chicpro 84009dc16c 관리자 글현황 추가 및 기타 오류 수정 2015-08-28 11:42:25 +09:00
chicpro 82c12f6d98 투표 결과 테마스킨 적용 오류 수정 2015-08-04 09:05:41 +09:00
chicpro 6beff3a333 그누보드 5.1.0 테마 지원버전 2015-08-03 15:44:15 +09:00
chicpro d49200c99e XSS 취약점 및 기타 오류 수정 2015-07-27 14:08:23 +09:00
sungkyuchunandchicpro faed6ac09a empty_mb_name checks mb_id, not mb_name
empty_mb_name is a function checking name from user input form. But it
was not checked by empty_mb_name function. So I fix it.
2015-07-21 09:48:45 +09:00
chicpro 9256a5618b 버전변경 2015-07-20 11:52:21 +09:00
chicpro a52858fc6d XSS 취약점, 새 우편번호, 기타 오류 수정 2015-07-20 11:40:09 +09:00
iz4blueandchicpro 2ccc407397 이미지 width 계산 이후 빠진 attributes 추가 2015-07-14 14:10:00 +09:00
chicpro d5bd57cdfa 그누보드 5.0.40 수정내역 적용 및 XSS 취약점 수정 2015-07-13 13:43:46 +09:00
chicpro 3bbbe96319 XSS 및 Blind SQL Injection 취약점 수정 2015-07-07 13:50:38 +09:00
chicpro 78169b372c Merge branch 'merge-patch' 2015-07-03 17:08:55 +09:00
chicpro a79a926221 Merge https://github.com/iz4blue/gnuboard5 into merge-patch 2015-07-03 17:08:21 +09:00
chicpro f72ea8774e Merge branch 'master' into merge-patch 2015-07-03 17:05:45 +09:00
iz4admin 3c9b72d17a PHP short_open_tag=0 에러 방지 2015-07-03 16:53:04 +09:00
chicpro 8821583e8f 그누보드 5.0.38 수정내역 적용 및 CSRF 취약점 수정 2015-06-29 10:36:44 +09:00
chicpro 6e90622328 그누보드 5.0.37 수정내역 적용 및 XSS 취약점 수정 2015-06-23 11:12:23 +09:00
chicpro d5aca5ab93 그누보드 5.0.36 수정 내역 및 XSS 취약점 수정 2015-06-11 09:54:48 +09:00
chicpro 7110ccc12f 그누보드 5.0.35 수정내역 적용 2015-06-01 09:38:12 +09:00
chicpro 330e656544 그누보드5.0.34 수정내역 적용 2015-05-19 13:59:00 +09:00
chicpro 18fc8ec6d1 오타 및 회원가입폼 스타일 수정 2015-05-14 09:14:37 +09:00
chicpro 01a31bb18f Magic Hash 관련 비밀번호 체크 코드 수정 2015-05-13 17:10:08 +09:00
chicpro 2705b9312c 그누보드5.0.33 수정내역 적용 2015-05-13 11:57:04 +09:00
chicpro 9fd14cfc17 그누보드 5.0.32 수정내역 적용 2015-04-09 09:16:36 +09:00
chicpro a6a2183c7d 그누보드 5.0.31 수정내역 적용 2015-03-10 13:47:21 +09:00
Mabin 4b9369599c RSS 헤더 오류 수정 (phpxml -> xml) 2015-03-04 16:05:18 +09:00
chicpro b477c2e720 XSS 취약점 패치 및 5.0.30버전 수정내역 적용 2015-02-09 09:57:32 +09:00
chicpro 7ef2029a31 그누보드 5.0.29 수정내역 적용 2015-02-02 13:35:15 +09:00
chicpro 1cd8d590b2 mb_tel 필드를 이용한 xss 취약점 수정 2015-01-14 09:13:22 +09:00
chicpro 82a55c96a5 관리자 부가서비스 페이지 추가 2015-01-12 15:00:04 +09:00
chicpro 489c859d3e 그누보드 5.0.26 수정내역 적용 2015-01-05 10:18:00 +09:00
chicpro d5db75a4c9 입력금지 메일 도메인 체크 코드 수정 2014-12-18 10:11:16 +09:00
chicpro db2ef39126 사용하지 않는 파일 삭제 2014-12-17 10:15:35 +09:00
chicpro 87adbf0f8d 그누보드 5.0.25 보안패치 및 수정내역 적용 2014-12-17 10:14:29 +09:00
chicpro 244b8ae819 보안패치 및 그누보드 5.0.24 수정내역 적용 2014-12-08 11:23:01 +09:00
chicpro 7ea9d2e1d2 그누보드 5.0.23 수정 내역 적용 2014-12-02 10:16:35 +09:00
chicpro 7dc293a147 그누보드 5.0.22 보안패치 적용 2014-11-07 09:26:16 +09:00
chicpro 097903d0ce 그누보드 5.0.21 보안패치 및 기타 오류 수정 2014-10-28 13:17:24 +09:00
chicpro 37b0fa5788 SQL Injection 및 관리자가 게시글 수정때 정보 반영되도록 수정 2014-10-24 11:02:39 +09:00
chicpro ad78efcdaa 회원 홈페이지를 이용한 SQL Injection 오류 수정 2014-10-23 09:25:33 +09:00
chicpro 352deb6133 보안패치 및 그누보드 5.0.20 수정사항 적용 2014-10-22 13:16:44 +09:00
chicpro 1355c7ef57 그누보드 5.0.19 수정사항 적용 2014-10-13 15:13:08 +09:00
chicpro 3fa9aec9f2 그누보드 5.0.18 수정사항 적용 2014-09-29 15:56:30 +09:00
chicpro 4c083b6471 기능개선 및 라이센스 기타오류 수정 2014-09-16 10:33:19 +09:00
chicpro 916cd86330 다음주소 API 기본코드로 변경 및 불필요한 파일 삭제 2014-08-22 15:21:23 +09:00
chicpro 5a37e8243d 다음주소API 관련 스크립트 코드 및 기타 코드 수정 2014-08-20 16:55:18 +09:00
chicpro e891791f86 불필요한 파일 삭제 2014-08-19 14:55:42 +09:00
chicpro 59468d1312 다음 주소 API 적용 및 기타 수정 2014-08-19 14:52:47 +09:00
chicpro 43fae4ed50 불필요한 파일 삭제 2014-08-19 14:47:55 +09:00
chicpro fdc93c1c2d 5.0.13 버전 패치 적용 2014-08-11 15:01:27 +09:00
chicpro 79d7a690f4 XSS 및 SQL Injection 보안 취약점 수정 2014-07-31 17:01:06 +09:00
chicpro 0742c5f81b 댓글 wr_name 이용한 XSS 보안 취약점 수정 2014-07-30 18:05:52 +09:00
chicpro d5e6a07dda xss 대응 코드 추가 2014-07-29 16:33:19 +09:00
chicpro e84a1c8c98 그누보드 5.0.9 패치 적용 2014-07-28 11:41:12 +09:00
chicpro 2579323ddf sql injection 보안패치 및 스마트에디터2 추가 2014-07-18 17:10:25 +09:00
chicpro 2658dde159 카카오톡 링크기능 추가 및 기타 버그 수정 2014-07-15 16:59:54 +09:00
chicpro d9b8d31225 gitignore 충돌수정 2014-07-09 10:02:56 +09:00
chicpro 4d8500be02 네이버 신디케이션 적용 및 기타 오류 수정 2014-07-09 10:01:21 +09:00
chicpro 288da7f9e1 전역배열변수 보안 오류 수정 2014-07-01 11:08:19 +09:00
chicpro 41aac91146 보고된 버그 수정 2014-06-27 10:12:06 +09:00
chicpro a949c32b4c 기능개선 및 오류 수정 2014-06-20 13:37:58 +09:00
chicpro dc06aed164 FAQ 검색기능 수정 및 이전 프로그램 오류 수정 2014-06-16 10:24:15 +09:00
chicpro 6518b22854 1:1문의 XSS 취약점 수정 2014-06-11 15:30:55 +09:00
chicpro c8a69b054e sns 사용 때 게시글 보기 로딩 속도 개선 2014-06-10 16:10:17 +09:00
chicpro cd50ef5d48 Subtree Merging 설정 2014-06-09 14:57:31 +09:00
chicpro 7983affa68 그누보드5 정식버전 2014-06-09 14:48:44 +09:00
chicpro 0243dabe20 first commit 2014-06-09 14:00:04 +09:00
918 changed files with 86914 additions and 65982 deletions
+4
View File
@@ -1,2 +1,6 @@
.gitattributes export-ignore
.gitignore export-ignore
*.php whitespace=blank-at-eol,blank-at-eof,space-before-tab,cr-at-eol
/tests export-ignore
/bin export-ignore
+14
View File
@@ -2,6 +2,8 @@
/.htaccess
data/
test/
/tests/
/bin/
sirgle/
test.php
*.key
@@ -13,7 +15,19 @@ cheditor5.*/
log/
g5_tree/
.vscode/
.claude/
.cursor/
.windsurf/
.idea/
.playwright-mcp
.mcp.json
.agents
.DS_Store
*.swp
*.swo
CLAUDE.local.md
naver*.html
initests01/
SIRsoft000/
config.php
pma/
+50
View File
@@ -0,0 +1,50 @@
# 저장소 작업 지침
## 적용 범위
이 문서는 저장소 루트와 모든 하위 디렉터리에 적용한다.
## 문서 작성 언어
- README, 보안 정책, 설치 안내, 개발 가이드 등 저장소 문서는 원칙적으로 한국어로 작성한다.
- 파일명, 코드 식별자, 명령어, API 명칭, 설정값과 외부 서비스의 고유 명칭은 원문을 유지한다.
- 영문 문서나 번역본이 별도로 필요한 경우에는 해당 작업에서 명시적으로 요청된 범위에 한해 추가한다.
## 커밋 메시지
- 커밋 메시지는 한국어로 작성한다.
- 제목은 `<접두어>: <변경 내용>` 형식을 사용한다.
- 접두어는 아래 권장 목록에서 변경 목적에 가장 가까운 항목을 선택한다.
- 변경 대상을 포함해 무엇을 왜 변경했는지 알 수 있도록 구체적으로 작성한다.
- `수정`, `업데이트`, `작업`처럼 변경 내용을 식별하기 어려운 표현만 사용하지 않는다.
- 하나의 커밋에는 가능한 한 하나의 목적에 해당하는 변경만 포함한다.
- 제목만으로 설명이 부족하면 본문에 변경 이유, 영향 범위와 검증 방법을 추가한다.
- 관련 이슈가 있으면 커밋 본문이나 꼬리말에 이슈 번호를 기록한다.
### 권장 접두어
- `feat`: 새로운 기능 추가
- `fix`: 버그 또는 잘못된 동작 수정
- `security`: 보안 취약점 수정이나 보안 강화
- `docs`: 문서 추가 또는 변경
- `refactor`: 동작 변경 없는 코드 구조 개선
- `perf`: 성능 개선
- `test`: 테스트 추가 또는 변경
- `build`: 빌드 시스템이나 의존성 변경
- `ci`: CI/CD 설정이나 자동화 변경
- `chore`: 기능과 직접 관련 없는 유지보수 작업
- `revert`: 이전 변경 되돌리기
### 보안 이슈 식별자
- KVE, CVE 등 식별자가 부여된 보안 이슈를 조치하는 커밋은 제목에 관련 식별자를 반드시 병기한다.
- 식별자는 `security:` 접두어 바로 뒤에 원문 그대로 작성한다.
- 하나의 커밋이 여러 보안 이슈를 함께 조치하면 관련 식별자를 모두 병기한다.
- 예: `security: KVE-2026-1909 모바일 KCP Windows 명령 인자 주입 차단`
### 작성 예시
- `docs: Git과 압축파일 설치 절차를 구분해 README에 안내`
- `fix: 품목 일부 취소 시 PG 취소금액 불일치 수정`
- `security: KVE-2026-1899 상품 정렬값 화이트리스트 검증으로 SQL 삽입 차단`
- `refactor: 객체 캐시의 유형별 저장 키 생성 로직 분리`
+88
View File
@@ -0,0 +1,88 @@
# 그누보드5
그누보드5는 PHP와 MySQL 또는 MariaDB 기반의 오픈소스 CMS입니다. 게시판과 회원 관리 기능을 제공하며 쇼핑몰 솔루션 영카트를 포함합니다.
## 버전 확인
현재 소스 코드의 버전은 [`version.php`](version.php)에서 확인할 수 있습니다.
## 다운로드 및 설치
### 설치 환경
#### 기본 요구사항
- PHP 5.2.17 이상
- 최소 요구 버전은 PHP 5.2.17이며 PHP 7.2 이상을 권장합니다.
- MySQL 5.0 이상 또는 MySQL 5.0 이상의 기능을 지원하는 MariaDB
- Linux 호환 운영체제
#### 필수 라이브러리
- GD Library 2.0 이상
- iconv
#### 추가로 필요한 모듈 및 프로그램
- 글을 SNS로 복사하는 기능 사용 시
- cURL
- JSON
- 영카트5 모바일 결제 사용 시
- SOAP
- OpenSSL
> SIR에서 직접 제작한 그누보드5 및 호환 프로그램은 Linux에서만 개발하고 테스트했습니다. 다른 운영체제에서의 정상 동작은 보장하지 않습니다.
설치 환경에 관한 자세한 내용은 [그누보드5 공식 매뉴얼](https://sir.kr/manuals/g5/1)을 확인하십시오.
### Git을 이용하는 방법
Git을 사용할 수 있는 서버에서는 [GitHub 저장소](https://github.com/gnuboard/gnuboard5)를 복제하여 설치할 수 있습니다.
```bash
git clone https://github.com/gnuboard/gnuboard5.git
cd gnuboard5
```
복제한 `gnuboard5` 디렉터리를 웹 서버의 서비스 경로로 사용하거나, 서비스 경로 안에 소스 전체를 배치합니다. 이후 아래의 공통 설치 절차를 진행합니다.
### 압축파일을 이용하는 방법
1. 다음 중 한 곳에서 설치할 버전의 압축파일을 내려받습니다.
- [GitHub Releases](https://github.com/gnuboard/gnuboard5/releases)에서 원하는 버전을 선택하고 `Source code (zip)`을 내려받습니다. `*.patch.zip` 파일은 기존 설치본을 업데이트하기 위한 패치이므로 신규 설치에는 사용하지 않습니다.
- [SIR 그누보드5 다운로드](https://sir.kr/boards/g5_pds)에서 원하는 버전의 배포본을 내려받습니다.
2. 내려받은 압축파일을 풉니다.
3. 압축을 푼 디렉터리의 파일과 하위 디렉터리를 FTP, SFTP 등의 방법으로 웹 서버의 서비스 경로에 업로드합니다.
4. 업로드가 끝나면 아래의 공통 설치 절차를 진행합니다.
### 공통 설치 절차
1. 브라우저에서 소스를 배치한 주소로 접속하여 설치 화면을 엽니다.
2. `data` 디렉터리를 만들라는 안내가 표시되면 `config.php`가 있는 디렉터리에 `data`를 만들고 웹 서버가 쓸 수 있도록 권한을 설정합니다. 공식 매뉴얼에서는 `707` 권한을 예시로 사용합니다.
3. 라이선스 내용을 확인하고 동의한 뒤 설치를 계속합니다.
4. MySQL 또는 MariaDB 접속 정보와 최고관리자 정보를 입력합니다.
5. 설치 완료 화면을 확인한 뒤 생성한 최고관리자 계정으로 로그인합니다.
> 기존 사이트에 재설치하면 데이터가 삭제될 수 있습니다. 진행하기 전에 파일과 데이터베이스를 백업하십시오.
### 기존 설치 업데이트
소스 코드를 업데이트한 뒤 데이터베이스 변경이 포함된 버전은 관리자 메뉴의 **환경설정 → DB업그레이드**에서 변경 내용을 확인하고 명시적으로 실행합니다.
운영 절차와 마이그레이션 작성 규칙은 [데이터베이스 마이그레이션 문서](docs/database-migrations.md)를 확인하십시오.
## 문서 및 지원
- [5.6.391 쇼핑몰 분류 표시 수정 안내](docs/release-5.6.391.md)
- [5.6.39 보안 업데이트 및 필수 DB업그레이드 안내](docs/release-5.6.39.md)
- [5.6.37 SIRK 전용 카카오페이 연동 종료 및 기존 거래 지원](docs/sirk-kakaopay-retirement.md)
- [그누보드5 공식 페이지](https://sir.kr/main/g5/)
- [그누보드5 공식 매뉴얼](https://sir.kr/manuals/g5/1)
- [그누보드5 Q&A](https://sir.kr/questions?s_tag=%EA%B7%B8%EB%88%84%EB%B3%B4%EB%93%9C5)
보안 취약점 신고 방법은 [`SECURITY.md`](SECURITY.md)를 확인하십시오.
## 라이선스
라이선스 전문과 적용 조건은 [`LICENSE.txt`](LICENSE.txt)를 확인하십시오.
+5
View File
@@ -0,0 +1,5 @@
# 그누보드5 보안 정책
그누보드5에서 보안 취약점을 발견한 경우 악용 가능한 상세 내용을 공개 GitHub 이슈에 게시하지 마십시오.
취약점 정보와 재현 방법은 [SIR 보안 취약점 신고 게시판](https://sir.kr/boards/co_qa)을 통해 제보해 주십시오.
+8 -4
View File
@@ -1,10 +1,14 @@
<?php
define('G5_IS_ADMIN', true);
include_once ('../common.php');
include_once(G5_ADMIN_PATH.'/admin.lib.php');
require_once '../common.php';
require_once G5_ADMIN_PATH . '/admin.lib.php';
if( isset($token) ){
if (function_exists('g5_check_data_htaccess')) {
g5_check_data_htaccess();
}
if (isset($token)) {
$token = @htmlspecialchars(strip_tags($token), ENT_QUOTES);
}
run_event('admin_common');
run_event('admin_common');
+47 -45
View File
@@ -1,5 +1,7 @@
<?php
if (!defined('_GNUBOARD_')) exit;
if (!defined('_GNUBOARD_')) {
exit;
}
$is_use_apache = (stripos($_SERVER['SERVER_SOFTWARE'], 'apache') !== false);
@@ -11,29 +13,29 @@ $is_write_file = false;
$is_apache_need_rules = false;
$is_apache_rewrite = false;
if( !($is_use_apache || $is_use_nginx || $is_use_iis) ){ // 셋다 아니면 다 출력시킨다.
if (!($is_use_apache || $is_use_nginx || $is_use_iis)) { // 셋다 아니면 다 출력시킨다.
$is_use_apache = true;
$is_use_nginx = true;
}
if ( $is_use_nginx ){
if ($is_use_nginx) {
$is_write_file = false;
}
if ( $is_use_apache ){
$is_write_file = (is_writable(G5_PATH) || (file_exists(G5_PATH.'/.htaccess') && is_writable(G5_PATH.'/.htaccess'))) ? true : false;
if ($is_use_apache) {
$is_write_file = (is_writable(G5_PATH) || (file_exists(G5_PATH . '/.htaccess') && is_writable(G5_PATH . '/.htaccess'))) ? true : false;
$is_apache_need_rules = check_need_rewrite_rules();
$is_apache_rewrite = function_exists('apache_get_modules') && in_array('mod_rewrite', apache_get_modules());
}
$get_path_url = parse_url( G5_URL );
$get_path_url = parse_url(G5_URL);
$base_path = isset($get_path_url['path']) ? $get_path_url['path'].'/' : '/';
$base_path = isset($get_path_url['path']) ? $get_path_url['path'] . '/' : '/';
// add_stylesheet('css 구문', 출력순서); 숫자가 작을 수록 먼저 출력됨
add_stylesheet('<link rel="stylesheet" href="'.G5_JS_URL.'/remodal/remodal.css">', 11);
add_stylesheet('<link rel="stylesheet" href="'.G5_JS_URL.'/remodal/remodal-default-theme.css">', 12);
add_javascript('<script src="'.G5_JS_URL.'/remodal/remodal.js"></script>', 10);
add_stylesheet('<link rel="stylesheet" href="' . G5_JS_URL . '/remodal/remodal.css">', 11);
add_stylesheet('<link rel="stylesheet" href="' . G5_JS_URL . '/remodal/remodal-default-theme.css">', 12);
add_javascript('<script src="' . G5_JS_URL . '/remodal/remodal.js"></script>', 10);
?>
<section id="anc_cf_url">
<h2 class="h2_frm">짧은 주소 설정</h2>
@@ -41,48 +43,48 @@ add_javascript('<script src="'.G5_JS_URL.'/remodal/remodal.js"></script>', 10);
<div class="local_desc02 local_desc">
<p>
게시판과 컨텐츠 페이지에 짧은 URL 을 사용합니다. <a href="https://sir.kr/manual/g5/286" class="btn btn_03" target="_blank" style="margin-left:10px">설정 관련 메뉴얼 보기</a>
<?php if( $is_use_apache && ! $is_use_nginx ){ ?>
<?php if( ! $is_apache_rewrite ){ ?>
<br><strong>Apache 서버인 경우 rewrite_module 이 비활성화 되어 있으면 짧은 주소를 사용할수 없습니다.</strong>
<?php } else if( ! $is_write_file && $is_apache_need_rules ) { // apache인 경우 ?>
<br><strong>짧은 주소 사용시 아래 Apache 설정 코드를 참고하여 설정해 주세요.</strong>
<?php if ($is_use_apache && !$is_use_nginx) { ?>
<?php if (!$is_apache_rewrite) { ?>
<br><strong>Apache 서버인 경우 rewrite_module 이 비활성화 되어 있으면 짧은 주소를 사용할수 없습니다.</strong>
<?php } elseif (!$is_write_file && $is_apache_need_rules) { // apache인 경우 ?>
<br><strong>짧은 주소 사용시 아래 Apache 설정 코드를 참고하여 설정해 주세요.</strong>
<?php } ?>
<?php } ?>
</p>
</div>
<div class="server_config_views">
<?php if ( $is_use_apache ){ ?>
<?php if ($is_use_apache) { ?>
<button type="button" data-remodal-target="modal_apache" class="btn btn_03">Apache 설정 코드 보기</button>
<?php } ?>
<?php if ( $is_use_nginx ) { ?>
<?php if ($is_use_nginx) { ?>
<button type="button" data-remodal-target="modal_nginx" class="btn btn_03">Nginx 설정 코드 보기</button>
<?php } ?>
</div>
<div class="tbl_frm01 tbl_wrap">
<table>
<caption>짧은주소 설정</caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<?php
$short_url_arrs = array(
'0'=>array('label'=>'사용안함', 'url'=>G5_URL.'/board.php?bo_table=free&wr_id=123'),
'1'=>array('label'=>'숫자', 'url'=>G5_URL.'/free/123'),
'2'=>array('label'=>'글 이름', 'url'=>G5_URL.'/free/안녕하세요/'),
);
foreach($short_url_arrs as $k=>$v){
$checked = ((int) $config['cf_bbs_rewrite'] === (int) $k) ? 'checked' : '';
?>
<tr>
<td><input name="cf_bbs_rewrite" id="cf_bbs_rewrite_<?php echo $k; ?>" type="radio" value="<?php echo $k; ?>" <?php echo $checked;?> ><label for="cf_bbs_rewrite_<?php echo $k; ?>" class="rules_label"><?php echo $v['label']; ?></label></td>
<td><?php echo $v['url']; ?></td>
</tr>
<?php } //end foreach ?>
</tbody>
<caption>짧은주소 설정</caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<?php
$short_url_arrs = array(
'0' => array('label' => '사용안함', 'url' => G5_URL . '/board.php?bo_table=free&wr_id=123'),
'1' => array('label' => '숫자', 'url' => G5_URL . '/free/123'),
'2' => array('label' => '글 이름', 'url' => G5_URL . '/free/안녕하세요/'),
);
foreach ($short_url_arrs as $k => $v) {
$checked = ((int) $config['cf_bbs_rewrite'] === (int) $k) ? 'checked' : '';
?>
<tr>
<td><input name="cf_bbs_rewrite" id="cf_bbs_rewrite_<?php echo $k; ?>" type="radio" value="<?php echo $k; ?>" <?php echo $checked; ?>><label for="cf_bbs_rewrite_<?php echo $k; ?>" class="rules_label"><?php echo $v['label']; ?></label></td>
<td><?php echo $v['url']; ?></td>
</tr>
<?php } //end foreach ?>
</tbody>
</table>
</div>
@@ -95,13 +97,13 @@ add_javascript('<script src="'.G5_JS_URL.'/remodal/remodal.js"></script>', 10);
</button>
<h4 class="copy_title">.htaccess 파일에 적용할 코드입니다.
<?php if( ! $is_apache_rewrite ) { ?>
<br><span class="info-warning">Apache 서버인 경우 rewrite_module 이 비활성화 되어 있으면 짧은 주소를 사용할수 없습니다.</span>
<?php } else if ( ! $is_write_file && $is_apache_need_rules ) { ?>
<br><span class="info-warning">자동으로 .htaccess 파일을 수정 할수 있는 권한이 없습니다.<br>.htaccess 파일이 없다면 생성 후에, 아래 코드가 없으면 코드를 복사하여 붙여넣기 해 주세요.</span>
<?php } else if ( ! $is_apache_need_rules ){ ?>
<br><span class="info-success">정상적으로 적용된 상태입니다.</span>
<?php } ?>
<?php if (!$is_apache_rewrite) { ?>
<br><span class="info-warning">Apache 서버인 경우 rewrite_module 이 비활성화 되어 있으면 짧은 주소를 사용할수 없습니다.</span>
<?php } elseif (!$is_write_file && $is_apache_need_rules) { ?>
<br><span class="info-warning">자동으로 .htaccess 파일을 수정 할수 있는 권한이 없습니다.<br>.htaccess 파일이 없다면 생성 후에, 아래 코드가 없으면 코드를 복사하여 붙여넣기 해 주세요.</span>
<?php } elseif (!$is_apache_need_rules) { ?>
<br><span class="info-success">정상적으로 적용된 상태입니다.</span>
<?php } ?>
</h4>
<textarea readonly="readonly" rows="10"><?php echo get_mod_rewrite_rules(true); ?></textarea>
</div>
+89 -82
View File
@@ -1,25 +1,29 @@
<?php
if (!defined('_GNUBOARD_')) exit;
if (!defined('_GNUBOARD_')) {
exit;
}
$g5_debug['php']['begin_time'] = $begin_time = get_microtime();
$files = glob(G5_ADMIN_PATH.'/css/admin_extend_*');
$files = glob(G5_ADMIN_PATH . '/css/admin_extend_*');
if (is_array($files)) {
foreach ((array) $files as $k=>$css_file) {
foreach ((array) $files as $k => $css_file) {
$fileinfo = pathinfo($css_file);
$ext = $fileinfo['extension'];
if( $ext !== 'css' ) continue;
if ($ext !== 'css') {
continue;
}
$css_file = str_replace(G5_ADMIN_PATH, G5_ADMIN_URL, $css_file);
add_stylesheet('<link rel="stylesheet" href="'.$css_file.'">', $k);
add_stylesheet('<link rel="stylesheet" href="' . $css_file . '">', $k);
}
}
include_once(G5_PATH.'/head.sub.php');
require_once G5_PATH . '/head.sub.php';
function print_menu1($key, $no='')
function print_menu1($key, $no = '')
{
global $menu;
@@ -28,35 +32,39 @@ function print_menu1($key, $no='')
return $str;
}
function print_menu2($key, $no='')
function print_menu2($key, $no = '')
{
global $menu, $auth_menu, $is_admin, $auth, $g5, $sub_menu;
$str = "<ul>";
for($i=1; $i<count($menu[$key]); $i++)
{
if( ! isset($menu[$key][$i]) ){
for ($i = 1; $i < count($menu[$key]); $i++) {
if (!isset($menu[$key][$i])) {
continue;
}
if ($is_admin != 'super' && (!array_key_exists($menu[$key][$i][0],$auth) || !strstr($auth[$menu[$key][$i][0]], 'r')))
if ($is_admin != 'super' && (!array_key_exists($menu[$key][$i][0], $auth) || strpos($auth[$menu[$key][$i][0]], 'r') === false)) {
continue;
}
$gnb_grp_div = $gnb_grp_style = '';
if (isset($menu[$key][$i][4])){
if (($menu[$key][$i][4] == 1 && $gnb_grp_style == false) || ($menu[$key][$i][4] != 1 && $gnb_grp_style == true)) $gnb_grp_div = 'gnb_grp_div';
if (isset($menu[$key][$i][4])) {
if (($menu[$key][$i][4] == 1 && $gnb_grp_style == false) || ($menu[$key][$i][4] != 1 && $gnb_grp_style == true)) {
$gnb_grp_div = 'gnb_grp_div';
}
if ($menu[$key][$i][4] == 1) $gnb_grp_style = 'gnb_grp_style';
if ($menu[$key][$i][4] == 1) {
$gnb_grp_style = 'gnb_grp_style';
}
}
$current_class = '';
if ($menu[$key][$i][0] == $sub_menu){
if ($menu[$key][$i][0] == $sub_menu) {
$current_class = ' on';
}
$str .= '<li data-menu="'.$menu[$key][$i][0].'"><a href="'.$menu[$key][$i][2].'" class="gnb_2da '.$gnb_grp_style.' '.$gnb_grp_div.$current_class.'">'.$menu[$key][$i][1].'</a></li>';
$str .= '<li data-menu="' . $menu[$key][$i][0] . '"><a href="' . $menu[$key][$i][2] . '" class="gnb_2da ' . $gnb_grp_style . ' ' . $gnb_grp_div . $current_class . '">' . $menu[$key][$i][1] . '</a></li>';
$auth_menu[$menu[$key][$i][0]] = $menu[$key][$i][1];
}
@@ -66,12 +74,12 @@ function print_menu2($key, $no='')
}
$adm_menu_cookie = array(
'container' => '',
'gnb' => '',
'btn_gnb' => '',
'container' => '',
'gnb' => '',
'btn_gnb' => '',
);
if( ! empty($_COOKIE['g5_admin_btn_gnb']) ){
if (!empty($_COOKIE['g5_admin_btn_gnb'])) {
$adm_menu_cookie['container'] = 'container-small';
$adm_menu_cookie['gnb'] = 'gnb_small';
$adm_menu_cookie['btn_gnb'] = 'btn_gnb_open';
@@ -79,26 +87,26 @@ if( ! empty($_COOKIE['g5_admin_btn_gnb']) ){
?>
<script>
var tempX = 0;
var tempY = 0;
var g5_admin_csrf_token_key = "<?php echo (function_exists('admin_csrf_token_key')) ? admin_csrf_token_key() : ''; ?>";
var tempX = 0;
var tempY = 0;
function imageview(id, w, h)
{
function imageview(id, w, h) {
menu(id);
menu(id);
var el_id = document.getElementById(id);
var el_id = document.getElementById(id);
//submenu = eval(name+".style");
submenu = el_id.style;
submenu.left = tempX - ( w + 11 );
submenu.top = tempY - ( h / 2 );
//submenu = eval(name+".style");
submenu = el_id.style;
submenu.left = tempX - (w + 11);
submenu.top = tempY - (h / 2);
selectBoxVisible();
selectBoxVisible();
if (el_id.style.display != 'none')
selectBoxHidden(id);
}
if (el_id.style.display != 'none')
selectBoxHidden(id);
}
</script>
<div id="to_content"><a href="#container">본문 바로가기</a></div>
@@ -106,13 +114,13 @@ function imageview(id, w, h)
<header id="hd">
<h1><?php echo $config['cf_title'] ?></h1>
<div id="hd_top">
<button type="button" id="btn_gnb" class="btn_gnb_close <?php echo $adm_menu_cookie['btn_gnb'];?>">메뉴</button>
<div id="logo"><a href="<?php echo correct_goto_url(G5_ADMIN_URL); ?>"><img src="<?php echo G5_ADMIN_URL ?>/img/logo.png" alt="<?php echo get_text($config['cf_title']); ?> 관리자"></a></div>
<button type="button" id="btn_gnb" class="btn_gnb_close <?php echo $adm_menu_cookie['btn_gnb']; ?>">메뉴</button>
<div id="logo"><a href="<?php echo correct_goto_url(G5_ADMIN_URL); ?>"><img src="<?php echo G5_ADMIN_URL ?>/img/logo.png" alt="<?php echo get_text($config['cf_title']); ?> 관리자"></a></div>
<div id="tnb">
<ul>
<?php if (defined('G5_USE_SHOP') && G5_USE_SHOP) { ?>
<li class="tnb_li"><a href="<?php echo G5_SHOP_URL ?>/" class="tnb_shop" target="_blank" title="쇼핑몰 바로가기">쇼핑몰 바로가기</a></li>
<li class="tnb_li"><a href="<?php echo G5_SHOP_URL ?>/" class="tnb_shop" target="_blank" title="쇼핑몰 바로가기">쇼핑몰 바로가기</a></li>
<?php } ?>
<li class="tnb_li"><a href="<?php echo G5_URL ?>/" class="tnb_community" target="_blank" title="커뮤니티 바로가기">커뮤니티 바로가기</a></li>
<li class="tnb_li"><a href="<?php echo G5_ADMIN_URL ?>/service.php" class="tnb_service">부가서비스</a></li>
@@ -130,33 +138,34 @@ function imageview(id, w, h)
<ul class="gnb_ul">
<?php
$jj = 1;
foreach($amenu as $key=>$value) {
foreach ($amenu as $key => $value) {
$href1 = $href2 = '';
if (isset($menu['menu'.$key][0][2]) && $menu['menu'.$key][0][2]) {
$href1 = '<a href="'.$menu['menu'.$key][0][2].'" class="gnb_1da">';
if (isset($menu['menu' . $key][0][2]) && $menu['menu' . $key][0][2]) {
$href1 = '<a href="' . $menu['menu' . $key][0][2] . '" class="gnb_1da">';
$href2 = '</a>';
} else {
continue;
}
$current_class = "";
if (isset($sub_menu) && (substr($sub_menu, 0, 3) == substr($menu['menu'.$key][0][0], 0, 3)))
if (isset($sub_menu) && (substr($sub_menu, 0, 3) == substr($menu['menu' . $key][0][0], 0, 3))) {
$current_class = " on";
}
$button_title = $menu['menu'.$key][0][1];
$button_title = $menu['menu' . $key][0][1];
?>
<li class="gnb_li<?php echo $current_class;?>">
<button type="button" class="btn_op menu-<?php echo $key; ?> menu-order-<?php echo $jj; ?>" title="<?php echo $button_title; ?>"><?php echo $button_title;?></button>
<div class="gnb_oparea_wr">
<div class="gnb_oparea">
<h3><?php echo $menu['menu'.$key][0][1];?></h3>
<?php echo print_menu1('menu'.$key, 1); ?>
<li class="gnb_li<?php echo $current_class; ?>">
<button type="button" class="btn_op menu-<?php echo $key; ?> menu-order-<?php echo $jj; ?>" title="<?php echo $button_title; ?>"><?php echo $button_title; ?></button>
<div class="gnb_oparea_wr">
<div class="gnb_oparea">
<h3><?php echo $menu['menu' . $key][0][1]; ?></h3>
<?php echo print_menu1('menu' . $key, 1); ?>
</div>
</div>
</div>
</li>
</li>
<?php
$jj++;
$jj++;
} //end foreach
?>
</ul>
@@ -164,39 +173,37 @@ function imageview(id, w, h)
</header>
<script>
jQuery(function($){
jQuery(function($) {
var menu_cookie_key = 'g5_admin_btn_gnb';
var menu_cookie_key = 'g5_admin_btn_gnb';
$(".tnb_mb_btn").click(function(){
$(".tnb_mb_area").toggle();
});
$(".tnb_mb_btn").click(function() {
$(".tnb_mb_area").toggle();
});
$("#btn_gnb").click(function(){
var $this = $(this);
$("#btn_gnb").click(function() {
try {
if( ! $this.hasClass("btn_gnb_open") ){
set_cookie(menu_cookie_key, 1, 60*60*24*365);
} else {
delete_cookie(menu_cookie_key);
}
}
catch(err) {
}
var $this = $(this);
$("#container").toggleClass("container-small");
$("#gnb").toggleClass("gnb_small");
$this.toggleClass("btn_gnb_open");
try {
if (!$this.hasClass("btn_gnb_open")) {
set_cookie(menu_cookie_key, 1, 60 * 60 * 24 * 365);
} else {
delete_cookie(menu_cookie_key);
}
} catch (err) {}
$("#container").toggleClass("container-small");
$("#gnb").toggleClass("gnb_small");
$this.toggleClass("btn_gnb_open");
});
$(".gnb_ul li .btn_op").click(function() {
$(this).parent().addClass("on").siblings().removeClass("on");
});
});
$(".gnb_ul li .btn_op" ).click(function() {
$(this).parent().addClass("on").siblings().removeClass("on");
});
});
</script>
+112 -6
View File
@@ -1,11 +1,115 @@
function check_all(f)
{
var chk = document.getElementsByName("chk[]");
/** 공통 UI 모듈 */
window.CommonUI = {
bindTabs(tabSelector, contentSelector, options = {}) {
const tabs = document.querySelectorAll(tabSelector);
const contents = document.querySelectorAll(contentSelector);
for (i=0; i<chk.length; i++)
chk[i].checked = f.chkall.checked;
tabs.forEach(tab => {
tab.addEventListener('click', () => {
const tabName = tab.dataset.tab;
const target = document.getElementById(`tab-${tabName}`);
tabs.forEach(t => t.classList.remove('active'));
tab.classList.add('active');
contents.forEach(c => c.classList.add('is-hidden'));
if (target) target.classList.remove('is-hidden');
options.onChange?.(tabName, target);
});
});
}
};
function setHtml(el, markup) {
if (!el) return;
if (markup == null || markup === '') {
el.textContent = '';
return;
}
const range = document.createRange();
range.selectNodeContents(el);
el.replaceChildren(range.createContextualFragment(markup));
}
/** 팝업 관리 모듈 */
window.PopupManager = {
open(id, options = {}) {
const el = document.getElementById(id);
if (el) {
el.classList.remove('is-hidden');
this.bindOutsideClickClose(id);
if (!options.disableOutsideClose) {
this.bindOutsideClickClose(id);
} else {
this.unbindOutsideClickClose(id);
}
}
},
close(id) {
const el = document.getElementById(id);
if (el) el.classList.add('is-hidden');
},
toggle(id) {
const el = document.getElementById(id);
if (el) el.classList.toggle('is-hidden');
},
bindOutsideClickClose(id) {
const el = document.getElementById(id);
if (!el) return;
el.onclick = () => this.close(id);
},
unbindOutsideClickClose(id) {
const el = document.getElementById(id);
if (!el) return;
el.onclick = null;
},
/**
* 팝업 콘텐츠 렌더링 (타이틀, 바디, 푸터 구성)
* @param {string} title - 팝업 제목
* @param {string} body - 팝업 본문 HTML
* @param {string} [footer] - 푸터 HTML
* @param {object} [options] - 팝업 열기 옵션
*/
render(title, body, footer = '', options = {}) {
const titleEl = document.getElementById('popupTitle');
const bodyEl = document.getElementById('popupBody');
const footerEl = document.getElementById('popupFooter');
if (titleEl) titleEl.textContent = title;
if (bodyEl) setHtml(bodyEl, body);
if (footerEl) setHtml(footerEl, footer);
this.open('popupOverlay', options);
}
};
/** 형식 체크 */
function check_all(target) {
const chkboxes = document.getElementsByName("chk[]");
let chkall;
if (target && target.tagName === "FORM") {
chkall = target.querySelector('input[name="chkall"]');
} else if (target && target.type === "checkbox") {
chkall = target;
}
if (!chkall) return;
for (const checkbox of chkboxes) {
checkbox.checked = chkall.checked;
}
}
function btn_check(f, act)
{
if (act == "update") // 선택수정
@@ -83,11 +187,13 @@ function delete_confirm2(msg)
function get_ajax_token()
{
var token = "";
var token = "",
admin_csrf_token_key = (typeof g5_admin_csrf_token_key !== "undefined") ? g5_admin_csrf_token_key : "";
$.ajax({
type: "POST",
url: g5_admin_url+"/ajax.token.php",
data : {admin_csrf_token_key:admin_csrf_token_key},
cache: false,
async: false,
dataType: "json",
+409 -192
View File
@@ -1,5 +1,7 @@
<?php
if (!defined('_GNUBOARD_')) exit;
if (!defined('_GNUBOARD_')) {
exit;
}
/*
// 081022 : CSRF 방지를 위해 코드를 작성했으나 효과가 없어 주석처리 함
@@ -10,17 +12,17 @@ if (!get_session('ss_admin')) {
*/
// 스킨디렉토리를 SELECT 형식으로 얻음
function get_skin_select($skin_gubun, $id, $name, $selected='', $event='')
function get_skin_select($skin_gubun, $id, $name, $selected = '', $event = '')
{
global $config;
$skins = array();
if(defined('G5_THEME_PATH') && $config['cf_theme']) {
$dirs = get_skin_dir($skin_gubun, G5_THEME_PATH.'/'.G5_SKIN_DIR);
if(!empty($dirs)) {
foreach($dirs as $dir) {
$skins[] = 'theme/'.$dir;
if (defined('G5_THEME_PATH') && $config['cf_theme']) {
$dirs = get_skin_dir($skin_gubun, G5_THEME_PATH . '/' . G5_SKIN_DIR);
if (!empty($dirs)) {
foreach ($dirs as $dir) {
$skins[] = 'theme/' . $dir;
}
}
}
@@ -28,12 +30,15 @@ function get_skin_select($skin_gubun, $id, $name, $selected='', $event='')
$skins = array_merge($skins, get_skin_dir($skin_gubun));
$str = "<select id=\"$id\" name=\"$name\" $event>\n";
for ($i=0; $i<count($skins); $i++) {
if ($i == 0) $str .= "<option value=\"\">선택</option>";
if(preg_match('#^theme/(.+)$#', $skins[$i], $match))
$text = '(테마) '.$match[1];
else
for ($i = 0; $i < count($skins); $i++) {
if ($i == 0) {
$str .= "<option value=\"\">선택</option>";
}
if (preg_match('#^theme/(.+)$#', $skins[$i], $match)) {
$text = '(테마) ' . $match[1];
} else {
$text = $skins[$i];
}
$str .= option_selected($skins[$i], $selected, $text);
}
@@ -42,30 +47,33 @@ function get_skin_select($skin_gubun, $id, $name, $selected='', $event='')
}
// 모바일 스킨디렉토리를 SELECT 형식으로 얻음
function get_mobile_skin_select($skin_gubun, $id, $name, $selected='', $event='')
function get_mobile_skin_select($skin_gubun, $id, $name, $selected = '', $event = '')
{
global $config;
$skins = array();
if(defined('G5_THEME_PATH') && $config['cf_theme']) {
$dirs = get_skin_dir($skin_gubun, G5_THEME_MOBILE_PATH.'/'.G5_SKIN_DIR);
if(!empty($dirs)) {
foreach($dirs as $dir) {
$skins[] = 'theme/'.$dir;
if (defined('G5_THEME_PATH') && $config['cf_theme']) {
$dirs = get_skin_dir($skin_gubun, G5_THEME_MOBILE_PATH . '/' . G5_SKIN_DIR);
if (!empty($dirs)) {
foreach ($dirs as $dir) {
$skins[] = 'theme/' . $dir;
}
}
}
$skins = array_merge($skins, get_skin_dir($skin_gubun, G5_MOBILE_PATH.'/'.G5_SKIN_DIR));
$skins = array_merge($skins, get_skin_dir($skin_gubun, G5_MOBILE_PATH . '/' . G5_SKIN_DIR));
$str = "<select id=\"$id\" name=\"$name\" $event>\n";
for ($i=0; $i<count($skins); $i++) {
if ($i == 0) $str .= "<option value=\"\">선택</option>";
if(preg_match('#^theme/(.+)$#', $skins[$i], $match))
$text = '(테마) '.$match[1];
else
for ($i = 0; $i < count($skins); $i++) {
if ($i == 0) {
$str .= "<option value=\"\">선택</option>";
}
if (preg_match('#^theme/(.+)$#', $skins[$i], $match)) {
$text = '(테마) ' . $match[1];
} else {
$text = $skins[$i];
}
$str .= option_selected($skins[$i], $selected, $text);
}
@@ -75,21 +83,26 @@ function get_mobile_skin_select($skin_gubun, $id, $name, $selected='', $event=''
// 스킨경로를 얻는다
function get_skin_dir($skin, $skin_path=G5_SKIN_PATH)
function get_skin_dir($skin, $skin_path = G5_SKIN_PATH)
{
global $g5;
$result_array = array();
$dirname = $skin_path.'/'.$skin.'/';
if(!is_dir($dirname))
return;
$dirname = $skin_path . '/' . $skin . '/';
if (!is_dir($dirname)) {
return array();
}
$handle = opendir($dirname);
while ($file = readdir($handle)) {
if($file == '.'||$file == '..') continue;
if ($file == '.' || $file == '..') {
continue;
}
if (is_dir($dirname.$file)) $result_array[] = $file;
if (is_dir($dirname . $file)) {
$result_array[] = $file;
}
}
closedir($handle);
sort($result_array);
@@ -103,15 +116,18 @@ function get_theme_dir()
{
$result_array = array();
$dirname = G5_PATH.'/'.G5_THEME_DIR.'/';
$dirname = G5_PATH . '/' . G5_THEME_DIR . '/';
$handle = opendir($dirname);
while ($file = readdir($handle)) {
if($file == '.'||$file == '..') continue;
if ($file == '.' || $file == '..') {
continue;
}
if (is_dir($dirname.$file)) {
$theme_path = $dirname.$file;
if(is_file($theme_path.'/index.php') && is_file($theme_path.'/head.php') && is_file($theme_path.'/tail.php'))
if (is_dir($dirname . $file)) {
$theme_path = $dirname . $file;
if (is_file($theme_path . '/index.php') && is_file($theme_path . '/head.php') && is_file($theme_path . '/tail.php')) {
$result_array[] = $file;
}
}
}
closedir($handle);
@@ -125,21 +141,23 @@ function get_theme_dir()
function get_theme_info($dir)
{
$info = array();
$path = G5_PATH.'/'.G5_THEME_DIR.'/'.$dir;
$path = G5_PATH . '/' . G5_THEME_DIR . '/' . $dir;
if(is_dir($path)) {
$screenshot = $path.'/screenshot.png';
if(is_file($screenshot)) {
if (is_dir($path)) {
$screenshot = $path . '/screenshot.png';
$screenshot_url = '';
if (is_file($screenshot)) {
$size = @getimagesize($screenshot);
if($size[2] == 3)
if ($size[2] == 3) {
$screenshot_url = str_replace(G5_PATH, G5_URL, $screenshot);
}
}
$info['screenshot'] = $screenshot_url;
$text = $path.'/readme.txt';
if(is_file($text)) {
$text = $path . '/readme.txt';
if (is_file($text)) {
$content = file($text, false);
$content = array_map('trim', $content);
@@ -162,8 +180,9 @@ function get_theme_info($dir)
$info['license_uri'] = trim($m7[1]);
}
if(!$info['theme_name'])
if (!$info['theme_name']) {
$info['theme_name'] = $dir;
}
}
return $info;
@@ -171,19 +190,19 @@ function get_theme_info($dir)
// 테마설정 정보
function get_theme_config_value($dir, $key='*')
function get_theme_config_value($dir, $key = '*')
{
$tconfig = array();
$theme_config_file = G5_PATH.'/'.G5_THEME_DIR.'/'.$dir.'/theme.config.php';
if(is_file($theme_config_file)) {
include($theme_config_file);
if($key == '*') {
$theme_config_file = G5_PATH . '/' . G5_THEME_DIR . '/' . $dir . '/theme.config.php';
if (is_file($theme_config_file)) {
include $theme_config_file;
// 22.05.26 Undefined Variable $theme_config;
if ($key == '*') {
$tconfig = $theme_config;
} else {
$keys = array_map('trim', explode(',', $key));
foreach($keys as $v) {
foreach ($keys as $v) {
$tconfig[$v] = isset($theme_config[$v]) ? trim($theme_config[$v]) : '';
}
}
@@ -194,17 +213,20 @@ function get_theme_config_value($dir, $key='*')
// 회원권한을 SELECT 형식으로 얻음
function get_member_level_select($name, $start_id=0, $end_id=10, $selected="", $event="")
function get_member_level_select($name, $start_id = 0, $end_id = 10, $selected = "", $event = "")
{
global $g5;
$str = "\n<select id=\"{$name}\" name=\"{$name}\"";
if ($event) $str .= " $event";
if ($event) {
$str .= " $event";
}
$str .= ">\n";
for ($i=$start_id; $i<=$end_id; $i++) {
$str .= '<option value="'.$i.'"';
if ($i == $selected)
for ($i = $start_id; $i <= $end_id; $i++) {
$str .= '<option value="' . $i . '"';
if ($i == $selected) {
$str .= ' selected="selected"';
}
$str .= ">{$i}</option>\n";
}
$str .= "</select>\n";
@@ -213,89 +235,98 @@ function get_member_level_select($name, $start_id=0, $end_id=10, $selected="", $
// 회원아이디를 SELECT 형식으로 얻음
function get_member_id_select($name, $level, $selected="", $event="")
function get_member_id_select($name, $level, $selected = "", $event = "")
{
global $g5;
$sql = " select mb_id from {$g5['member_table']} where mb_level >= '{$level}' ";
$result = sql_query($sql);
$str = '<select id="'.$name.'" name="'.$name.'" '.$event.'><option value="">선택안함</option>';
for ($i=0; $row=sql_fetch_array($result); $i++)
{
$str .= '<option value="'.$row['mb_id'].'"';
if ($row['mb_id'] == $selected) $str .= ' selected';
$str .= '>'.$row['mb_id'].'</option>';
$str = '<select id="' . $name . '" name="' . $name . '" ' . $event . '><option value="">선택안함</option>';
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$str .= '<option value="' . $row['mb_id'] . '"';
if ($row['mb_id'] == $selected) {
$str .= ' selected';
}
$str .= '>' . $row['mb_id'] . '</option>';
}
$str .= '</select>';
return $str;
}
// php8 버전 호환 권한 검사 함수
function auth_check_menu($auth, $sub_menu, $attr, $return=false) {
function auth_check_menu($auth, $sub_menu, $attr, $return = false)
{
$check_auth = isset($auth[$sub_menu]) ? $auth[$sub_menu] : '';
return auth_check($check_auth, $attr, $return);
}
// 권한 검사
function auth_check($auth, $attr, $return=false)
function auth_check($auth, $attr, $return = false)
{
global $is_admin;
if ($is_admin == 'super') return;
if ($is_admin == 'super') {
return;
}
if (!trim($auth)) {
$msg = '이 메뉴에는 접근 권한이 없습니다.\\n\\n접근 권한은 최고관리자만 부여할 수 있습니다.';
if($return)
if ($return) {
return $msg;
else
} else {
alert($msg);
}
}
$attr = strtolower($attr);
if (!strstr($auth, $attr)) {
if (strpos($auth, $attr) === false) {
if ($attr == 'r') {
$msg = '읽을 권한이 없습니다.';
if($return)
if ($return) {
return $msg;
else
} else {
alert($msg);
}
} else if ($attr == 'w') {
$msg = '입력, 추가, 생성, 수정 권한이 없습니다.';
if($return)
if ($return) {
return $msg;
else
} else {
alert($msg);
}
} else if ($attr == 'd') {
$msg = '삭제 권한이 없습니다.';
if($return)
if ($return) {
return $msg;
else
} else {
alert($msg);
}
} else {
$msg = '속성이 잘못 되었습니다.';
if($return)
if ($return) {
return $msg;
else
} else {
alert($msg);
}
}
}
}
// 작업아이콘 출력
function icon($act, $link='', $target='_parent')
function icon($act, $link = '', $target = '_parent')
{
global $g5;
$img = array('입력'=>'insert', '추가'=>'insert', '생성'=>'insert', '수정'=>'modify', '삭제'=>'delete', '이동'=>'move', '그룹'=>'move', '보기'=>'view', '미리보기'=>'view', '복사'=>'copy');
$icon = '<img src="'.G5_ADMIN_PATH.'/img/icon_'.$img[$act].'.gif" title="'.$act.'">';
if ($link)
$s = '<a href="'.$link.'">'.$icon.'</a>';
else
$img = array('입력' => 'insert', '추가' => 'insert', '생성' => 'insert', '수정' => 'modify', '삭제' => 'delete', '이동' => 'move', '그룹' => 'move', '보기' => 'view', '미리보기' => 'view', '복사' => 'copy');
$icon = '<img src="' . G5_ADMIN_PATH . '/img/icon_' . $img[$act] . '.gif" title="' . $act . '">';
if ($link) {
$s = '<a href="' . $link . '">' . $icon . '</a>';
} else {
$s = $icon;
}
return $s;
}
@@ -307,9 +338,10 @@ function rm_rf($file)
if (file_exists($file)) {
if (is_dir($file)) {
$handle = opendir($file);
while($filename = readdir($handle)) {
if ($filename != '.' && $filename != '..')
rm_rf($file.'/'.$filename);
while ($filename = readdir($handle)) {
if ($filename != '.' && $filename != '..') {
rm_rf($file . '/' . $filename);
}
}
closedir($handle);
@@ -323,21 +355,21 @@ function rm_rf($file)
}
// 입력 폼 안내문
function help($help="")
function help($help = "")
{
global $g5;
$str = '<span class="frm_info">'.str_replace("\n", "<br>", $help).'</span>';
$str = '<span class="frm_info">' . str_replace("\n", "<br>", $help) . '</span>';
return $str;
}
// 출력순서
function order_select($fld, $sel='')
function order_select($fld, $sel = '')
{
$s = '<select name="'.$fld.'" id="'.$fld.'">';
for ($i=1; $i<=100; $i++) {
$s .= '<option value="'.$i.'" ';
$s = '<select name="' . $fld . '" id="' . $fld . '">';
for ($i = 1; $i <= 100; $i++) {
$s .= '<option value="' . $i . '" ';
if ($sel) {
if ($i == $sel) {
$s .= 'selected';
@@ -347,7 +379,7 @@ function order_select($fld, $sel='')
$s .= 'selected';
}
}
$s .= '>'.$i.'</option>';
$s .= '>' . $i . '</option>';
}
$s .= '</select>';
@@ -357,18 +389,19 @@ function order_select($fld, $sel='')
// 불법접근을 막도록 토큰을 생성하면서 토큰값을 리턴
function get_admin_token()
{
$token = md5(uniqid(rand(), true));
$token = get_random_token_string(16);
set_session('ss_admin_token', $token);
return $token;
}
// 관리자가 자동등록방지를 사용해야 할 경우
function get_admin_captcha_by($type='get'){
function get_admin_captcha_by($type = 'get')
{
$captcha_name = 'ss_admin_use_captcha';
if($type === 'remove'){
if ($type === 'remove') {
set_session($captcha_name, '');
}
@@ -376,9 +409,10 @@ function get_admin_captcha_by($type='get'){
}
//input value 에서 xss 공격 filter 역할을 함 ( 반드시 input value='' 타입에만 사용할것 )
function get_sanitize_input($s, $is_html=false){
function get_sanitize_input($s, $is_html = false)
{
if(!$is_html){
if (!$is_html) {
$s = strip_tags($s);
}
@@ -387,50 +421,85 @@ function get_sanitize_input($s, $is_html=false){
return $s;
}
function check_log_folder($log_path, $is_delete=true){
function domain_mail_host($is_at=true){
list($domain_host,) = explode(':', $_SERVER['HTTP_HOST']);
if( is_writable($log_path) ){
if ('www.' === substr($domain_host, 0, 4)) {
$domain_host = substr($domain_host, 4);
}
return $is_at ? '@'.$domain_host : $domain_host;
}
function check_log_folder($log_path, $is_delete = true)
{
if (is_writable($log_path)) {
// 아파치 서버인 경우 웹에서 해당 폴더 접근 막기
$htaccess_file = $log_path.'/.htaccess';
if ( !file_exists( $htaccess_file ) ) {
if ( $handle = @fopen( $htaccess_file, 'w' ) ) {
fwrite( $handle, 'Order deny,allow' . "\n" );
fwrite( $handle, 'Deny from all' . "\n" );
fclose( $handle );
$htaccess_file = $log_path . '/.htaccess';
if (!file_exists($htaccess_file)) {
if ($handle = @fopen($htaccess_file, 'w')) {
fwrite($handle, 'Order deny,allow' . "\n");
fwrite($handle, 'Deny from all' . "\n");
fclose($handle);
}
}
// 아파치 서버인 경우 해당 디렉토리 파일 목록 안보이게 하기
$index_file = $log_path . '/index.php';
if ( !file_exists( $index_file ) ) {
if ( $handle = @fopen( $index_file, 'w' ) ) {
fwrite( $handle, '' );
fclose( $handle );
if (!file_exists($index_file)) {
if ($handle = @fopen($index_file, 'w')) {
fwrite($handle, '');
fclose($handle);
}
}
}
if( $is_delete ) {
try {
// txt 파일과 log 파일을 조회하여 30일이 지난 파일은 삭제합니다.
$txt_files = glob($log_path.'/*.txt');
$log_files = glob($log_path.'/*.log');
$del_files = array_merge($txt_files, $log_files);
if( $del_files && is_array($del_files) ){
foreach ($del_files as $del_file) {
$filetime = filemtime($del_file);
// 30일이 지난 파일을 삭제
if($filetime && $filetime < (G5_SERVER_TIME - 2592000)) {
@unlink($del_file);
}
}
}
} catch(Exception $e) {
}
}
if ($is_delete) {
try {
// txt 파일과 log 파일을 조회하여 30일이 지난 파일은 삭제합니다.
$txt_files = glob($log_path . '/*.txt');
$log_files = glob($log_path . '/*.log');
$del_files = array_merge($txt_files, $log_files);
if ($del_files && is_array($del_files)) {
foreach ($del_files as $del_file) {
$filetime = filemtime($del_file);
// 30일이 지난 파일을 삭제
if ($filetime && $filetime < (G5_SERVER_TIME - 2592000)) {
@unlink($del_file);
}
}
}
} catch (Exception $e) {
}
}
}
// 회원 본인확인 식별값과 인증 이력만 정리한다. 호출부에서 관리자 권한을 검증한다.
function admin_clear_member_certification($mb_id)
{
global $g5;
$esc_mb_id = sql_real_escape_string($mb_id);
$history_table = isset($g5['member_cert_history_table']) ? $g5['member_cert_history_table'] : G5_TABLE_PREFIX.'member_cert_history';
// 일반 회원정보(이름·연락처)와 이메일 인증 상태는 유지한다.
if (!sql_query(" update {$g5['member_table']}
set mb_certify = '', mb_adult = 0, mb_dupinfo = '', mb_birth = '', mb_sex = ''
where mb_id = '{$esc_mb_id}' ", false)) {
return false;
}
if (!sql_query(" delete from {$history_table} where mb_id = '{$esc_mb_id}' ", false)) {
return false;
}
if (!sql_query(" delete from {$g5['cert_history_table']} where mb_id = '{$esc_mb_id}' ", false)) {
return false;
}
return true;
}
// POST로 넘어온 토큰과 세션에 저장된 토큰 비교
@@ -439,23 +508,37 @@ function check_admin_token()
$token = get_session('ss_admin_token');
set_session('ss_admin_token', '');
if(!$token || !$_REQUEST['token'] || $token != $_REQUEST['token'])
if (!$token || !$_REQUEST['token'] || $token != $_REQUEST['token']) {
alert('올바른 방법으로 이용해 주십시오.', G5_URL);
}
return true;
}
function admin_csrf_token_key($is_must=0){
global $member;
$key = '';
if($is_must || !((isset($_SERVER['HTTP_X_REQUESTED_WITH']) && strtolower($_SERVER['HTTP_X_REQUESTED_WITH']) == 'xmlhttprequest'))){
$key = md5((isset($_SERVER['SERVER_SOFTWARE']) ? $_SERVER['SERVER_SOFTWARE'] : '').(defined('G5_TOKEN_ENCRYPTION_KEY') ? G5_TOKEN_ENCRYPTION_KEY : '').$member['mb_id'].$_SERVER['DOCUMENT_ROOT']);
}
return run_replace('admin_csrf_token_key', $key, $is_must);
}
// 관리자 페이지 referer 체크
function admin_referer_check($return=false)
function admin_referer_check($return = false)
{
$referer = isset($_SERVER['HTTP_REFERER']) ? trim($_SERVER['HTTP_REFERER']) : '';
if(!$referer) {
if (!$referer) {
$msg = '정보가 올바르지 않습니다.';
if($return)
if ($return) {
return $msg;
else
} else {
alert($msg, G5_URL);
}
}
$p = @parse_url($referer);
@@ -463,16 +546,16 @@ function admin_referer_check($return=false)
$host = preg_replace('/:[0-9]+$/', '', $_SERVER['HTTP_HOST']);
$msg = '';
if($host != $p['host']) {
if ($host != $p['host']) {
$msg = '올바른 방법으로 이용해 주십시오.';
}
if( $p['path'] && ! preg_match( '/\/'.preg_quote(G5_ADMIN_DIR).'\//i', $p['path'] ) ){
if ($p['path'] && !preg_match('/\/' . preg_quote(G5_ADMIN_DIR) . '\//i', $p['path'])) {
$msg = '올바른 방법으로 이용해 주십시오';
}
if( $msg ){
if($return) {
if ($msg) {
if ($return) {
return $msg;
} else {
alert($msg, G5_URL);
@@ -480,91 +563,210 @@ function admin_referer_check($return=false)
}
}
function admin_check_xss_params($params){
function admin_check_xss_params($params)
{
if( ! $params ) return;
if (!$params) {
return;
}
foreach( $params as $key=>$value ){
foreach ($params as $key => $value) {
if ( empty($value) ) continue;
if (empty($value)) {
continue;
}
if( is_array($value) ){
if (is_array($value)) {
admin_check_xss_params($value);
} else if ( (preg_match('/<\s?[^\>]*\/?\s?>/i', $value) && (preg_match('/script.*?\/script/ius', $value) || preg_match('/[onload|onerror]=.*/ius', $value))) || preg_match('/^(?=.*token\()(?=.*xmlhttprequest\()(?=.*send\().*$/im', $value) || (preg_match('/[onload|onerror|focus]=.*/ius', $value) && preg_match('/(eval|expression|exec|prompt)(\s*)\((.*)\)/ius', $value)) ){
} else if (
(preg_match('/<\s?[^\>]*\/?\s?>/i', $value) && (preg_match('/script.*?\/script/ius', $value) || preg_match('/on[a-z]+=*/ius', $value))) || preg_match('/^(?=.*token\()(?=.*xmlhttprequest\()(?=.*send\().*$/im', $value) ||
(preg_match('/(on[a-z]+|focus)=.*/ius', $value) && preg_match('/(eval|atob|fetch|expression|exec|prompt)(\s*)\((.*)\)/ius', $value))) {
alert('요청 쿼리에 잘못된 스크립트문장이 있습니다.\\nXSS 공격일수도 있습니다.', G5_URL);
die();
} else if (preg_match('/atob\s*\(\s*[\'"]?([a-zA-Z0-9+\/=]+)[\'"]?\s*\)/ius', $value, $matches)) {
$decoded = base64_decode($matches[1], true);
if ($decoded && preg_match('/(eval|fetch|script|alert|settimeout|setinterval)/ius', $decoded)) {
// error_log("Base64 XSS 시도 감지: key=$key, decoded=$decoded, IP=" . $_SERVER['REMOTE_ADDR']);
alert('Base64로 인코딩된 위험한 스크립트가 발견되었습니다.', G5_URL);
die();
}
}
}
return;
}
function admin_menu_find_by($call, $search_key){
function admin_menu_find_by($call, $search_key)
{
global $menu;
static $cache_menu = array();
if( empty($cache_menu) ){
foreach( $menu as $k1=>$arr1 ){
if (empty($arr1) ) continue;
foreach( $arr1 as $k2=>$arr2 ){
if (empty($arr2) ) continue;
static $cache_menu = array();
if (empty($cache_menu)) {
foreach ($menu as $k1 => $arr1) {
if (empty($arr1)) {
continue;
}
foreach ($arr1 as $k2 => $arr2) {
if (empty($arr2)) {
continue;
}
$menu_key = isset($arr2[3]) ? $arr2[3] : '';
if (empty($menu_key) ) continue;
if (empty($menu_key)) {
continue;
}
$cache_menu[$menu_key] = array(
'sub_menu'=>$arr2[0],
'title'=>$arr2[1],
'link'=>$arr2[2],
);
'sub_menu' => $arr2[0],
'title' => $arr2[1],
'link' => $arr2[2],
);
}
}
}
if( isset($cache_menu[$call]) && isset($cache_menu[$call][$search_key]) ){
if (isset($cache_menu[$call]) && isset($cache_menu[$call][$search_key])) {
return $cache_menu[$call][$search_key];
}
return '';
}
// 접근 권한 검사
if (!$member['mb_id'])
function admin_menu_local_path($url)
{
alert('로그인 하십시오.', G5_BBS_URL.'/login.php?url=' . urlencode(correct_goto_url(G5_ADMIN_URL)));
$url = (string) $url;
if (!$url) {
return '';
}
$url = preg_replace('/[?#].*$/', '', $url);
$maps = array(
G5_ADMIN_URL => G5_ADMIN_PATH,
);
if (defined('G5_SMS5_ADMIN_URL') && defined('G5_SMS5_ADMIN_PATH')) {
$maps[G5_SMS5_ADMIN_URL] = G5_SMS5_ADMIN_PATH;
}
foreach ($maps as $base_url => $base_path) {
if (strpos($url, $base_url) !== 0) {
continue;
}
$path = $base_path.substr($url, strlen($base_url));
if (substr($path, -1) === '/') {
$path .= 'index.php';
}
return $path;
}
return '';
}
else if ($is_admin != 'super')
function admin_menu_is_super_only($menu_item)
{
static $cache = array();
$sub_menu = isset($menu_item[0]) ? (string) $menu_item[0] : '';
if (!$sub_menu) {
return false;
}
if (isset($cache[$sub_menu])) {
return $cache[$sub_menu];
}
// 향후 메뉴 정의에서 명시적으로 최고관리자 전용 표시가 필요할 때 사용한다.
if (isset($menu_item[4]) && $menu_item[4] === 'super') {
return $cache[$sub_menu] = true;
}
$path = admin_menu_local_path(isset($menu_item[2]) ? $menu_item[2] : '');
if (!$path || !is_readable($path)) {
return $cache[$sub_menu] = false;
}
$content = file_get_contents($path, false, null, 0, 12000);
if ($content === false) {
return $cache[$sub_menu] = false;
}
$pattern = '/if\s*\([^\)]*\$is_admin\s*(?:!==|!=)\s*[\'"]super[\'"][^\)]*\)\s*\{?[\s\S]{0,250}(?:alert|alert_close|die)\s*\([^\;]*(?:최고관리자만|최고관리자로)/u';
return $cache[$sub_menu] = (bool) preg_match($pattern, $content);
}
function admin_get_assignable_auth_menu()
{
global $menu;
$assignable_auth_menu = array();
if (!isset($menu) || !is_array($menu)) {
return $assignable_auth_menu;
}
foreach ($menu as $menu_group) {
if (!is_array($menu_group)) {
continue;
}
for ($i=1; $i<count($menu_group); $i++) {
if (!isset($menu_group[$i]) || !is_array($menu_group[$i])) {
continue;
}
$sub_menu = isset($menu_group[$i][0]) ? $menu_group[$i][0] : '';
if (!$sub_menu || $sub_menu === '-' || substr($sub_menu, -3) === '000') {
continue;
}
if (admin_menu_is_super_only($menu_group[$i])) {
continue;
}
$assignable_auth_menu[$sub_menu] = isset($menu_group[$i][1]) ? $menu_group[$i][1] : '';
}
}
return $assignable_auth_menu;
}
// 접근 권한 검사
if (!$member['mb_id']) {
alert('로그인 하십시오.', G5_BBS_URL . '/login.php?url=' . urlencode(correct_goto_url(G5_ADMIN_URL)));
} else if ($is_admin != 'super') {
$auth = array();
$sql = " select au_menu, au_auth from {$g5['auth_table']} where mb_id = '{$member['mb_id']}' ";
$result = sql_query($sql);
for($i=0; $row=sql_fetch_array($result); $i++)
{
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$auth[$row['au_menu']] = $row['au_auth'];
}
if (!$i)
{
if (!$i) {
alert('최고관리자 또는 관리권한이 있는 회원만 접근 가능합니다.', G5_URL);
}
}
// 관리자의 아이피, 브라우저와 다르다면 세션을 끊고 관리자에게 메일을 보낸다.
$admin_key = md5($member['mb_datetime'] . get_real_client_ip() . $_SERVER['HTTP_USER_AGENT']);
if (get_session('ss_mb_key') !== $admin_key) {
// 관리자의 클라이언트를 검증하여 일치하지 않으면 세션을 끊고 관리자에게 메일을 보낸다.
if (!verify_mb_key($member)) {
session_destroy();
include_once(G5_LIB_PATH.'/mailer.lib.php');
include_once G5_LIB_PATH . '/mailer.lib.php';
// 메일 알림
mailer($member['mb_nick'], $member['mb_email'], $member['mb_email'], 'XSS 공격 알림', $_SERVER['REMOTE_ADDR'].' 아이피로 XSS 공격이 있었습니다.<br><br>관리자 권한을 탈취하려는 접근이므로 주의하시기 바랍니다.<br><br>해당 아이피는 차단하시고 의심되는 게시물이 있는지 확인하시기 바랍니다.'.G5_URL, 0);
mailer($member['mb_nick'], $member['mb_email'], $member['mb_email'], 'XSS 공격 알림', $_SERVER['REMOTE_ADDR'] . ' 아이피로 XSS 공격이 있었습니다.<br><br>관리자 권한을 탈취하려는 접근이므로 주의하시기 바랍니다.<br><br>해당 아이피는 차단하시고 의심되는 게시물이 있는지 확인하시기 바랍니다.' . G5_URL, 0);
alert_close('정상적으로 로그인하여 접근하시기 바랍니다.');
}
if(isset($auth) && is_array($auth)) {
if (isset($auth) && is_array($auth)) {
@ksort($auth);
} else {
$auth = array();
@@ -577,36 +779,51 @@ unset($amenu);
$tmp = dir(G5_ADMIN_PATH);
$menu_files = array();
while ($entry = $tmp->read()) {
if (!preg_match('/^admin.menu([0-9]{3}).*\.php$/', $entry, $m))
if (!preg_match('/^admin.menu([0-9]{3}).*\.php$/', $entry, $m)) {
continue; // 파일명이 menu 으로 시작하지 않으면 무시한다.
}
$amenu[$m[1]] = $entry;
$menu_files[] = G5_ADMIN_PATH.'/'.$entry;
$menu_files[] = G5_ADMIN_PATH . '/' . $entry;
}
@asort($menu_files);
foreach($menu_files as $file){
include_once($file);
foreach ($menu_files as $file) {
include_once $file;
}
@ksort($amenu);
$amenu = run_replace('admin_amenu', $amenu);
if( isset($menu) && $menu ){
$menu = run_replace('admin_menu', $menu);
if (isset($menu) && $menu) {
$menu = run_replace('admin_menu', $menu);
}
$arr_query = array();
if (isset($sst)) $arr_query[] = 'sst='.$sst;
if (isset($sod)) $arr_query[] = 'sod='.$sod;
if (isset($sfl)) $arr_query[] = 'sfl='.$sfl;
if (isset($stx)) $arr_query[] = 'stx='.$stx;
if (isset($page)) $arr_query[] = 'page='.$page;
if (isset($sst)) {
$arr_query[] = 'sst=' . $sst;
}
if (isset($sod)) {
$arr_query[] = 'sod=' . $sod;
}
if (isset($sfl)) {
$arr_query[] = 'sfl=' . $sfl;
}
if (isset($stx)) {
$arr_query[] = 'stx=' . $stx;
}
if (isset($page)) {
$arr_query[] = 'page=' . $page;
}
$qstr = implode("&amp;", $arr_query);
if ( isset($_REQUEST) && $_REQUEST ){
if( admin_referer_check(true) ){
if (isset($_REQUEST) && $_REQUEST) {
if (admin_referer_check(true)) {
admin_check_xss_params($_REQUEST);
}
}
// 관리자에서는 추가 스크립트는 사용하지 않는다.
//$config['cf_add_script'] = '';
// 관리자에서는 추가 스크립트와 추가 매타태그, 방문자분석 스크립트가 실행되지 않게 빈값으로 합니다.
if (run_replace('safe_admin_add_script_boolean', false) === false) {
$config['cf_analytics'] = '';
$config['cf_add_script'] = '';
$config['cf_add_meta'] = '';
}
+19 -18
View File
@@ -1,23 +1,24 @@
<?php
$menu['menu100'] = array (
array('100000', '환경설정', G5_ADMIN_URL.'/config_form.php', 'config'),
array('100100', '기본환경설정', G5_ADMIN_URL.'/config_form.php', 'cf_basic'),
array('100200', '관리권한설정', G5_ADMIN_URL.'/auth_list.php', 'cf_auth'),
array('100280', '테마설정', G5_ADMIN_URL.'/theme.php', 'cf_theme', 1),
array('100290', '메뉴설정', G5_ADMIN_URL.'/menu_list.php', 'cf_menu', 1),
array('100300', '메일 테스트', G5_ADMIN_URL.'/sendmail_test.php', 'cf_mailtest'),
array('100310', '팝업레이어관리', G5_ADMIN_URL.'/newwinlist.php', 'scf_poplayer'),
array('100800', '세션파일 일괄삭제',G5_ADMIN_URL.'/session_file_delete.php', 'cf_session', 1),
array('100900', '캐시파일 일괄삭제',G5_ADMIN_URL.'/cache_file_delete.php', 'cf_cache', 1),
array('100910', '캡챠파일 일괄삭제',G5_ADMIN_URL.'/captcha_file_delete.php', 'cf_captcha', 1),
array('100920', '썸네일파일 일괄삭제',G5_ADMIN_URL.'/thumbnail_file_delete.php', 'cf_thumbnail', 1),
array('100500', 'phpinfo()', G5_ADMIN_URL.'/phpinfo.php', 'cf_phpinfo')
$menu['menu100'] = array(
array('100000', '환경설정', G5_ADMIN_URL . '/config_form.php', 'config'),
array('100100', '기본환경설정', G5_ADMIN_URL . '/config_form.php', 'cf_basic'),
array('100200', '관리권한설정', G5_ADMIN_URL . '/auth_list.php', 'cf_auth'),
array('100280', '테마설정', G5_ADMIN_URL . '/theme.php', 'cf_theme', 1),
array('100290', '메뉴설정', G5_ADMIN_URL . '/menu_list.php', 'cf_menu', 1),
array('100300', '메일 테스트', G5_ADMIN_URL . '/sendmail_test.php', 'cf_mailtest'),
array('100310', '팝업레이어관리', G5_ADMIN_URL . '/newwinlist.php', 'scf_poplayer'),
array('100800', '세션파일 일괄삭제', G5_ADMIN_URL . '/session_file_delete.php', 'cf_session', 1),
array('100900', '캐시파일 일괄삭제', G5_ADMIN_URL . '/cache_file_delete.php', 'cf_cache', 1),
array('100910', '캡챠파일 일괄삭제', G5_ADMIN_URL . '/captcha_file_delete.php', 'cf_captcha', 1),
array('100920', '썸네일파일 일괄삭제', G5_ADMIN_URL . '/thumbnail_file_delete.php', 'cf_thumbnail', 1),
array('100930', '회원관리파일 일괄삭제', G5_ADMIN_URL . '/member_list_file_delete.php', 'cf_memberlist', 1),
array('100500', 'phpinfo()', G5_ADMIN_URL . '/phpinfo.php', 'cf_phpinfo')
);
if(version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE) {
$menu['menu100'][] = array('100510', 'Browscap 업데이트', G5_ADMIN_URL.'/browscap.php', 'cf_browscap');
$menu['menu100'][] = array('100520', '접속로그 변환', G5_ADMIN_URL.'/browscap_convert.php', 'cf_visit_cnvrt');
if (version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE) {
$menu['menu100'][] = array('100510', 'Browscap 업데이트', G5_ADMIN_URL . '/browscap.php', 'cf_browscap');
$menu['menu100'][] = array('100520', '접속로그 변환', G5_ADMIN_URL . '/browscap_convert.php', 'cf_visit_cnvrt');
}
$menu['menu100'][] = array('100410', 'DB업그레이드', G5_ADMIN_URL.'/dbupgrade.php', 'db_upgrade');
$menu['menu100'][] = array('100400', '부가서비스', G5_ADMIN_URL.'/service.php', 'cf_service');
$menu['menu100'][] = array('100410', 'DB업그레이드', G5_ADMIN_URL . '/dbupgrade.php', 'db_upgrade');
$menu['menu100'][] = array('100400', '부가서비스', G5_ADMIN_URL . '/service.php', 'cf_service');
+11 -10
View File
@@ -1,11 +1,12 @@
<?php
$menu['menu200'] = array (
array('200000', '회원관리', G5_ADMIN_URL.'/member_list.php', 'member'),
array('200100', '회원관리', G5_ADMIN_URL.'/member_list.php', 'mb_list'),
array('200300', '회원메일발송', G5_ADMIN_URL.'/mail_list.php', 'mb_mail'),
array('200800', '접속자집계', G5_ADMIN_URL.'/visit_list.php', 'mb_visit', 1),
array('200810', '접속자검색', G5_ADMIN_URL.'/visit_search.php', 'mb_search', 1),
array('200820', '접속자로그삭제', G5_ADMIN_URL.'/visit_delete.php', 'mb_delete', 1),
array('200200', '포인트관리', G5_ADMIN_URL.'/point_list.php', 'mb_point'),
array('200900', '투표관리', G5_ADMIN_URL.'/poll_list.php', 'mb_poll')
);
$menu['menu200'] = array(
array('200000', '회원관리', G5_ADMIN_URL . '/member_list.php', 'member'),
array('200100', '회원관리', G5_ADMIN_URL . '/member_list.php', 'mb_list'),
array('200400', '회원관리파일', G5_ADMIN_URL . '/member_list_exel.php', 'mb_list'),
array('200300', '회원메일발송', G5_ADMIN_URL . '/mail_list.php', 'mb_mail'),
array('200800', '접속자집계', G5_ADMIN_URL . '/visit_list.php', 'mb_visit', 1),
array('200810', '접속자검색', G5_ADMIN_URL . '/visit_search.php', 'mb_search', 1),
array('200820', '접속자로그삭제', G5_ADMIN_URL . '/visit_delete.php', 'mb_delete', 1),
array('200200', '포인트관리', G5_ADMIN_URL . '/point_list.php', 'mb_point'),
array('200900', '투표관리', G5_ADMIN_URL . '/poll_list.php', 'mb_poll')
);
+11 -11
View File
@@ -1,12 +1,12 @@
<?php
$menu['menu300'] = array (
array('300000', '게시판관리', ''.G5_ADMIN_URL.'/board_list.php', 'board'),
array('300100', '게시판관리', ''.G5_ADMIN_URL.'/board_list.php', 'bbs_board'),
array('300200', '게시판그룹관리', ''.G5_ADMIN_URL.'/boardgroup_list.php', 'bbs_group'),
array('300300', '인기검색어관리', ''.G5_ADMIN_URL.'/popular_list.php', 'bbs_poplist', 1),
array('300400', '인기검색어순위', ''.G5_ADMIN_URL.'/popular_rank.php', 'bbs_poprank', 1),
array('300500', '1:1문의설정', ''.G5_ADMIN_URL.'/qa_config.php', 'qa'),
array('300600', '내용관리', G5_ADMIN_URL.'/contentlist.php', 'scf_contents', 1),
array('300700', 'FAQ관리', G5_ADMIN_URL.'/faqmasterlist.php', 'scf_faq', 1),
array('300820', '글,댓글 현황', G5_ADMIN_URL.'/write_count.php', 'scf_write_count'),
);
$menu['menu300'] = array(
array('300000', '게시판관리', '' . G5_ADMIN_URL . '/board_list.php', 'board'),
array('300100', '게시판관리', '' . G5_ADMIN_URL . '/board_list.php', 'bbs_board'),
array('300200', '게시판그룹관리', '' . G5_ADMIN_URL . '/boardgroup_list.php', 'bbs_group'),
array('300300', '인기검색어관리', '' . G5_ADMIN_URL . '/popular_list.php', 'bbs_poplist', 1),
array('300400', '인기검색어순위', '' . G5_ADMIN_URL . '/popular_rank.php', 'bbs_poprank', 1),
array('300500', '1:1문의설정', '' . G5_ADMIN_URL . '/qa_config.php', 'qa'),
array('300600', '내용관리', G5_ADMIN_URL . '/contentlist.php', 'scf_contents', 1),
array('300700', 'FAQ관리', G5_ADMIN_URL . '/faqmasterlist.php', 'scf_faq', 1),
array('300820', '글,댓글 현황', G5_ADMIN_URL . '/write_count.php', 'scf_write_count'),
);
+28 -19
View File
@@ -1,21 +1,30 @@
<?php
if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) return;
if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) {
return;
}
$menu['menu400'] = array (
array('400000', '쇼핑몰관리', G5_ADMIN_URL.'/shop_admin/', 'shop_config'),
array('400010', '쇼핑몰현황', G5_ADMIN_URL.'/shop_admin/', 'shop_index'),
array('400100', '쇼핑몰설정', G5_ADMIN_URL.'/shop_admin/configform.php', 'scf_config'),
array('400400', '주문내역', G5_ADMIN_URL.'/shop_admin/orderlist.php', 'scf_order', 1),
array('400440', '개인결제관리', G5_ADMIN_URL.'/shop_admin/personalpaylist.php', 'scf_personalpay', 1),
array('400200', '분류관리', G5_ADMIN_URL.'/shop_admin/categorylist.php', 'scf_cate'),
array('400300', '상품관리', G5_ADMIN_URL.'/shop_admin/itemlist.php', 'scf_item'),
array('400660', '상품문의', G5_ADMIN_URL.'/shop_admin/itemqalist.php', 'scf_item_qna'),
array('400650', '사용후기', G5_ADMIN_URL.'/shop_admin/itemuselist.php', 'scf_ps'),
array('400620', '상품재고관리', G5_ADMIN_URL.'/shop_admin/itemstocklist.php', 'scf_item_stock'),
array('400610', '상품유형관리', G5_ADMIN_URL.'/shop_admin/itemtypelist.php', 'scf_item_type'),
array('400500', '상품옵션재고관리', G5_ADMIN_URL.'/shop_admin/optionstocklist.php', 'scf_item_option'),
array('400800', '쿠폰관리', G5_ADMIN_URL.'/shop_admin/couponlist.php', 'scf_coupon'),
array('400810', '쿠폰존관리', G5_ADMIN_URL.'/shop_admin/couponzonelist.php', 'scf_coupon_zone'),
array('400750', '추가배송비관리', G5_ADMIN_URL.'/shop_admin/sendcostlist.php', 'scf_sendcost', 1),
array('400410', '미완료주문', G5_ADMIN_URL.'/shop_admin/inorderlist.php', 'scf_inorder', 1),
);
global $default;
$menu['menu400'] = array(
array('400000', '쇼핑몰관리', G5_ADMIN_URL . '/shop_admin/', 'shop_config'),
array('400010', '쇼핑몰현황', G5_ADMIN_URL . '/shop_admin/', 'shop_index'),
array('400100', '쇼핑몰설정', G5_ADMIN_URL . '/shop_admin/configform.php', 'scf_config'),
array('400400', '주문내역', G5_ADMIN_URL . '/shop_admin/orderlist.php', 'scf_order', 1),
array('400440', '개인결제관리', G5_ADMIN_URL . '/shop_admin/personalpaylist.php', 'scf_personalpay', 1),
array('400200', '분류관리', G5_ADMIN_URL . '/shop_admin/categorylist.php', 'scf_cate'),
array('400300', '상품관리', G5_ADMIN_URL . '/shop_admin/itemlist.php', 'scf_item'),
array('400660', '상품문의', G5_ADMIN_URL . '/shop_admin/itemqalist.php', 'scf_item_qna'),
array('400650', '사용후기', G5_ADMIN_URL . '/shop_admin/itemuselist.php', 'scf_ps'),
array('400620', '상품재고관리', G5_ADMIN_URL . '/shop_admin/itemstocklist.php', 'scf_item_stock'),
array('400610', '상품유형관리', G5_ADMIN_URL . '/shop_admin/itemtypelist.php', 'scf_item_type'),
array('400500', '상품옵션재고관리', G5_ADMIN_URL . '/shop_admin/optionstocklist.php', 'scf_item_option'),
array('400800', '쿠폰관리', G5_ADMIN_URL . '/shop_admin/couponlist.php', 'scf_coupon'),
array('400810', '쿠폰존관리', G5_ADMIN_URL . '/shop_admin/couponzonelist.php', 'scf_coupon_zone'),
array('400750', '추가배송비관리', G5_ADMIN_URL . '/shop_admin/sendcostlist.php', 'scf_sendcost', 1),
array('400410', '미완료주문', G5_ADMIN_URL . '/shop_admin/inorderlist.php', 'scf_inorder', 1),
);
// 결제방식이 KG이니시스이고 INIpay PRO를 사용할 때만 노출한다.
if (isset($default['de_pg_service']) && $default['de_pg_service'] === 'inicis' && !empty($default['de_inicis_pro_use'])) {
$menu['menu400'][] = array('400420', 'KG이니시스 PRO 현황', G5_ADMIN_URL . '/shop_admin/inicisloglist.php', 'scf_inicis_log');
}
+15 -13
View File
@@ -1,15 +1,17 @@
<?php
if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) return;
if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) {
return;
}
$menu['menu500'] = array (
array('500000', '쇼핑몰현황/기타', G5_ADMIN_URL.'/shop_admin/itemsellrank.php', 'shop_stats'),
array('500110', '매출현황', G5_ADMIN_URL.'/shop_admin/sale1.php', 'sst_order_stats'),
array('500100', '상품판매순위', G5_ADMIN_URL.'/shop_admin/itemsellrank.php', 'sst_rank'),
array('500120', '주문내역출력', G5_ADMIN_URL.'/shop_admin/orderprint.php', 'sst_print_order', 1),
array('500400', '재입고SMS알림', G5_ADMIN_URL.'/shop_admin/itemstocksms.php', 'sst_stock_sms', 1),
array('500300', '이벤트관리', G5_ADMIN_URL.'/shop_admin/itemevent.php', 'scf_event'),
array('500310', '이벤트일괄처리', G5_ADMIN_URL.'/shop_admin/itemeventlist.php', 'scf_event_mng'),
array('500500', '배너관리', G5_ADMIN_URL.'/shop_admin/bannerlist.php', 'scf_banner', 1),
array('500140', '보관함현황', G5_ADMIN_URL.'/shop_admin/wishlist.php', 'sst_wish'),
array('500210', '가격비교사이트', G5_ADMIN_URL.'/shop_admin/price.php', 'sst_compare', 1)
);
$menu['menu500'] = array(
array('500000', '쇼핑몰현황/기타', G5_ADMIN_URL . '/shop_admin/itemsellrank.php', 'shop_stats'),
array('500110', '매출현황', G5_ADMIN_URL . '/shop_admin/sale1.php', 'sst_order_stats'),
array('500100', '상품판매순위', G5_ADMIN_URL . '/shop_admin/itemsellrank.php', 'sst_rank'),
array('500120', '주문내역출력', G5_ADMIN_URL . '/shop_admin/orderprint.php', 'sst_print_order', 1),
array('500400', '재입고SMS알림', G5_ADMIN_URL . '/shop_admin/itemstocksms.php', 'sst_stock_sms', 1),
array('500300', '이벤트관리', G5_ADMIN_URL . '/shop_admin/itemevent.php', 'scf_event'),
array('500310', '이벤트일괄처리', G5_ADMIN_URL . '/shop_admin/itemeventlist.php', 'scf_event_mng'),
array('500500', '배너관리', G5_ADMIN_URL . '/shop_admin/bannerlist.php', 'scf_banner', 1),
array('500140', '보관함현황', G5_ADMIN_URL . '/shop_admin/wishlist.php', 'sst_wish'),
array('500210', '가격비교사이트', G5_ADMIN_URL . '/shop_admin/price.php', 'sst_compare', 1)
);
+14 -14
View File
@@ -1,14 +1,14 @@
<?php
$menu["menu900"] = array (
array('900000', 'SMS 관리', ''.G5_SMS5_ADMIN_URL.'/config.php', 'sms5'),
array('900100', 'SMS 기본설정', ''.G5_SMS5_ADMIN_URL.'/config.php', 'sms5_config'),
array('900200', '회원정보업데이트', ''.G5_SMS5_ADMIN_URL.'/member_update.php', 'sms5_mb_update'),
array('900300', '문자 보내기', ''.G5_SMS5_ADMIN_URL.'/sms_write.php', 'sms_write'),
array('900400', '전송내역-건별', ''.G5_SMS5_ADMIN_URL.'/history_list.php', 'sms_history' , 1),
array('900410', '전송내역-번호별', ''.G5_SMS5_ADMIN_URL.'/history_num.php', 'sms_history_num' , 1),
array('900500', '이모티콘 그룹', ''.G5_SMS5_ADMIN_URL.'/form_group.php' , 'emoticon_group'),
array('900600', '이모티콘 관리', ''.G5_SMS5_ADMIN_URL.'/form_list.php', 'emoticon_list'),
array('900700', '휴대폰번호 그룹', ''.G5_SMS5_ADMIN_URL.'/num_group.php' , 'hp_group', 1),
array('900800', '휴대폰번호 관리', ''.G5_SMS5_ADMIN_URL.'/num_book.php', 'hp_manage', 1),
array('900900', '휴대폰번호 파일', ''.G5_SMS5_ADMIN_URL.'/num_book_file.php' , 'hp_file', 1)
);
<?php
$menu["menu900"] = array(
array('900000', 'SMS 관리', '' . G5_SMS5_ADMIN_URL . '/config.php', 'sms5'),
array('900100', 'SMS 기본설정', '' . G5_SMS5_ADMIN_URL . '/config.php', 'sms5_config'),
array('900200', '회원정보업데이트', '' . G5_SMS5_ADMIN_URL . '/member_update.php', 'sms5_mb_update'),
array('900300', '문자 보내기', '' . G5_SMS5_ADMIN_URL . '/sms_write.php', 'sms_write'),
array('900400', '전송내역-건별', '' . G5_SMS5_ADMIN_URL . '/history_list.php', 'sms_history', 1),
array('900410', '전송내역-번호별', '' . G5_SMS5_ADMIN_URL . '/history_num.php', 'sms_history_num', 1),
array('900500', '이모티콘 그룹', '' . G5_SMS5_ADMIN_URL . '/form_group.php', 'emoticon_group'),
array('900600', '이모티콘 관리', '' . G5_SMS5_ADMIN_URL . '/form_list.php', 'emoticon_list'),
array('900700', '휴대폰번호 그룹', '' . G5_SMS5_ADMIN_URL . '/num_group.php', 'hp_group', 1),
array('900800', '휴대폰번호 관리', '' . G5_SMS5_ADMIN_URL . '/num_book.php', 'hp_manage', 1),
array('900900', '휴대폰번호 파일', '' . G5_SMS5_ADMIN_URL . '/num_book_file.php', 'hp_file', 1)
);
+129 -111
View File
@@ -1,155 +1,173 @@
<?php
if (!defined('_GNUBOARD_')) exit;
if (!defined('_GNUBOARD_')) {
exit;
}
// 그누보드5.4.5.5 버전과 영카트5.4.5.5.1 버전이 통합됨에 따라 그누보드 버전만 표시
// $print_version = defined('G5_YOUNGCART_VER') ? 'YoungCart Version '.G5_YOUNGCART_VER : 'Version '.G5_GNUBOARD_VER;
$print_version = 'Version '.G5_GNUBOARD_VER;
$print_version = ($is_admin == 'super') ? 'Version ' . G5_GNUBOARD_VER : '';
?>
<noscript>
<p>
귀하께서 사용하시는 브라우저는 현재 <strong>자바스크립트를 사용하지 않음</strong>으로 설정되어 있습니다.<br>
<strong>자바스크립트를 사용하지 않음</strong>으로 설정하신 경우는 수정이나 삭제시 별도의 경고창이 나오지 않으므로 이점 주의하시기 바랍니다.
</p>
</noscript>
<noscript>
<p>
귀하께서 사용하시는 브라우저는 현재 <strong>자바스크립트를 사용하지 않음</strong>으로 설정되어 있습니다.<br>
<strong>자바스크립트를 사용하지 않음</strong>으로 설정하신 경우는 수정이나 삭제시 별도의 경고창이 나오지 않으므로 이점 주의하시기 바랍니다.
</p>
</noscript>
</div>
<footer id="ft">
<p>
Copyright &copy; <?php echo htmlspecialchars($_SERVER['HTTP_HOST']); ?>. All rights reserved. <?php echo $print_version; ?><br>
<button type="button" class="scroll_top"><span class="top_img"></span><span class="top_txt">TOP</span></button>
</p>
</footer>
</div>
<footer id="ft">
<p>
Copyright &copy; <?php echo $_SERVER['HTTP_HOST']; ?>. All rights reserved. <?php echo $print_version; ?><br>
<button type="button" class="scroll_top"><span class="top_img"></span><span class="top_txt">TOP</span></button>
</p>
</footer>
<!-- 공통 레이어 팝업 컨테이너 -->
<div id="adminPopupContainer">
<div id="popupOverlay" class="popup-overlay is-hidden" onclick="PopupManager.close('popupOverlay')">
<div class="popup-content" onclick="event.stopPropagation()">
<div class="popup-header">
<strong id="popupTitle" class="popup-title"></strong>
<button type="button" class="popup-close-btn" onclick="PopupManager.close('popupOverlay')">
<i class="fa fa-close"></i><span class="sound_only">팝업 닫기</span>
</button>
</div>
<div class="popup-body" id="popupBody">
<!-- 동적으로 내용 주입 -->
</div>
<div class="popup-footer" id="popupFooter">
<!-- 버튼 등 동적으로 -->
</div>
</div>
</div>
</div>
<script>
$(".scroll_top").click(function(){
$("body,html").animate({scrollTop:0},400);
})
$(".scroll_top").click(function() {
$("body,html").animate({
scrollTop: 0
}, 400);
})
</script>
<!-- <p>실행시간 : <?php echo get_microtime() - $begin_time; ?> -->
<script src="<?php echo G5_ADMIN_URL ?>/admin.js?ver=<?php echo G5_JS_VER; ?>"></script>
<script src="<?php echo G5_JS_URL ?>/jquery.anchorScroll.js?ver=<?php echo G5_JS_VER; ?>"></script>
<script src="<?php echo get_versioned_asset_url(G5_ADMIN_URL.'/admin.js'); ?>"></script>
<script src="<?php echo get_versioned_asset_url(G5_JS_URL.'/jquery.anchorScroll.js'); ?>"></script>
<script>
$(function(){
$(function() {
var admin_head_height = $("#hd_top").height() + $("#container_title").height() + 5;
var admin_head_height = $("#hd_top").height() + $("#container_title").height() + 5;
$("a[href^='#']").anchorScroll({
scrollSpeed: 0, // scroll speed
offsetTop: admin_head_height, // offset for fixed top bars (defaults to 0)
onScroll: function () {
// callback on scroll start
},
scrollEnd: function () {
// callback on scroll end
}
});
$("a[href^='#']").anchorScroll({
scrollSpeed: 0, // scroll speed
offsetTop: admin_head_height, // offset for fixed top bars (defaults to 0)
onScroll: function() {
// callback on scroll start
},
scrollEnd: function() {
// callback on scroll end
}
});
var hide_menu = false;
var mouse_event = false;
var oldX = oldY = 0;
var hide_menu = false;
var mouse_event = false;
var oldX = oldY = 0;
$(document).mousemove(function(e) {
if(oldX == 0) {
oldX = e.pageX;
oldY = e.pageY;
}
$(document).mousemove(function(e) {
if (oldX == 0) {
oldX = e.pageX;
oldY = e.pageY;
}
if(oldX != e.pageX || oldY != e.pageY) {
mouse_event = true;
}
});
if (oldX != e.pageX || oldY != e.pageY) {
mouse_event = true;
}
});
// 주메뉴
var $gnb = $(".gnb_1dli > a");
$gnb.mouseover(function() {
if(mouse_event) {
// 주메뉴
var $gnb = $(".gnb_1dli > a");
$gnb.mouseover(function() {
if (mouse_event) {
$(".gnb_1dli").removeClass("gnb_1dli_over gnb_1dli_over2 gnb_1dli_on");
$(this).parent().addClass("gnb_1dli_over gnb_1dli_on");
menu_rearrange($(this).parent());
hide_menu = false;
}
});
$gnb.mouseout(function() {
hide_menu = true;
});
$(".gnb_2dli").mouseover(function() {
hide_menu = false;
});
$(".gnb_2dli").mouseout(function() {
hide_menu = true;
});
$gnb.focusin(function() {
$(".gnb_1dli").removeClass("gnb_1dli_over gnb_1dli_over2 gnb_1dli_on");
$(this).parent().addClass("gnb_1dli_over gnb_1dli_on");
menu_rearrange($(this).parent());
hide_menu = false;
}
});
});
$gnb.mouseout(function() {
hide_menu = true;
});
$gnb.focusout(function() {
hide_menu = true;
});
$(".gnb_2dli").mouseover(function() {
hide_menu = false;
});
$(".gnb_2da").focusin(function() {
$(".gnb_1dli").removeClass("gnb_1dli_over gnb_1dli_over2 gnb_1dli_on");
var $gnb_li = $(this).closest(".gnb_1dli").addClass("gnb_1dli_over gnb_1dli_on");
menu_rearrange($(this).closest(".gnb_1dli"));
hide_menu = false;
});
$(".gnb_2dli").mouseout(function() {
hide_menu = true;
});
$(".gnb_2da").focusout(function() {
hide_menu = true;
});
$gnb.focusin(function() {
$(".gnb_1dli").removeClass("gnb_1dli_over gnb_1dli_over2 gnb_1dli_on");
$(this).parent().addClass("gnb_1dli_over gnb_1dli_on");
menu_rearrange($(this).parent());
hide_menu = false;
});
$gnb.focusout(function() {
hide_menu = true;
});
$(".gnb_2da").focusin(function() {
$(".gnb_1dli").removeClass("gnb_1dli_over gnb_1dli_over2 gnb_1dli_on");
var $gnb_li = $(this).closest(".gnb_1dli").addClass("gnb_1dli_over gnb_1dli_on");
menu_rearrange($(this).closest(".gnb_1dli"));
hide_menu = false;
});
$(".gnb_2da").focusout(function() {
hide_menu = true;
});
$('#gnb_1dul>li').bind('mouseleave',function(){
submenu_hide();
});
$(document).bind('click focusin',function(){
if(hide_menu) {
$('#gnb_1dul>li').bind('mouseleave', function() {
submenu_hide();
});
$(document).bind('click focusin', function() {
if (hide_menu) {
submenu_hide();
}
});
// 폰트 리사이즈 쿠키있으면 실행
var font_resize_act = get_cookie("ck_font_resize_act");
if (font_resize_act != "") {
font_resize("container", font_resize_act);
}
});
// 폰트 리사이즈 쿠키있으면 실행
var font_resize_act = get_cookie("ck_font_resize_act");
if(font_resize_act != "") {
font_resize("container", font_resize_act);
function submenu_hide() {
$(".gnb_1dli").removeClass("gnb_1dli_over gnb_1dli_over2 gnb_1dli_on");
}
});
function submenu_hide() {
$(".gnb_1dli").removeClass("gnb_1dli_over gnb_1dli_over2 gnb_1dli_on");
}
function menu_rearrange(el) {
var width = $("#gnb_1dul").width();
var left = w1 = w2 = 0;
var idx = $(".gnb_1dli").index(el);
function menu_rearrange(el)
{
var width = $("#gnb_1dul").width();
var left = w1 = w2 = 0;
var idx = $(".gnb_1dli").index(el);
for (i = 0; i <= idx; i++) {
w1 = $(".gnb_1dli:eq(" + i + ")").outerWidth();
w2 = $(".gnb_2dli > a:eq(" + i + ")").outerWidth(true);
for(i=0; i<=idx; i++) {
w1 = $(".gnb_1dli:eq("+i+")").outerWidth();
w2 = $(".gnb_2dli > a:eq("+i+")").outerWidth(true);
if ((left + w2) > width) {
el.removeClass("gnb_1dli_over").addClass("gnb_1dli_over2");
}
if((left + w2) > width) {
el.removeClass("gnb_1dli_over").addClass("gnb_1dli_over2");
left += w1;
}
left += w1;
}
}
</script>
<?php
include_once(G5_PATH.'/tail.sub.php');
require_once G5_PATH . '/tail.sub.php';
+11 -5
View File
@@ -1,13 +1,19 @@
<?php
include_once('./_common.php');
include_once(G5_LIB_PATH.'/json.lib.php');
require_once './_common.php';
set_session('ss_admin_token', '');
$admin_csrf_token_key = isset($_POST['admin_csrf_token_key']) ? $_POST['admin_csrf_token_key'] : '';
if(function_exists('admin_csrf_token_key') && $admin_csrf_token_key !== admin_csrf_token_key(1)){
die(json_encode(array('error' => '토큰키 에러!', 'url' => G5_URL)));
}
$error = admin_referer_check(true);
if($error)
die(json_encode(array('error'=>$error, 'url'=>G5_URL)));
if ($error) {
die(json_encode(array('error' => $error, 'url' => G5_URL)));
}
$token = get_admin_token();
die(json_encode(array('error'=>'', 'token'=>$token, 'url'=>'')));
die(json_encode(array('error' => '', 'token' => $token, 'url' => '')));
+3 -3
View File
@@ -1,6 +1,6 @@
<?php
include_once('./_common.php');
require_once './_common.php';
if( isset($_POST['admin_use_captcha']) ){
if (isset($_POST['admin_use_captcha'])) {
set_session('ss_admin_use_captcha', true);
}
}
+194 -181
View File
@@ -1,17 +1,23 @@
<?php
$sub_menu = "100200";
include_once('./_common.php');
require_once './_common.php';
if ($is_admin != 'super')
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
$sql_common = " from {$g5['auth_table']} a left join {$g5['member_table']} b on (a.mb_id=b.mb_id) ";
$allowed_sfl = array('a.mb_id');
if (!in_array($sfl, $allowed_sfl)) {
$sfl = 'a.mb_id';
}
$sql_search = " where (1) ";
if ($stx) {
$sql_search .= " and ( ";
switch ($sfl) {
default :
default:
$sql_search .= " ({$sfl} like '%{$stx}%') ";
break;
}
@@ -22,6 +28,9 @@ if (!$sst) {
$sst = "a.mb_id, au_menu";
$sod = "";
}
$allowed_sst = array('a.mb_id', 'mb_nick', 'au_menu', 'au_auth', 'a.mb_id, au_menu');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'a.mb_id, au_menu';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by $sst $sod ";
$sql = " select count(*) as cnt
@@ -33,7 +42,9 @@ $total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) $page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
if ($page < 1) {
$page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
}
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select *
@@ -43,10 +54,12 @@ $sql = " select *
limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall btn_ov02">전체목록</a>';
$listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall btn_ov02">전체목록</a>';
$g5['title'] = "관리권한설정";
include_once('./admin.head.php');
require_once './admin.head.php';
$assignable_auth_menu = admin_get_assignable_auth_menu();
$colspan = 5;
?>
@@ -57,213 +70,213 @@ $colspan = 5;
</div>
<form name="fsearch" id="fsearch" class="local_sch01 local_sch" method="get">
<input type="hidden" name="sfl" value="a.mb_id" id="sfl">
<input type="hidden" name="sfl" value="a.mb_id" id="sfl">
<label for="stx" class="sound_only">회원아이디<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" value="검색" id="fsearch_submit" class="btn_submit">
<label for="stx" class="sound_only">회원아이디<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" value="검색" id="fsearch_submit" class="btn_submit">
</form>
<form name="fauthlist" id="fauthlist" method="post" action="./auth_list_delete.php" onsubmit="return fauthlist_submit(this);">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">현재 페이지 회원 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('a.mb_id') ?>회원아이디</a></th>
<th scope="col"><?php echo subject_sort_link('mb_nick') ?>닉네임</a></th>
<th scope="col">메뉴</th>
<th scope="col">권한</th>
</tr>
</thead>
<tbody>
<?php
$count = 0;
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$is_continue = false;
// 회원아이디가 없는 메뉴는 삭제함
if ($row['mb_id'] == '' && $row['mb_nick'] == '') {
sql_query(" delete from {$g5['auth_table']} where au_menu = '{$row['au_menu']}' ");
$is_continue = true;
}
// 메뉴번호가 바뀌거나 권한 부여 대상이 아닌 메뉴는 삭제함
if (!isset($assignable_auth_menu[$row['au_menu']])) {
sql_query(" delete from {$g5['auth_table']} where au_menu = '{$row['au_menu']}' ");
$is_continue = true;
}
if ($is_continue) {
continue;
}
$mb_nick = get_sideview($row['mb_id'], $row['mb_nick'], $row['mb_email'], $row['mb_homepage']);
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<input type="hidden" name="au_menu[<?php echo $i ?>]" value="<?php echo $row['au_menu'] ?>">
<input type="hidden" name="mb_id[<?php echo $i ?>]" value="<?php echo $row['mb_id'] ?>">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['mb_nick'] ?>님 권한</label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_mbid"><a href="?sfl=a.mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
<td class="td_auth_mbnick"><?php echo $mb_nick ?></td>
<td class="td_menu">
<?php echo $row['au_menu'] ?>
<?php echo $assignable_auth_menu[$row['au_menu']] ?>
</td>
<td class="td_auth"><?php echo $row['au_auth'] ?></td>
</tr>
<?php
$count++;
}
if ($count == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list01 btn_list">
<input type="submit" name="act_button" value="선택삭제" onclick="document.pressed=this.value" class="btn btn_02">
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">현재 페이지 회원 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('a.mb_id') ?>회원아이디</a></th>
<th scope="col"><?php echo subject_sort_link('mb_nick') ?>닉네임</a></th>
<th scope="col">메뉴</th>
<th scope="col">권한</th>
</tr>
</thead>
<tbody>
<?php
$count = 0;
for ($i=0; $row=sql_fetch_array($result); $i++)
{
$is_continue = false;
// 회원아이디가 없는 메뉴는 삭제함
if($row['mb_id'] == '' && $row['mb_nick'] == '') {
sql_query(" delete from {$g5['auth_table']} where au_menu = '{$row['au_menu']}' ");
$is_continue = true;
}
//if (isset($stx))
// echo '<script>document.fsearch.sfl.value = "'.$sfl.'";</script>'."\n";
// 메뉴번호가 바뀌는 경우에 현재 없는 저장된 메뉴는 삭제함
if (!isset($auth_menu[$row['au_menu']]))
{
sql_query(" delete from {$g5['auth_table']} where au_menu = '{$row['au_menu']}' ");
$is_continue = true;
}
if($is_continue)
continue;
$mb_nick = get_sideview($row['mb_id'], $row['mb_nick'], $row['mb_email'], $row['mb_homepage']);
$bg = 'bg'.($i%2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<input type="hidden" name="au_menu[<?php echo $i ?>]" value="<?php echo $row['au_menu'] ?>">
<input type="hidden" name="mb_id[<?php echo $i ?>]" value="<?php echo $row['mb_id'] ?>">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['mb_nick'] ?>님 권한</label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_mbid"><a href="?sfl=a.mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
<td class="td_auth_mbnick"><?php echo $mb_nick ?></td>
<td class="td_menu">
<?php echo $row['au_menu'] ?>
<?php echo $auth_menu[$row['au_menu']] ?>
</td>
<td class="td_auth"><?php echo $row['au_auth'] ?></td>
</tr>
<?php
$count++;
if (strpos($sfl, 'mb_id') !== false) {
$mb_id = $stx;
} else {
$mb_id = '';
}
if ($count == 0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
<div class="btn_list01 btn_list">
<input type="submit" name="act_button" value="선택삭제" onclick="document.pressed=this.value" class="btn btn_02">
</div>
<?php
//if (isset($stx))
// echo '<script>document.fsearch.sfl.value = "'.$sfl.'";</script>'."\n";
if (strstr($sfl, 'mb_id'))
$mb_id = $stx;
else
$mb_id = '';
?>
</form>
<?php
$pagelist = get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, $_SERVER['SCRIPT_NAME'].'?'.$qstr.'&amp;page=');
$pagelist = get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, $_SERVER['SCRIPT_NAME'] . '?' . $qstr . '&amp;page=');
echo $pagelist;
?>
<form name="fauthlist2" id="fauthlist2" action="./auth_update.php" method="post" autocomplete="off" onsubmit="return fauth_add_submit(this);">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<section id="add_admin">
<h2 class="h2_frm">관리권한 추가</h2>
<section id="add_admin">
<h2 class="h2_frm">관리권한 추가</h2>
<div class="local_desc01 local_desc">
<p>
다음 양식에서 회원에게 관리권한을 부여하실 수 있습니다.<br>
권한 <strong>r</strong>은 읽기권한, <strong>w</strong>는 쓰기권한, <strong>d</strong>는 삭제권한입니다.
</p>
</div>
<div class="local_desc01 local_desc">
<p>
다음 양식에서 회원에게 관리권한을 부여하실 수 있습니다.<br>
권한 <strong>r</strong>은 읽기권한, <strong>w</strong>는 쓰기권한, <strong>d</strong>는 삭제권한입니다.
</p>
</div>
<div class="tbl_frm01 tbl_wrap">
<table>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="mb_id">회원아이디<strong class="sound_only">필수</strong></label></th>
<td>
<strong id="msg_mb_id" class="msg_sound_only"></strong>
<input type="text" name="mb_id" value="<?php echo $mb_id ?>" id="mb_id" required class="required frm_input">
</td>
</tr>
<tr>
<th scope="row"><label for="au_menu">접근가능메뉴<strong class="sound_only">필수</strong></label></th>
<td>
<select id="au_menu" name="au_menu" required class="required">
<option value=''>선택하세요</option>
<?php
foreach($auth_menu as $key=>$value)
{
if (!(substr($key, -3) == '000' || $key == '-' || !$key))
echo '<option value="'.$key.'">'.$key.' '.$value.'</option>';
}
?>
</select>
</td>
</tr>
<tr>
<th scope="row">권한지정</th>
<td>
<input type="checkbox" name="r" value="r" id="r" checked>
<label for="r">r (읽기)</label>
<input type="checkbox" name="w" value="w" id="w">
<label for="w">w (쓰기)</label>
<input type="checkbox" name="d" value="d" id="d">
<label for="d">d (삭제)</label>
</td>
</tr>
<tr>
<th scope="row">자동등록방지</th>
<td>
<?php
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
$captcha_html = captcha_html();
$captcha_js = chk_captcha_js();
echo $captcha_html;
?>
</td>
</tr>
</tbody>
</table>
</div>
<div class="tbl_frm01 tbl_wrap">
<table>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="mb_id">회원아이디<strong class="sound_only">필수</strong></label></th>
<td>
<strong id="msg_mb_id" class="msg_sound_only"></strong>
<input type="text" name="mb_id" value="<?php echo $mb_id ?>" id="mb_id" required class="required frm_input">
</td>
</tr>
<tr>
<th scope="row"><label for="au_menu">접근가능메뉴<strong class="sound_only">필수</strong></label></th>
<td>
<select id="au_menu" name="au_menu" required class="required">
<option value=''>선택하세요</option>
<?php
foreach ($assignable_auth_menu as $key => $value) {
if (!(substr($key, -3) == '000' || $key == '-' || !$key)) {
echo '<option value="' . $key . '">' . $key . ' ' . $value . '</option>';
}
}
?>
</select>
</td>
</tr>
<tr>
<th scope="row">권한지정</th>
<td>
<input type="checkbox" name="r" value="r" id="r" checked>
<label for="r">r (읽기)</label>
<input type="checkbox" name="w" value="w" id="w">
<label for="w">w (쓰기)</label>
<input type="checkbox" name="d" value="d" id="d">
<label for="d">d (삭제)</label>
</td>
</tr>
<tr>
<th scope="row">자동등록방지</th>
<td>
<?php
require_once G5_CAPTCHA_PATH . '/captcha.lib.php';
$captcha_html = captcha_html();
$captcha_js = chk_captcha_js();
echo $captcha_html;
?>
</td>
</tr>
</tbody>
</table>
</div>
<div class="btn_confirm01 btn_confirm">
<input type="submit" value="추가" class="btn_submit btn">
</div>
</section>
<div class="btn_confirm01 btn_confirm">
<input type="submit" value="추가" class="btn_submit btn">
</div>
</section>
</form>
<script>
function fauth_add_submit(f){
<?php echo $captcha_js; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
function fauth_add_submit(f) {
return true;
}
<?php echo $captcha_js; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
function fauthlist_submit(f)
{
if (!is_checked("chk[]")) {
alert(document.pressed+" 하실 항목을 하나 이상 선택하세요.");
return false;
return true;
}
if(document.pressed == "선택삭제") {
if(!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
function fauthlist_submit(f) {
if (!is_checked("chk[]")) {
alert(document.pressed + " 하실 항목을 하나 이상 선택하세요.");
return false;
}
}
return true;
}
if (document.pressed == "선택삭제") {
if (!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
return false;
}
}
return true;
}
</script>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+11 -10
View File
@@ -1,36 +1,37 @@
<?php
$sub_menu = "100200";
include_once('./_common.php');
require_once './_common.php';
check_demo();
if ($is_admin != 'super')
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
check_admin_token();
$count = (isset($_POST['chk']) && is_array($_POST['chk'])) ? count($_POST['chk']) : 0;
$post_act_button = isset($_POST['act_button']) ? clean_xss_tags($_POST['act_button'], 1, 1) : '';
if (!$count)
alert($_POST['act_button']." 하실 항목을 하나 이상 체크하세요.");
if (!$count) {
alert($_POST['act_button'] . " 하실 항목을 하나 이상 체크하세요.");
}
if ( (isset($_POST['mb_id']) && ! is_array($_POST['mb_id'])) || (isset($_POST['au_menu']) && ! is_array($_POST['au_menu'])) ){
if ((isset($_POST['mb_id']) && !is_array($_POST['mb_id'])) || (isset($_POST['au_menu']) && !is_array($_POST['au_menu']))) {
alert("잘못된 요청입니다.");
}
for ($i=0; $i<$count; $i++)
{
for ($i = 0; $i < $count; $i++) {
// 실제 번호를 넘김
$k = isset($_POST['chk'][$i]) ? (int) $_POST['chk'][$i] : 0;
$mb_id = isset($_POST['mb_id'][$k]) ? preg_replace('/[^a-zA-Z0-9_]/', '', $_POST['mb_id'][$k]) : '';
$au_menu = isset($_POST['au_menu'][$k]) ? preg_replace('/[^a-zA-Z0-9_]/', '', $_POST['au_menu'][$k]) : '';
$sql = " delete from {$g5['auth_table']} where mb_id = '".$mb_id."' and au_menu = '".$au_menu."' ";
$sql = " delete from {$g5['auth_table']} where mb_id = '" . $mb_id . "' and au_menu = '" . $au_menu . "' ";
sql_query($sql);
run_event('adm_auth_delete_member', $mb_id, $au_menu);
}
goto_url('./auth_list.php?'.$qstr);
goto_url('./auth_list.php?' . $qstr);
+17 -10
View File
@@ -1,23 +1,30 @@
<?php
$sub_menu = "100200";
include_once('./_common.php');
include_once(G5_LIB_PATH.'/mailer.lib.php');
require_once './_common.php';
require_once G5_LIB_PATH . '/mailer.lib.php';
$au_menu = isset($_POST['au_menu']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['au_menu']) : '';
$post_r = isset($_POST['r']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['r']) : '';
$post_w = isset($_POST['w']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['w']) : '';
$post_d = isset($_POST['d']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['d']) : '';
if ($is_admin != 'super')
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
$mb = get_member($mb_id);
if (!$mb['mb_id'])
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
alert('존재하는 회원아이디가 아닙니다.');
}
check_admin_token();
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
$assignable_auth_menu = admin_get_assignable_auth_menu();
if (!$au_menu || !isset($assignable_auth_menu[$au_menu])) {
alert('해당 메뉴는 관리권한을 부여할 수 없습니다.');
}
require_once G5_CAPTCHA_PATH . '/captcha.lib.php';
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
@@ -27,7 +34,7 @@ $sql = " insert into {$g5['auth_table']}
set mb_id = '$mb_id',
au_menu = '$au_menu',
au_auth = '{$post_r},{$post_w},{$post_d}' ";
$result = sql_query($sql, FALSE);
$result = sql_query($sql, false);
if (!$result) {
$sql = " update {$g5['auth_table']}
set au_auth = '{$post_r},{$post_w},{$post_d}'
@@ -39,15 +46,15 @@ if (!$result) {
//sql_query(" OPTIMIZE TABLE `$g5['auth_table']` ");
// 세션을 체크하여 하루에 한번만 메일알림이 가게 합니다.
if( str_replace('-', '', G5_TIME_YMD) !== get_session('adm_auth_update') ){
if (str_replace('-', '', G5_TIME_YMD) !== get_session('adm_auth_update')) {
$site_url = preg_replace('/^www\./', '', strtolower($_SERVER['SERVER_NAME']));
$to_email = 'gnuboard@'.$site_url;
$to_email = 'gnuboard@' . $site_url;
mailer($config['cf_admin_email_name'], $to_email, $config['cf_admin_email'], '['.$config['cf_title'].'] 관리권한설정 알림', '<p><b>['.$config['cf_title'].'] 관리권한설정 변경 안내</b></p><p style="padding-top:1em">회원 아이디 '.$mb['mb_id'].' 에 관리권한이 추가 되었습니다.</p><p style="padding-top:1em">'.G5_TIME_YMDHIS.'</p><p style="padding-top:1em"><a href="'.G5_URL.'" target="_blank">'.$config['cf_title'].'</a></p>', 1);
mailer($config['cf_admin_email_name'], $to_email, $config['cf_admin_email'], '[' . $config['cf_title'] . '] 관리권한설정 알림', '<p><b>[' . $config['cf_title'] . '] 관리권한설정 변경 안내</b></p><p style="padding-top:1em">회원 아이디 ' . $mb['mb_id'] . ' 에 관리권한이 추가 되었습니다.</p><p style="padding-top:1em">' . G5_TIME_YMDHIS . '</p><p style="padding-top:1em"><a href="' . G5_URL . '" target="_blank">' . $config['cf_title'] . '</a></p>', 1);
set_session('adm_auth_update', str_replace('-', '', G5_TIME_YMD));
}
run_event('adm_auth_update', $mb);
goto_url('./auth_list.php?'.$qstr);
goto_url('./auth_list.php?' . $qstr);
+65 -59
View File
@@ -1,85 +1,91 @@
<?php
$sub_menu = "300100";
include_once("./_common.php");
require_once "./_common.php";
auth_check_menu($auth, $sub_menu, 'w');
$g5['title'] = '게시판 복사';
include_once(G5_PATH.'/head.sub.php');
?>
require_once G5_PATH . '/head.sub.php';
<script src="<?php echo G5_ADMIN_URL ?>/admin.js?ver=<?php echo G5_JS_VER; ?>"></script>
if (empty($bo_table)) {
alert_close("정상적인 방법으로 이용해주세요.");
}
?>
<script>
var g5_admin_csrf_token_key = "<?php echo (function_exists('admin_csrf_token_key')) ? admin_csrf_token_key() : ''; ?>";
</script>
<script src="<?php echo get_versioned_asset_url(G5_ADMIN_URL.'/admin.js'); ?>"></script>
<div class="new_win">
<h1><?php echo $g5['title']; ?></h1>
<form name="fboardcopy" id="fboardcopy" action="./board_copy_update.php" onsubmit="return fboardcopy_check(this);" method="post">
<input type="hidden" name="bo_table" value="<?php echo $bo_table ?>" id="bo_table">
<input type="hidden" name="token" value="">
<div class=" new_win_con">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<tbody>
<tr>
<th scope="col">원본 테이블명</th>
<td><?php echo $bo_table ?></td>
</tr>
<tr>
<th scope="col"><label for="target_table">복사 테이블명<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="target_table" id="target_table" required class="required alnum_ frm_input" maxlength="20">영문자, 숫자, _ 만 가능 (공백없이)</td>
</tr>
<tr>
<th scope="col"><label for="target_subject">게시판 제목<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="target_subject" value="[복사본] <?php echo get_sanitize_input($board['bo_subject']); ?>" id="target_subject" required class="required frm_input" maxlength="120"></td>
</tr>
<tr>
<th scope="col">복사 유형</th>
<td>
<input type="radio" name="copy_case" value="schema_only" id="copy_case" checked>
<label for="copy_case">구조만</label>
<input type="radio" name="copy_case" value="schema_data_both" id="copy_case2">
<label for="copy_case2">구조와 데이터</label>
</td>
</tr>
</tbody>
</table>
<input type="hidden" name="bo_table" value="<?php echo $bo_table ?>" id="bo_table">
<input type="hidden" name="token" value="">
<div class=" new_win_con">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<tbody>
<tr>
<th scope="col">원본 테이블명</th>
<td><?php echo $bo_table ?></td>
</tr>
<tr>
<th scope="col"><label for="target_table">복사 테이블명<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="target_table" id="target_table" required class="required alnum_ frm_input" maxlength="20">영문자, 숫자, _ 만 가능 (공백없이)</td>
</tr>
<tr>
<th scope="col"><label for="target_subject">게시판 제목<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="target_subject" value="[복사본] <?php echo get_sanitize_input($board['bo_subject']); ?>" id="target_subject" required class="required frm_input" maxlength="120"></td>
</tr>
<tr>
<th scope="col">복사 유형</th>
<td>
<input type="radio" name="copy_case" value="schema_only" id="copy_case" checked>
<label for="copy_case">구조만</label>
<input type="radio" name="copy_case" value="schema_data_both" id="copy_case2">
<label for="copy_case2">구조와 데이터</label>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="win_btn ">
<input type="submit" class="btn_submit btn" value="복사">
<input type="button" class="btn_close btn" value="창닫기" onclick="window.close();">
</div>
</div>
<div class="win_btn ">
<input type="submit" class="btn_submit btn" value="복사">
<input type="button" class="btn_close btn" value="창닫기" onclick="window.close();">
</div>
</form>
</div>
<script>
function fboardcopy_check(f)
{
<?php
if(!$w){
$js_array = get_bo_table_banned_word();
echo "var banned_array = ". json_encode($js_array) . ";\n";
}
?>
function fboardcopy_check(f) {
<?php
// 게시판명이 금지된 단어로 되어 있으면
if( (typeof banned_array != 'undefined') && jQuery.inArray(f.target_table.value, banned_array) !== -1 ){
alert("입력한 게시판 TABLE명을 사용할수 없습니다. 다른 이름으로 입력해 주세요.");
return false;
}
if (!$w) {
$js_array = get_bo_table_banned_word();
echo "var banned_array = " . json_encode($js_array) . ";\n";
}
?>
if (f.bo_table.value == f.target_table.value) {
alert("원본 테이블명과 복사할 테이블명이 달라야 합니다.");
return false;
}
// 게시판명이 금지된 단어로 되어 있으면
if ((typeof banned_array != 'undefined') && jQuery.inArray(f.target_table.value, banned_array) !== -1) {
alert("입력한 게시판 TABLE명을 사용할수 없습니다. 다른 이름으로 입력해 주세요.");
return false;
}
return true;
}
if (f.bo_table.value == f.target_table.value) {
alert("원본 테이블명과 복사할 테이블명이 달라야 합니다.");
return false;
}
return true;
}
</script>
<?php
include_once(G5_PATH.'/tail.sub.php');
require_once G5_PATH . '/tail.sub.php';
+73 -63
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = '300100';
include_once('./_common.php');
require_once './_common.php';
check_demo();
@@ -8,31 +8,39 @@ auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
$bo_table = isset($_POST['bo_table']) ? substr(preg_replace('/[^a-z0-9_]/i', '', $_POST['bo_table']), 0, 20) : null;
$target_table = isset($_POST['target_table']) ? trim($_POST['target_table']) : '';
$target_subject = isset($_POST['target_subject']) ? trim($_POST['target_subject']) : '';
$target_subject = strip_tags(clean_xss_attributes($target_subject));
$target_subject = addslashes(strip_tags(clean_xss_attributes(stripslashes($target_subject))));
$file_copy = array();
if (empty($bo_table)) {
alert("원본 테이블 정보가 없습니다.");
}
if (!preg_match('/[A-Za-z0-9_]{1,20}/', $target_table)) {
alert('게시판 TABLE명은 공백없이 영문자, 숫자, _ 만 사용 가능합니다. (20자 이내)');
}
$target_table = substr(preg_replace('/[^a-z0-9_]/i', '', $target_table), 0, 20);
// 게시판명이 금지된 단어로 되어 있으면
if ( $w == '' && in_array($target_table, get_bo_table_banned_word()) ){
if ($w == '' && in_array($target_table, get_bo_table_banned_word())) {
alert('입력한 게시판 TABLE명을 사용할수 없습니다. 다른 이름으로 입력해 주세요.');
}
$row = sql_fetch(" select count(*) as cnt from {$g5['board_table']} where bo_table = '$target_table' ");
if ($row['cnt'])
alert($target_table.'은(는) 이미 존재하는 게시판 테이블명 입니다.\\n복사할 테이블명으로 사용할 수 없습니다.');
if ($row['cnt']) {
alert($target_table . '은(는) 이미 존재하는 게시판 테이블명 입니다.\\n복사할 테이블명으로 사용할 수 없습니다.');
}
// 게시판 테이블 생성
$sql = get_table_define($g5['write_prefix'] . $bo_table);
$sql = str_replace($g5['write_prefix'] . $bo_table, $g5['write_prefix'] . $target_table, $sql);
sql_query($sql, false);
$file_copy = array();
// 구조만 복사시에는 공지사항 번호는 복사하지 않는다.
if ($copy_case == 'schema_only') {
$board['bo_notice'] = '';
@@ -83,15 +91,15 @@ $sql = " insert into {$g5['board_table']}
bo_new = '{$board['bo_new']}',
bo_hot = '{$board['bo_hot']}',
bo_image_width = '{$board['bo_image_width']}',
bo_skin = '{$board['bo_skin']}',
bo_mobile_skin = '{$board['bo_mobile_skin']}',
bo_include_head = '{$board['bo_include_head']}',
bo_include_tail = '{$board['bo_include_tail']}',
bo_content_head = '".addslashes($board['bo_content_head'])."',
bo_content_tail = '".addslashes($board['bo_content_tail'])."',
bo_mobile_content_head = '".addslashes($board['bo_mobile_content_head'])."',
bo_mobile_content_tail = '".addslashes($board['bo_mobile_content_tail'])."',
bo_insert_content = '".addslashes($board['bo_insert_content'])."',
bo_skin = '" . sql_real_escape_string($board['bo_skin']). "',
bo_mobile_skin = '" . sql_real_escape_string($board['bo_mobile_skin']). "',
bo_include_head = '" . sql_real_escape_string($board['bo_include_head']). "',
bo_include_tail = '" . sql_real_escape_string($board['bo_include_tail']). "',
bo_content_head = '" . addslashes($board['bo_content_head']) . "',
bo_content_tail = '" . addslashes($board['bo_content_tail']) . "',
bo_mobile_content_head = '" . addslashes($board['bo_mobile_content_head']) . "',
bo_mobile_content_tail = '" . addslashes($board['bo_mobile_content_tail']) . "',
bo_insert_content = '" . addslashes($board['bo_insert_content']) . "',
bo_gallery_cols = '{$board['bo_gallery_cols']}',
bo_gallery_width = '{$board['bo_gallery_width']}',
bo_gallery_height = '{$board['bo_gallery_height']}',
@@ -108,34 +116,34 @@ $sql = " insert into {$g5['board_table']}
bo_use_sns = '{$board['bo_use_sns']}',
bo_use_captcha = '{$board['bo_use_captcha']}',
bo_sort_field = '{$board['bo_sort_field']}',
bo_1_subj = '".addslashes($board['bo_1_subj'])."',
bo_2_subj = '".addslashes($board['bo_2_subj'])."',
bo_3_subj = '".addslashes($board['bo_3_subj'])."',
bo_4_subj = '".addslashes($board['bo_4_subj'])."',
bo_5_subj = '".addslashes($board['bo_5_subj'])."',
bo_6_subj = '".addslashes($board['bo_6_subj'])."',
bo_7_subj = '".addslashes($board['bo_7_subj'])."',
bo_8_subj = '".addslashes($board['bo_8_subj'])."',
bo_9_subj = '".addslashes($board['bo_9_subj'])."',
bo_10_subj = '".addslashes($board['bo_10_subj'])."',
bo_1 = '".addslashes($board['bo_1'])."',
bo_2 = '".addslashes($board['bo_2'])."',
bo_3 = '".addslashes($board['bo_3'])."',
bo_4 = '".addslashes($board['bo_4'])."',
bo_5 = '".addslashes($board['bo_5'])."',
bo_6 = '".addslashes($board['bo_6'])."',
bo_7 = '".addslashes($board['bo_7'])."',
bo_8 = '".addslashes($board['bo_8'])."',
bo_9 = '".addslashes($board['bo_9'])."',
bo_10 = '".addslashes($board['bo_10'])."' ";
bo_1_subj = '" . addslashes($board['bo_1_subj']) . "',
bo_2_subj = '" . addslashes($board['bo_2_subj']) . "',
bo_3_subj = '" . addslashes($board['bo_3_subj']) . "',
bo_4_subj = '" . addslashes($board['bo_4_subj']) . "',
bo_5_subj = '" . addslashes($board['bo_5_subj']) . "',
bo_6_subj = '" . addslashes($board['bo_6_subj']) . "',
bo_7_subj = '" . addslashes($board['bo_7_subj']) . "',
bo_8_subj = '" . addslashes($board['bo_8_subj']) . "',
bo_9_subj = '" . addslashes($board['bo_9_subj']) . "',
bo_10_subj = '" . addslashes($board['bo_10_subj']) . "',
bo_1 = '" . addslashes($board['bo_1']) . "',
bo_2 = '" . addslashes($board['bo_2']) . "',
bo_3 = '" . addslashes($board['bo_3']) . "',
bo_4 = '" . addslashes($board['bo_4']) . "',
bo_5 = '" . addslashes($board['bo_5']) . "',
bo_6 = '" . addslashes($board['bo_6']) . "',
bo_7 = '" . addslashes($board['bo_7']) . "',
bo_8 = '" . addslashes($board['bo_8']) . "',
bo_9 = '" . addslashes($board['bo_9']) . "',
bo_10 = '" . addslashes($board['bo_10']) . "' ";
sql_query($sql, false);
// 게시판 폴더 생성
@mkdir(G5_DATA_PATH.'/file/'.$target_table, G5_DIR_PERMISSION);
@chmod(G5_DATA_PATH.'/file/'.$target_table, G5_DIR_PERMISSION);
@mkdir(G5_DATA_PATH . '/file/' . $target_table, G5_DIR_PERMISSION);
@chmod(G5_DATA_PATH . '/file/' . $target_table, G5_DIR_PERMISSION);
// 디렉토리에 있는 파일의 목록을 보이지 않게 한다.
$board_path = G5_DATA_PATH.'/file/'.$target_table;
$board_path = G5_DATA_PATH . '/file/' . $target_table;
$file = $board_path . '/index.php';
$f = @fopen($file, 'w');
@fwrite($f, '');
@@ -144,31 +152,34 @@ $f = @fopen($file, 'w');
$copy_file = 0;
if ($copy_case == 'schema_data_both') {
$d = dir(G5_DATA_PATH.'/file/'.$bo_table);
$d = dir(G5_DATA_PATH . '/file/' . $bo_table);
while ($entry = $d->read()) {
if ($entry == '.' || $entry == '..') continue;
if ($entry == '.' || $entry == '..') {
continue;
}
// 김선용 201007 :
if(is_dir(G5_DATA_PATH.'/file/'.$bo_table.'/'.$entry)){
$dd = dir(G5_DATA_PATH.'/file/'.$bo_table.'/'.$entry);
@mkdir(G5_DATA_PATH.'/file/'.$target_table.'/'.$entry, G5_DIR_PERMISSION);
@chmod(G5_DATA_PATH.'/file/'.$target_table.'/'.$entry, G5_DIR_PERMISSION);
if (is_dir(G5_DATA_PATH . '/file/' . $bo_table . '/' . $entry)) {
$dd = dir(G5_DATA_PATH . '/file/' . $bo_table . '/' . $entry);
@mkdir(G5_DATA_PATH . '/file/' . $target_table . '/' . $entry, G5_DIR_PERMISSION);
@chmod(G5_DATA_PATH . '/file/' . $target_table . '/' . $entry, G5_DIR_PERMISSION);
while ($entry2 = $dd->read()) {
if ($entry2 == '.' || $entry2 == '..') continue;
@copy(G5_DATA_PATH.'/file/'.$bo_table.'/'.$entry.'/'.$entry2, G5_DATA_PATH.'/file/'.$target_table.'/'.$entry.'/'.$entry2);
@chmod(G5_DATA_PATH.'/file/'.$target_table.'/'.$entry.'/'.$entry2, G5_DIR_PERMISSION);
if ($entry2 == '.' || $entry2 == '..') {
continue;
}
@copy(G5_DATA_PATH . '/file/' . $bo_table . '/' . $entry . '/' . $entry2, G5_DATA_PATH . '/file/' . $target_table . '/' . $entry . '/' . $entry2);
@chmod(G5_DATA_PATH . '/file/' . $target_table . '/' . $entry . '/' . $entry2, G5_DIR_PERMISSION);
$copy_file++;
}
$dd->close();
}
else {
@copy(G5_DATA_PATH.'/file/'.$bo_table.'/'.$entry, G5_DATA_PATH.'/file/'.$target_table.'/'.$entry);
@chmod(G5_DATA_PATH.'/file/'.$target_table.'/'.$entry, G5_DIR_PERMISSION);
} else {
@copy(G5_DATA_PATH . '/file/' . $bo_table . '/' . $entry, G5_DATA_PATH . '/file/' . $target_table . '/' . $entry);
@chmod(G5_DATA_PATH . '/file/' . $target_table . '/' . $entry, G5_DIR_PERMISSION);
$copy_file++;
}
}
$d->close();
run_event('admin_board_copy_file', $bo_table, $target_table);
// 글복사
@@ -182,29 +193,28 @@ if ($copy_case == 'schema_data_both') {
sql_query($sql, false);
// 4.00.01
// 위의 코드는 같은 테이블명을 사용하였다는 오류가 발생함. (희한하네 ㅡㅡ;)
$sql = " select * from {$g5['board_file_table']} where bo_table = '$bo_table' ";
$result = sql_query($sql, false);
for ($i=0; $row=sql_fetch_array($result); $i++)
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$file_copy[$i] = $row;
}
}
if (count($file_copy)) {
for ($i=0; $i<count($file_copy); $i++) {
for ($i = 0; $i < count($file_copy); $i++) {
$file_copy[$i] = run_replace('admin_copy_update_file', $file_copy[$i], $file_copy[$i]['bf_file'], $bo_table, $target_table);
$sql = " insert into {$g5['board_file_table']}
set bo_table = '$target_table',
wr_id = '{$file_copy[$i]['wr_id']}',
bf_no = '{$file_copy[$i]['bf_no']}',
bf_source = '".addslashes($file_copy[$i]['bf_source'])."',
bf_source = '" . addslashes($file_copy[$i]['bf_source']) . "',
bf_file = '{$file_copy[$i]['bf_file']}',
bf_download = '{$file_copy[$i]['bf_download']}',
bf_content = '".addslashes($file_copy[$i]['bf_content'])."',
bf_fileurl = '".addslashes($file_copy[$i]['bf_fileurl'])."',
bf_thumburl = '".addslashes($file_copy[$i]['bf_thumburl'])."',
bf_storage = '".addslashes($file_copy[$i]['bf_storage'])."',
bf_content = '" . addslashes($file_copy[$i]['bf_content']) . "',
bf_fileurl = '" . addslashes($file_copy[$i]['bf_fileurl']) . "',
bf_thumburl = '" . addslashes($file_copy[$i]['bf_thumburl']) . "',
bf_storage = '" . addslashes($file_copy[$i]['bf_storage']) . "',
bf_filesize = '{$file_copy[$i]['bf_filesize']}',
bf_width = '{$file_copy[$i]['bf_width']}',
bf_height = '{$file_copy[$i]['bf_height']}',
@@ -220,4 +230,4 @@ delete_cache_latest($target_table);
echo "<script>opener.document.location.reload();</script>";
alert("복사에 성공 했습니다.", './board_copy.php?bo_table='.$bo_table.'&amp;'.$qstr);
alert("복사에 성공 했습니다.", './board_copy.php?bo_table=' . $bo_table . '&amp;' . $qstr);
+12 -5
View File
@@ -1,11 +1,18 @@
<?php
// board_delete.php , boardgroup_delete.php 에서 include 하는 파일
if (!defined('_GNUBOARD_')) exit;
if (!defined('_BOARD_DELETE_')) exit; // 개별 페이지 접근 불가
// 개별 페이지 접근 불가
if (!defined('_GNUBOARD_')) {
exit;
}
if (!defined('_BOARD_DELETE_')) {
exit;
}
// $tmp_bo_table 에는 $bo_table 값을 넘겨주어야 함
if (!$tmp_bo_table) { return; }
if (!$tmp_bo_table) {
return;
}
// 게시판 1개는 삭제 불가 (게시판 복사를 위해서)
//$row = sql_fetch(" select count(*) as cnt from $g5['board_table'] ");
@@ -24,7 +31,7 @@ sql_query(" delete from {$g5['scrap_table']} where bo_table = '{$tmp_bo_table}'
sql_query(" delete from {$g5['board_file_table']} where bo_table = '{$tmp_bo_table}' ");
// 게시판 테이블 DROP
sql_query(" drop table {$g5['write_prefix']}{$tmp_bo_table} ", FALSE);
sql_query(" drop table {$g5['write_prefix']}{$tmp_bo_table} ", false);
// 좋아요 테이블에서 기록 삭제
sql_query(" delete from {$g5['board_good_table']} where bo_table = '{$tmp_bo_table}' ");
@@ -32,4 +39,4 @@ sql_query(" delete from {$g5['board_good_table']} where bo_table = '{$tmp_bo_tab
delete_cache_latest($tmp_bo_table);
// 게시판 폴더 전체 삭제
rm_rf(G5_DATA_PATH.'/file/'.$tmp_bo_table);
rm_rf(G5_DATA_PATH . '/file/' . $tmp_bo_table);
+44 -96
View File
@@ -1,88 +1,32 @@
<?php
$sub_menu = "300100";
include_once('./_common.php');
include_once(G5_EDITOR_LIB);
require_once './_common.php';
require_once G5_EDITOR_LIB;
auth_check_menu($auth, $sub_menu, 'w');
$sql = " select count(*) as cnt from {$g5['group_table']} ";
$row = sql_fetch($sql);
if (!$row['cnt'])
if (!$row['cnt']) {
alert('게시판그룹이 한개 이상 생성되어야 합니다.', './boardgroup_form.php');
}
$html_title = '게시판';
if (!isset($board['bo_device'])) {
// 게시판 사용 필드 추가
// both : pc, mobile 둘다 사용
// pc : pc 전용 사용
// mobile : mobile 전용 사용
// none : 사용 안함
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_device` ENUM( 'both', 'pc', 'mobile' ) NOT NULL DEFAULT 'both' AFTER `bo_subject` ", false);
}
if (!isset($board['bo_mobile_skin'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_mobile_skin` VARCHAR(255) NOT NULL DEFAULT '' AFTER `bo_skin` ", false);
}
if (!isset($board['bo_gallery_width'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_gallery_width` INT NOT NULL AFTER `bo_gallery_cols`, ADD `bo_gallery_height` INT NOT NULL DEFAULT '0' AFTER `bo_gallery_width`, ADD `bo_mobile_gallery_width` INT NOT NULL DEFAULT '0' AFTER `bo_gallery_height`, ADD `bo_mobile_gallery_height` INT NOT NULL DEFAULT '0' AFTER `bo_mobile_gallery_width` ", false);
}
if (!isset($board['bo_mobile_subject_len'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_mobile_subject_len` INT(11) NOT NULL DEFAULT '0' AFTER `bo_subject_len` ", false);
}
if (!isset($board['bo_mobile_page_rows'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_mobile_page_rows` INT(11) NOT NULL DEFAULT '0' AFTER `bo_page_rows` ", false);
}
if (!isset($board['bo_mobile_content_head'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_mobile_content_head` TEXT NOT NULL AFTER `bo_content_head`, ADD `bo_mobile_content_tail` TEXT NOT NULL AFTER `bo_content_tail`", false);
}
if (!isset($board['bo_use_cert'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_use_cert` ENUM('','cert','adult') NOT NULL DEFAULT '' AFTER `bo_use_email` ", false);
}
if (!isset($board['bo_use_sns'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_use_sns` TINYINT NOT NULL DEFAULT '0' AFTER `bo_use_cert` ", false);
$result = sql_query(" select bo_table from `{$g5['board_table']}` ");
for ($i=0; $row=sql_fetch_array($result); $i++) {
sql_query(" ALTER TABLE `{$g5['write_prefix']}{$row['bo_table']}`
ADD `wr_facebook_user` VARCHAR(255) NOT NULL DEFAULT '' AFTER `wr_ip`,
ADD `wr_twitter_user` VARCHAR(255) NOT NULL DEFAULT '' AFTER `wr_facebook_user` ", false);
}
}
$sql = " SHOW COLUMNS FROM `{$g5['board_table']}` LIKE 'bo_use_cert' ";
$row = sql_fetch($sql);
if(strpos($row['Type'], 'hp-') === false) {
sql_query(" ALTER TABLE `{$g5['board_table']}` CHANGE `bo_use_cert` `bo_use_cert` ENUM('','cert','adult','hp-cert','hp-adult') NOT NULL DEFAULT '' ", false);
}
if (!isset($board['bo_use_list_file'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_use_list_file` TINYINT NOT NULL DEFAULT '0' AFTER `bo_use_list_view` ", false);
$result = sql_query(" select bo_table from `{$g5['board_table']}` ");
for ($i=0; $row=sql_fetch_array($result); $i++) {
sql_query(" ALTER TABLE `{$g5['write_prefix']}{$row['bo_table']}`
ADD `wr_file` TINYINT NOT NULL DEFAULT '0' AFTER `wr_datetime` ", false);
}
}
if (!isset($board['bo_mobile_subject'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_mobile_subject` VARCHAR(255) NOT NULL DEFAULT '' AFTER `bo_subject` ", false);
}
if (!isset($board['bo_use_captcha'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_use_captcha` TINYINT NOT NULL DEFAULT '0' AFTER `bo_use_sns` ", false);
}
if (!isset($board['bo_select_editor'])) {
sql_query(" ALTER TABLE `{$g5['board_table']}` ADD `bo_select_editor` VARCHAR(50) NOT NULL DEFAULT '' AFTER `bo_use_dhtml_editor` ", false);
}
$board_default = array(
'bo_mobile_subject'=>'',
@@ -128,7 +72,7 @@ $board_default = array(
'bo_sort_field'=>'',
);
for($i=0;$i<=10;$i++){
for ($i = 0; $i <= 10; $i++) {
$board_default['bo_'.$i.'_subj'] = '';
$board_default['bo_'.$i] = '';
}
@@ -142,7 +86,6 @@ $readonly = "";
$sound_only = "";
$required_valid = "";
if ($w == '') {
$html_title .= ' 생성';
$required = 'required';
@@ -179,21 +122,20 @@ if ($w == '') {
$board['bo_use_secret'] = 0;
$board['bo_include_head'] = '_head.php';
$board['bo_include_tail'] = '_tail.php';
} else if ($w == 'u') {
} elseif ($w == 'u') {
$html_title .= ' 수정';
if (!$board['bo_table'])
if (!$board['bo_table']) {
alert('존재하지 않은 게시판 입니다.');
}
if ($is_admin == 'group') {
if ($member['mb_id'] != $group['gr_admin'])
if ($member['mb_id'] != $group['gr_admin']) {
alert('그룹이 틀립니다.');
}
}
$readonly = 'readonly';
}
if ($is_admin != 'super') {
@@ -202,7 +144,7 @@ if ($is_admin != 'super') {
}
$g5['title'] = $html_title;
include_once ('./admin.head.php');
require_once './admin.head.php';
$pg_anchor = '<ul class="anchor">
<li><a href="#anc_bo_basic">기본 설정</a></li>
@@ -253,7 +195,9 @@ $pg_anchor = '<ul class="anchor">
<th scope="row"><label for="gr_id">그룹<strong class="sound_only">필수</strong></label></th>
<td colspan="2">
<?php echo get_group_select('gr_id', $board['gr_id'], 'required'); ?>
<?php if ($w=='u') { ?><a href="javascript:document.location.href='./board_list.php?sfl=a.gr_id&stx='+document.fboardform.gr_id.value;" class="btn_frmline">동일그룹 게시판목록</a><?php } ?>
<?php if ($w=='u') { ?>
<a href="javascript:document.location.href='./board_list.php?sfl=a.gr_id&stx='+document.fboardform.gr_id.value;" class="btn_frmline">동일그룹 게시판목록</a>
<?php } ?>
</td>
</tr>
<tr>
@@ -548,7 +492,9 @@ $pg_anchor = '<ul class="anchor">
<?php
$arr = get_skin_dir('', G5_EDITOR_PATH);
for ($i=0; $i<count($arr); $i++) {
if ($i == 0) echo "<option value=\"\">기본환경설정의 에디터 사용</option>";
if ($i == 0) {
echo "<option value=\"\">기본환경설정의 에디터 사용</option>";
}
echo "<option value=\"".$arr[$i]."\"".get_selected($board['bo_select_editor'], $arr[$i]).">".$arr[$i]."</option>\n";
}
?>
@@ -701,12 +647,10 @@ $pg_anchor = '<ul class="anchor">
<?php echo help("본인확인 여부에 따라 게시물을 조회 할 수 있도록 합니다."); ?>
<select id="bo_use_cert" name="bo_use_cert">
<?php
echo option_selected("", $board['bo_use_cert'], "사용안함");
echo option_selected("", $board['bo_use_cert'], "사용안함");
if ($config['cf_cert_use']) {
echo option_selected("cert", $board['bo_use_cert'], "본인확인된 회원전체");
echo option_selected("cert", $board['bo_use_cert'], "본인확인된 회원전체");
echo option_selected("adult", $board['bo_use_cert'], "본인확인된 성인회원만");
echo option_selected("hp-cert", $board['bo_use_cert'], "휴대폰 본인확인된 회원전체");
echo option_selected("hp-adult", $board['bo_use_cert'], "휴대폰 본인확인된 성인회원만");
}
?>
</select>
@@ -905,11 +849,11 @@ $pg_anchor = '<ul class="anchor">
<label for="chk_all_mobile_skin">전체적용</label>
</td>
</tr>
<?php if ($is_admin === 'super'){ // 슈퍼관리자인 경우에만 수정 가능 ?>
<?php if ($is_admin === 'super') { // 슈퍼관리자인 경우에만 수정 가능 ?>
<tr>
<th scope="row"><label for="bo_include_head">상단 파일 경로</label></th>
<td>
<input type="text" name="bo_include_head" value="<?php echo $board['bo_include_head'] ?>" id="bo_include_head" class="frm_input" size="50">
<input type="text" name="bo_include_head" value="<?php echo get_sanitize_input($board['bo_include_head']); ?>" id="bo_include_head" class="frm_input" size="50">
</td>
<td class="td_grpset">
<input type="checkbox" name="chk_grp_include_head" value="1" id="chk_grp_include_head">
@@ -921,7 +865,7 @@ $pg_anchor = '<ul class="anchor">
<tr>
<th scope="row"><label for="bo_include_tail">하단 파일 경로</label></th>
<td>
<input type="text" name="bo_include_tail" value="<?php echo $board['bo_include_tail'] ?>" id="bo_include_tail" class="frm_input" size="50">
<input type="text" name="bo_include_tail" value="<?php echo get_sanitize_input($board['bo_include_tail']); ?>" id="bo_include_tail" class="frm_input" size="50">
</td>
<td class="td_grpset">
<input type="checkbox" name="chk_grp_include_tail" value="1" id="chk_grp_include_tail">
@@ -936,7 +880,7 @@ $pg_anchor = '<ul class="anchor">
<?php
echo help("파일 경로를 입력 또는 수정시 캡챠를 반드시 입력해야 합니다.");
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
include_once G5_CAPTCHA_PATH.'/captcha.lib.php';
$captcha_html = captcha_html();
$captcha_js = chk_captcha_js();
echo $captcha_html;
@@ -1194,17 +1138,16 @@ $pg_anchor = '<ul class="anchor">
<td>
<?php echo help('리스트에서 기본으로 정렬에 사용할 필드를 선택합니다. "기본"으로 사용하지 않으시는 경우 속도가 느려질 수 있습니다.') ?>
<select id="bo_sort_field" name="bo_sort_field">
<?php foreach( get_board_sort_fields($board) as $v ){
<?php foreach (get_board_sort_fields($board) as $v) {
$option_value = $order_by_str = $v[0];
if( $v[0] === 'wr_num, wr_reply' ){
if ($v[0] === 'wr_num, wr_reply') {
$selected = (! $board['bo_sort_field']) ? 'selected="selected"' : '';
$option_value = '';
} else {
$selected = ($board['bo_sort_field'] === $v[0]) ? 'selected="selected"' : '';
}
if( $order_by_str !== 'wr_num, wr_reply' ){
if ($order_by_str !== 'wr_num, wr_reply') {
$tmp = explode(',', $v[0]);
$order_by_str = $tmp[0];
}
@@ -1337,7 +1280,7 @@ $pg_anchor = '<ul class="anchor">
<div class="btn_fixed_top">
<?php if( $bo_table && $w ){ ?>
<?php if ($bo_table && $w) { ?>
<a href="./board_copy.php?bo_table=<?php echo $board['bo_table']; ?>" id="board_copy" target="win_board_copy" class=" btn_02 btn">게시판복사</a>
<a href="<?php echo get_pretty_url($board['bo_table']); ?>" class=" btn_02 btn">게시판 바로가기</a>
<a href="./board_thumbnail_delete.php?bo_table=<?php echo $board['bo_table'].'&amp;'.$qstr;?>" onclick="return delete_confirm2('게시판 썸네일 파일을 삭제하시겠습니까?');" class="btn_02 btn">게시판 썸네일 삭제</a>
@@ -1419,9 +1362,10 @@ function use_captcha_check(){
});
}
var bo_include_head = jQuery.trim(jQuery("#bo_include_head").val()),
bo_include_tail = jQuery.trim(jQuery("#bo_include_tail").val());
function frm_check_file(){
var bo_include_head = "<?php echo $board['bo_include_head']; ?>";
var bo_include_tail = "<?php echo $board['bo_include_tail']; ?>";
var head = jQuery.trim(jQuery("#bo_include_head").val());
var tail = jQuery.trim(jQuery("#bo_include_tail").val());
@@ -1434,7 +1378,7 @@ function frm_check_file(){
return false;
} else {
jQuery("#admin_captcha_box").hide();
// jQuery("#admin_captcha_box").hide();
}
return true;
@@ -1442,20 +1386,20 @@ function frm_check_file(){
jQuery(function($){
if( window.self !== window.top ){ // frame 또는 iframe을 사용할 경우 체크
$("#bo_include_head, #bo_include_tail").on("change paste keyup", function(e) {
frm_check_file();
});
use_captcha_check();
}
$("#bo_include_head, #bo_include_tail").on("change paste keyup", function(e) {
frm_check_file();
});
});
function fboardform_submit(f)
{
<?php
if(!$w){
$js_array = get_bo_table_banned_word();
echo "var banned_array = ". json_encode($js_array) . ";\n";
if (!$w) {
$js_array = get_bo_table_banned_word();
echo "var banned_array = ". json_encode($js_array) . ";\n";
}
?>
@@ -1482,13 +1426,17 @@ function fboardform_submit(f)
return false;
}
if (frm_check_file() == false) {
jQuery(window).scrollTop($('#bo_include_tail').offset().top - 30);
}
if( captcha_chk ) {
<?php echo isset($captcha_js) ? $captcha_js : ''; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
}
return true;
}
</script>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+109 -63
View File
@@ -2,44 +2,76 @@
$sub_menu = "300100";
include_once('./_common.php');
if ($w == 'u')
if ($w == 'u') {
check_demo();
}
auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
$gr_id = isset($_POST['gr_id']) ? preg_replace('/[^a-z0-9_]/i', '', $_POST['gr_id']) : '';
$bo_admin = isset($_POST['bo_admin']) ? preg_replace('/[^a-z0-9_\, \|\#]/i', '', $_POST['bo_admin']) : '';
$bo_subject = isset($_POST['bo_subject']) ? strip_tags(clean_xss_attributes($_POST['bo_subject'])) : '';
$bo_mobile_subject = isset($_POST['bo_mobile_subject']) ? strip_tags(clean_xss_attributes($_POST['bo_mobile_subject'])) : '';
$gr_id = isset($_POST['gr_id']) ? preg_replace('/[^a-z0-9_]/i', '', (string)$_POST['gr_id']) : '';
$bo_admin = isset($_POST['bo_admin']) ? preg_replace('/[^a-z0-9_\, \|\#]/i', '', $_POST['bo_admin']) : '';
$bo_subject = isset($_POST['bo_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bo_subject'])))) : '';
$bo_mobile_subject = isset($_POST['bo_mobile_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bo_mobile_subject'])))) : '';
if (!$gr_id) { alert('그룹 ID는 반드시 선택하세요.'); }
if (!$bo_table) { alert('게시판 TABLE명은 반드시 입력하세요.'); }
if (!preg_match("/^([A-Za-z0-9_]{1,20})$/", $bo_table)) { alert('게시판 TABLE명은 공백없이 영문자, 숫자, _ 만 사용 가능합니다. (20자 이내)'); }
if (!$bo_subject) { alert('게시판 제목을 입력하세요.'); }
if (!$gr_id) {
alert('그룹 ID는 반드시 선택하세요.');
}
if (!$bo_table) {
alert('게시판 TABLE명은 반드시 입력하세요.');
}
if (!preg_match("/^([A-Za-z0-9_]{1,20})$/", $bo_table)) {
alert('게시판 TABLE명은 공백없이 영문자, 숫자, _ 만 사용 가능합니다. (20자 이내)');
}
if (!$bo_subject) {
alert('게시판 제목을 입력하세요.');
}
// 게시판명이 금지된 단어로 되어 있으면
if ( $w == '' && in_array($bo_table, get_bo_table_banned_word()) ){
if ($w == '' && in_array($bo_table, get_bo_table_banned_word())) {
alert('입력한 게시판 TABLE명을 사용할수 없습니다. 다른 이름으로 입력해 주세요.');
}
$bo_include_head = isset($_POST['bo_include_head']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['bo_include_head'], 0, 255)) : '';
$bo_include_tail = isset($_POST['bo_include_tail']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['bo_include_tail'], 0, 255)) : '';
// 관리자가 자동등록방지를 사용해야 할 경우
if ($board && ($board['bo_include_head'] !== $bo_include_head || $board['bo_include_tail'] !== $bo_include_tail) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()){
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
$check_captcha = false;
// 관리자가 자동등록방지 CAPTCHA를 사용해야 할 경우
// 최고 관리자인 경우에만 수정가능
if ($is_admin === 'super') {
if ($w === 'u') {
if (isset($board['bo_include_head'], $board['bo_include_tail']) &&
($board['bo_include_head'] !== $bo_include_head || $board['bo_include_tail'] !== $bo_include_tail)) {
$check_captcha = true;
}
} elseif ($w === '') {
if ($bo_include_head !== '_head.php' || $bo_include_tail !== '_tail.php') {
$check_captcha = true;
}
}
}
// 실제 CAPTCHA 검증
if ($check_captcha) {
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
}
// 저장·검증 전에 경로를 먼저 정규화하여, 검증 이후 경로가 달라지지 않도록 한다.
if (function_exists('filter_input_include_path')) {
$bo_include_head = filter_input_include_path($bo_include_head);
$bo_include_tail = filter_input_include_path($bo_include_tail);
}
if ($file = $bo_include_head) {
$file_ext = pathinfo($file, PATHINFO_EXTENSION);
if( ! $file_ext || ! in_array($file_ext, array('php', 'htm', 'html')) || ! preg_match('/^.*\.(php|htm|html)$/i', $file) ) {
if (!$file_ext || !in_array($file_ext, array('php', 'htm', 'html')) || !preg_match('/^.*\.(php|htm|html)$/i', $file)) {
alert('상단 파일 경로의 확장자는 php, htm, html 만 허용합니다.');
}
}
@@ -47,25 +79,28 @@ if ($file = $bo_include_head) {
if ($file = $bo_include_tail) {
$file_ext = pathinfo($file, PATHINFO_EXTENSION);
if( ! $file_ext || ! in_array($file_ext, array('php', 'htm', 'html')) || ! preg_match('/^.*\.(php|htm|html)$/i', $file) ) {
if (!$file_ext || !in_array($file_ext, array('php', 'htm', 'html')) || !preg_match('/^.*\.(php|htm|html)$/i', $file)) {
alert('하단 파일 경로의 확장자는 php, htm, html 만 허용합니다.');
}
}
if(!is_include_path_check($bo_include_head, 1)) {
if (!is_include_path_check($bo_include_head, 1)) {
alert('상단 파일 경로에 포함시킬수 없는 문자열이 있습니다.');
}
if(!is_include_path_check($bo_include_tail, 1)) {
if (!is_include_path_check($bo_include_tail, 1)) {
alert('하단 파일 경로에 포함시킬수 없는 문자열이 있습니다.');
}
if( function_exists('filter_input_include_path') ){
$bo_include_head = filter_input_include_path($bo_include_head);
$bo_include_tail = filter_input_include_path($bo_include_tail);
if ($bo_include_head && function_exists('is_content_include_allowed') && !is_content_include_allowed($bo_include_head)) {
alert('상단 파일 경로로 사용할 수 없는 위치입니다.');
}
$board_path = G5_DATA_PATH.'/file/'.$bo_table;
if ($bo_include_tail && function_exists('is_content_include_allowed') && !is_content_include_allowed($bo_include_tail)) {
alert('하단 파일 경로로 사용할 수 없는 위치입니다.');
}
$board_path = G5_DATA_PATH . '/file/' . $bo_table;
// 게시판 디렉토리 생성
@mkdir($board_path, G5_DIR_PERMISSION);
@@ -73,7 +108,7 @@ $board_path = G5_DATA_PATH.'/file/'.$bo_table;
// 디렉토리에 있는 파일의 목록을 보이지 않게 한다.
$file = $board_path . '/index.php';
if( $f = @fopen($file, 'w') ){
if ($f = @fopen($file, 'w')) {
@fwrite($f, '');
@fclose($f);
@chmod($file, G5_FILE_PERMISSION);
@@ -84,7 +119,7 @@ $src_char = array('&', '=');
$dst_char = array('&', '〓');
$bo_category_list = isset($_POST['bo_category_list']) ? str_replace($src_char, $dst_char, $_POST['bo_category_list']) : '';
//https://github.com/gnuboard/gnuboard5/commit/f5f4925d4eb28ba1af728e1065fc2bdd9ce1da58 에 따른 조치
$str_bo_category_list = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\/\^\*]/", "", $bo_category_list);
$str_bo_category_list = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\/\^\*]/", "", (string)$bo_category_list);
$bo_use_category = isset($_POST['bo_use_category']) ? (int) $_POST['bo_use_category'] : 0;
$bo_use_sideview = isset($_POST['bo_use_sideview']) ? (int) $_POST['bo_use_sideview'] : 0;
@@ -113,7 +148,7 @@ $bo_hot = isset($_POST['bo_hot']) ? (int) $_POST['bo_hot'] : 0;
$bo_image_width = isset($_POST['bo_image_width']) ? (int) $_POST['bo_image_width'] : 0;
$bo_use_search = isset($_POST['bo_use_search']) ? (int) $_POST['bo_use_search'] : 0;
$bo_use_cert = isset($_POST['bo_use_cert']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['bo_use_cert']) : '';
$bo_device = isset($_POST['bo_device']) ? clean_xss_tags($_POST['bo_device'], 1, 1) : '';
$bo_device = isset($_POST['bo_device']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_device']), 1, 1)) : '';
$bo_list_level = isset($_POST['bo_list_level']) ? (int) $_POST['bo_list_level'] : 0;
$bo_read_level = isset($_POST['bo_read_level']) ? (int) $_POST['bo_read_level'] : 0;
$bo_write_level = isset($_POST['bo_write_level']) ? (int) $_POST['bo_write_level'] : 0;
@@ -129,9 +164,9 @@ $bo_read_point = isset($_POST['bo_read_point']) ? (int) $_POST['bo_read_point']
$bo_write_point = isset($_POST['bo_write_point']) ? (int) $_POST['bo_write_point'] : 0;
$bo_comment_point = isset($_POST['bo_comment_point']) ? (int) $_POST['bo_comment_point'] : 0;
$bo_download_point = isset($_POST['bo_download_point']) ? (int) $_POST['bo_download_point'] : 0;
$bo_select_editor = isset($_POST['bo_select_editor']) ? clean_xss_tags($_POST['bo_select_editor'], 1, 1) : '';
$bo_skin = isset($_POST['bo_skin']) ? clean_xss_tags($_POST['bo_skin'], 1, 1) : '';
$bo_mobile_skin = isset($_POST['bo_mobile_skin']) ? clean_xss_tags($_POST['bo_mobile_skin'], 1, 1) : '';
$bo_select_editor = isset($_POST['bo_select_editor']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_select_editor']), 1, 1)) : '';
$bo_skin = isset($_POST['bo_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_skin']), 1, 1)) : '';
$bo_mobile_skin = isset($_POST['bo_mobile_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_mobile_skin']), 1, 1)) : '';
$bo_content_head = isset($_POST['bo_content_head']) ? $_POST['bo_content_head'] : '';
$bo_content_tail = isset($_POST['bo_content_tail']) ? $_POST['bo_content_tail'] : '';
$bo_mobile_content_head = isset($_POST['bo_mobile_content_head']) ? $_POST['bo_mobile_content_head'] : '';
@@ -150,13 +185,27 @@ $bo_write_min = isset($_POST['bo_write_min']) ? (int) $_POST['bo_write_min'] : 0
$bo_write_max = isset($_POST['bo_write_max']) ? (int) $_POST['bo_write_max'] : 0;
$bo_comment_min = isset($_POST['bo_comment_min']) ? (int) $_POST['bo_comment_min'] : 0;
$bo_comment_max = isset($_POST['bo_comment_max']) ? (int) $_POST['bo_comment_max'] : 0;
$bo_sort_field = isset($_POST['bo_sort_field']) ? clean_xss_tags($_POST['bo_sort_field'], 1, 1) : '';
$bo_sort_field = isset($_POST['bo_sort_field']) ? trim(stripslashes($_POST['bo_sort_field'])) : '';
$bo_allowed_sort_field = array('');
if (function_exists('get_board_sort_fields')) {
foreach (get_board_sort_fields(isset($board) ? $board : array()) as $bo_sort_v) {
$bo_allowed_sort_field[] = $bo_sort_v[0];
}
}
if (!in_array($bo_sort_field, $bo_allowed_sort_field, true)) {
$bo_sort_field = '';
}
$bo_sort_field = addslashes($bo_sort_field);
if (strpbrk($bo_skin.$bo_mobile_skin, "?%*:|\"<>") !== false) {
alert('스킨 디렉토리명 오류!');
}
$etcs = array();
for($i=1;$i<=10;$i++){
$etcs['bo_'.$i.'_subj'] = ${'bo_'.$i.'_subj'} = isset($_POST['bo_'.$i.'_subj']) ? $_POST['bo_'.$i.'_subj'] : '';
$etcs['bo_'.$i] = ${'bo_'.$i} = isset($_POST['bo_'.$i]) ? $_POST['bo_'.$i] : '';
for ($i = 1; $i <= 10; $i++) {
$etcs['bo_' . $i . '_subj'] = ${'bo_' . $i . '_subj'} = isset($_POST['bo_' . $i . '_subj']) ? $_POST['bo_' . $i . '_subj'] : '';
$etcs['bo_' . $i] = ${'bo_' . $i} = isset($_POST['bo_' . $i]) ? $_POST['bo_' . $i] : '';
}
$sql_common = " gr_id = '{$gr_id}',
@@ -212,9 +261,9 @@ $sql_common = " gr_id = '{$gr_id}',
";
// 최고 관리자인 경우에만 수정가능
if ($is_admin === 'super'){
$sql_common .= " bo_include_head = '".$bo_include_head."',
bo_include_tail = '".$bo_include_tail."',
if ($is_admin === 'super') {
$sql_common .= " bo_include_head = '" . $bo_include_head . "',
bo_include_tail = '" . $bo_include_tail . "',
bo_content_head = '{$bo_content_head}',
bo_content_tail = '{$bo_content_tail}',
bo_mobile_content_head = '{$bo_mobile_content_head}',
@@ -260,10 +309,10 @@ $sql_common .= " bo_insert_content = '{$bo_insert_content}',
bo_10 = '{$bo_10}' ";
if ($w == '') {
$row = sql_fetch(" select count(*) as cnt from {$g5['board_table']} where bo_table = '{$bo_table}' ");
if ($row['cnt'])
alert($bo_table.' 은(는) 이미 존재하는 TABLE 입니다.');
if ($row['cnt']) {
alert($bo_table . ' 은(는) 이미 존재하는 TABLE 입니다.');
}
$sql = " insert into {$g5['board_table']}
set bo_table = '{$bo_table}',
@@ -284,10 +333,8 @@ if ($w == '') {
$source = array('/__TABLE_NAME__/', '/;/');
$target = array($create_table, '');
$sql = preg_replace($source, $target, $sql);
sql_query($sql, FALSE);
} else if ($w == 'u') {
sql_query($sql, false);
} elseif ($w == 'u') {
// 게시판의 글 수
$sql = " select count(*) as cnt from {$g5['write_prefix']}{$bo_table} where wr_is_comment = 0 ";
$row = sql_fetch($sql);
@@ -308,7 +355,7 @@ if ($w == '') {
//$sql = " select wr_id from {$g5['write_prefix']}{$bo_table} where wr_is_comment = 0 ";
$sql = " select a.wr_id, (count(b.wr_parent) - 1) as cnt from {$g5['write_prefix']}{$bo_table} a, {$g5['write_prefix']}{$bo_table} b where a.wr_id=b.wr_parent and a.wr_is_comment=0 group by a.wr_id ";
$result = sql_query($sql);
for ($i=0; $row=sql_fetch_array($result); $i++) {
for ($i = 0; $row = sql_fetch_array($result); $i++) {
/*
// 코멘트수를 얻습니다.
$sql2 = " select count(*) as cnt from {$g5['write_prefix']}$bo_table where wr_parent = '{$row['wr_id']}' and wr_is_comment = 1 ";
@@ -324,11 +371,10 @@ if ($w == '') {
$lf = "";
if ($board['bo_notice']) {
$tmp_array = explode(",", $board['bo_notice']);
for ($i=0; $i<count($tmp_array); $i++) {
for ($i = 0; $i < count($tmp_array); $i++) {
$tmp_wr_id = trim($tmp_array[$i]);
$row = sql_fetch(" select count(*) as cnt from {$g5['write_prefix']}{$bo_table} where wr_id = '{$tmp_wr_id}' ");
if ($row['cnt'])
{
if ($row['cnt']) {
$bo_notice .= $lf . $tmp_wr_id;
$lf = ",";
}
@@ -342,7 +388,6 @@ if ($w == '') {
{$sql_common}
where bo_table = '{$bo_table}' ";
sql_query($sql);
}
@@ -396,9 +441,9 @@ if (is_checked('chk_grp_mobile_gallery_width')) $grp_fields .= " , bo_mobile_gal
if (is_checked('chk_grp_mobile_gallery_height'))$grp_fields .= " , bo_mobile_gallery_height = '{$bo_mobile_gallery_height}' ";
if (is_checked('chk_grp_table_width')) $grp_fields .= " , bo_table_width = '{$bo_table_width}' ";
if (is_checked('chk_grp_page_rows')) $grp_fields .= " , bo_page_rows = '{$bo_page_rows}' ";
if (is_checked('chk_grp_mobile_page_rows')) $grp_fields .= " , bo_mobile_page_rows = '{$bo_mobile_page_rows}' ";
if (is_checked('chk_grp_mobile_page_rows')) $grp_fields .= " , bo_mobile_page_rows = '{$bo_mobile_page_rows}' ";
if (is_checked('chk_grp_subject_len')) $grp_fields .= " , bo_subject_len = '{$bo_subject_len}' ";
if (is_checked('chk_grp_mobile_subject_len')) $grp_fields .= " , bo_mobile_subject_len = '{$bo_mobile_subject_len}' ";
if (is_checked('chk_grp_mobile_subject_len')) $grp_fields .= " , bo_mobile_subject_len = '{$bo_mobile_subject_len}' ";
if (is_checked('chk_grp_new')) $grp_fields .= " , bo_new = '{$bo_new}' ";
if (is_checked('chk_grp_hot')) $grp_fields .= " , bo_hot = '{$bo_hot}' ";
if (is_checked('chk_grp_image_width')) $grp_fields .= " , bo_image_width = '{$bo_image_width}' ";
@@ -412,7 +457,7 @@ if (is_checked('chk_grp_upload_count')) $grp_fields .= " , bo_upload_cou
if (is_checked('chk_grp_upload_size')) $grp_fields .= " , bo_upload_size = '{$bo_upload_size}' ";
//최고관리자만 수정가능
if ($is_admin === 'super'){
if ($is_admin === 'super') {
if (is_checked('chk_grp_include_head')) $grp_fields .= " , bo_include_head = '{$bo_include_head}' ";
if (is_checked('chk_grp_include_tail')) $grp_fields .= " , bo_include_tail = '{$bo_include_tail}' ";
if (is_checked('chk_grp_content_head')) $grp_fields .= " , bo_content_head = '{$bo_content_head}' ";
@@ -424,10 +469,10 @@ if ($is_admin === 'super'){
if (is_checked('chk_grp_insert_content')) $grp_fields .= " , bo_insert_content = '{$bo_insert_content}' ";
if (is_checked('chk_grp_use_search')) $grp_fields .= " , bo_use_search = '{$bo_use_search}' ";
if (is_checked('chk_grp_order')) $grp_fields .= " , bo_order = '{$bo_order}' ";
for ($i=1; $i<=10; $i++) {
if (is_checked('chk_grp_'.$i)) {
$grp_fields .= " , bo_{$i}_subj = '".$etcs['bo_'.$i.'_subj']."' ";
$grp_fields .= " , bo_{$i} = '".$etcs['bo_'.$i]."' ";
for ($i = 1; $i <= 10; $i++) {
if (is_checked('chk_grp_' . $i)) {
$grp_fields .= " , bo_{$i}_subj = '" . $etcs['bo_' . $i . '_subj'] . "' ";
$grp_fields .= " , bo_{$i} = '" . $etcs['bo_' . $i] . "' ";
}
}
@@ -483,12 +528,12 @@ if (is_checked('chk_all_gallery_cols')) $all_fields .= " , bo_gallery_co
if (is_checked('chk_all_gallery_width')) $all_fields .= " , bo_gallery_width = '{$bo_gallery_width}' ";
if (is_checked('chk_all_gallery_height')) $all_fields .= " , bo_gallery_height = '{$bo_gallery_height}' ";
if (is_checked('chk_all_mobile_gallery_width')) $all_fields .= " , bo_mobile_gallery_width = '{$bo_mobile_gallery_width}' ";
if (is_checked('chk_all_mobile_gallery_height'))$all_fields .= " , bo_mobile_gallery_height = '{$bo_mobile_gallery_height}' ";
if (is_checked('chk_all_mobile_gallery_height')) $all_fields .= " , bo_mobile_gallery_height = '{$bo_mobile_gallery_height}' ";
if (is_checked('chk_all_table_width')) $all_fields .= " , bo_table_width = '{$bo_table_width}' ";
if (is_checked('chk_all_page_rows')) $all_fields .= " , bo_page_rows = '{$bo_page_rows}' ";
if (is_checked('chk_all_mobile_page_rows')) $all_fields .= " , bo_mobile_page_rows = '{$bo_mobile_page_rows}' ";
if (is_checked('chk_all_mobile_page_rows')) $all_fields .= " , bo_mobile_page_rows = '{$bo_mobile_page_rows}' ";
if (is_checked('chk_all_subject_len')) $all_fields .= " , bo_subject_len = '{$bo_subject_len}' ";
if (is_checked('chk_all_mobile_subject_len')) $all_fields .= " , bo_mobile_subject_len = '{$bo_mobile_subject_len}' ";
if (is_checked('chk_all_mobile_subject_len')) $all_fields .= " , bo_mobile_subject_len = '{$bo_mobile_subject_len}' ";
if (is_checked('chk_all_new')) $all_fields .= " , bo_new = '{$bo_new}' ";
if (is_checked('chk_all_hot')) $all_fields .= " , bo_hot = '{$bo_hot}' ";
if (is_checked('chk_all_image_width')) $all_fields .= " , bo_image_width = '{$bo_image_width}' ";
@@ -502,7 +547,7 @@ if (is_checked('chk_all_upload_count')) $all_fields .= " , bo_upload_cou
if (is_checked('chk_all_upload_size')) $all_fields .= " , bo_upload_size = '{$bo_upload_size}' ";
//최고관리자만 수정가능
if ($is_admin === 'super'){
if ($is_admin === 'super') {
if (is_checked('chk_all_include_head')) $all_fields .= " , bo_include_head = '{$bo_include_head}' ";
if (is_checked('chk_all_include_tail')) $all_fields .= " , bo_include_tail = '{$bo_include_tail}' ";
if (is_checked('chk_all_content_head')) $all_fields .= " , bo_content_head = '{$bo_content_head}' ";
@@ -514,10 +559,10 @@ if ($is_admin === 'super'){
if (is_checked('chk_all_insert_content')) $all_fields .= " , bo_insert_content = '{$bo_insert_content}' ";
if (is_checked('chk_all_use_search')) $all_fields .= " , bo_use_search = '{$bo_use_search}' ";
if (is_checked('chk_all_order')) $all_fields .= " , bo_order = '{$bo_order}' ";
for ($i=1; $i<=10; $i++) {
if (is_checked('chk_all_'.$i)) {
$all_fields .= " , bo_{$i}_subj = '".$etcs['bo_'.$i.'_subj']."' ";
$all_fields .= " , bo_{$i} = '".$etcs['bo_'.$i]."' ";
for ($i = 1; $i <= 10; $i++) {
if (is_checked('chk_all_' . $i)) {
$all_fields .= " , bo_{$i}_subj = '" . $etcs['bo_' . $i . '_subj'] . "' ";
$all_fields .= " , bo_{$i} = '" . $etcs['bo_' . $i] . "' ";
}
}
@@ -527,9 +572,10 @@ if ($all_fields) {
delete_cache_latest($bo_table);
if(function_exists('get_admin_captcha_by'))
if (function_exists('get_admin_captcha_by')) {
get_admin_captcha_by('remove');
}
run_event('admin_board_form_update', $bo_table, $w);
goto_url("./board_form.php?w=u&bo_table={$bo_table}&amp;{$qstr}");
goto_url("./board_form.php?w=u&bo_table={$bo_table}&amp;{$qstr}");
+167 -163
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = "300100";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
@@ -12,16 +12,21 @@ if ($is_admin != "super") {
$sql_search .= " and (a.gr_id = b.gr_id and b.gr_admin = '{$member['mb_id']}') ";
}
$allowed_sfl = array('bo_table', 'bo_subject', 'a.gr_id');
if (!in_array($sfl, $allowed_sfl)) {
$sfl = 'bo_table';
}
if ($stx) {
$sql_search .= " and ( ";
switch ($sfl) {
case "bo_table" :
case "bo_table":
$sql_search .= " ($sfl like '$stx%') ";
break;
case "a.gr_id" :
case "a.gr_id":
$sql_search .= " ($sfl = '$stx') ";
break;
default :
default:
$sql_search .= " ($sfl like '%$stx%') ";
break;
}
@@ -32,6 +37,9 @@ if (!$sst) {
$sst = "a.gr_id, a.bo_table";
$sod = "asc";
}
$allowed_sst = array('a.gr_id', 'bo_table', 'bo_skin', 'bo_mobile_skin', 'bo_subject', 'bo_use_sns', 'bo_use_search', 'bo_order', 'a.gr_id, a.bo_table');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'a.gr_id, a.bo_table';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by $sst $sod ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
@@ -40,16 +48,18 @@ $total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) { $page = 1; } // 페이지가 없으면 첫 페이지 (1 페이지)
if ($page < 1) {
$page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
}
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select * {$sql_common} {$sql_search} {$sql_order} limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목록</a>';
$listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall">전체목록</a>';
$g5['title'] = '게시판관리';
include_once('./admin.head.php');
require_once './admin.head.php';
$colspan = 15;
?>
@@ -60,179 +70,173 @@ $colspan = 15;
</div>
<form name="fsearch" id="fsearch" class="local_sch01 local_sch" method="get">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="bo_table"<?php echo get_selected($sfl, "bo_table", true); ?>>TABLE</option>
<option value="bo_subject"<?php echo get_selected($sfl, "bo_subject"); ?>>제목</option>
<option value="a.gr_id"<?php echo get_selected($sfl, "a.gr_id"); ?>>그룹ID</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" value="검색" class="btn_submit">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="bo_table" <?php echo get_selected($sfl, "bo_table", true); ?>>TABLE</option>
<option value="bo_subject" <?php echo get_selected($sfl, "bo_subject"); ?>>제목</option>
<option value="a.gr_id" <?php echo get_selected($sfl, "a.gr_id"); ?>>그룹ID</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" value="검색" class="btn_submit">
</form>
<form name="fboardlist" id="fboardlist" action="./board_list_update.php" onsubmit="return fboardlist_submit(this);" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo isset($token) ? $token : ''; ?>">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo isset($token) ? $token : ''; ?>">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">게시판 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('a.gr_id') ?>그룹</a></th>
<th scope="col"><?php echo subject_sort_link('bo_table') ?>TABLE</a></th>
<th scope="col"><?php echo subject_sort_link('bo_skin', '', 'desc') ?>스킨</a></th>
<th scope="col"><?php echo subject_sort_link('bo_mobile_skin', '', 'desc') ?>모바일<br>스킨</a></th>
<th scope="col"><?php echo subject_sort_link('bo_subject') ?>제목</a></th>
<th scope="col">읽기P<span class="sound_only">포인트</span></th>
<th scope="col">쓰기P<span class="sound_only">포인트</span></th>
<th scope="col">댓글P<span class="sound_only">포인트</span></th>
<th scope="col">다운P<span class="sound_only">포인트</span></th>
<th scope="col"><?php echo subject_sort_link('bo_use_sns') ?>SNS<br>사용</a></th>
<th scope="col"><?php echo subject_sort_link('bo_use_search') ?>검색<br>사용</a></th>
<th scope="col"><?php echo subject_sort_link('bo_order') ?>출력<br>순서</a></th>
<th scope="col">접속기기</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++) {
$one_update = '<a href="./board_form.php?w=u&amp;bo_table='.$row['bo_table'].'&amp;'.$qstr.'" class="btn btn_03">수정</a>';
$one_copy = '<a href="./board_copy.php?bo_table='.$row['bo_table'].'" class="board_copy btn btn_02" target="win_board_copy">복사</a>';
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">게시판 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('a.gr_id') ?>그룹</a></th>
<th scope="col"><?php echo subject_sort_link('bo_table') ?>TABLE</a></th>
<th scope="col"><?php echo subject_sort_link('bo_skin', '', 'desc') ?>스킨</a></th>
<th scope="col"><?php echo subject_sort_link('bo_mobile_skin', '', 'desc') ?>모바일<br>스킨</a></th>
<th scope="col"><?php echo subject_sort_link('bo_subject') ?>제목</a></th>
<th scope="col">읽기P<span class="sound_only">포인트</span></th>
<th scope="col">쓰기P<span class="sound_only">포인트</span></th>
<th scope="col">댓글P<span class="sound_only">포인트</span></th>
<th scope="col">다운P<span class="sound_only">포인트</span></th>
<th scope="col"><?php echo subject_sort_link('bo_use_sns') ?>SNS<br>사용</a></th>
<th scope="col"><?php echo subject_sort_link('bo_use_search') ?>검색<br>사용</a></th>
<th scope="col"><?php echo subject_sort_link('bo_order') ?>출력<br>순서</a></th>
<th scope="col">접속기기</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$one_update = '<a href="./board_form.php?w=u&amp;bo_table=' . $row['bo_table'] . '&amp;' . $qstr . '" class="btn btn_03">수정</a>';
$one_copy = '<a href="./board_copy.php?bo_table=' . $row['bo_table'] . '" class="board_copy btn btn_02" target="win_board_copy">복사</a>';
$bg = 'bg'.($i%2);
?>
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo get_text($row['bo_subject']) ?></label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td>
<?php if ($is_admin == 'super'){ ?>
<?php echo get_group_select("gr_id[$i]", $row['gr_id']) ?>
<?php }else{ ?>
<input type="hidden" name="gr_id[<?php echo $i ?>]" value="<?php echo $row['gr_id'] ?>"><?php echo $row['gr_subject'] ?>
<?php } ?>
</td>
<td>
<input type="hidden" name="board_table[<?php echo $i ?>]" value="<?php echo $row['bo_table'] ?>">
<a href="<?php echo get_pretty_url($row['bo_table']) ?>"><?php echo $row['bo_table'] ?></a>
</td>
<td>
<label for="bo_skin_<?php echo $i; ?>" class="sound_only">스킨</label>
<?php echo get_skin_select('board', 'bo_skin_'.$i, "bo_skin[$i]", $row['bo_skin']); ?>
</td>
<td>
<label for="bo_mobile_skin_<?php echo $i; ?>" class="sound_only">모바일 스킨</label>
<?php echo get_mobile_skin_select('board', 'bo_mobile_skin_'.$i, "bo_mobile_skin[$i]", $row['bo_mobile_skin']); ?>
</td>
<td>
<label for="bo_subject_<?php echo $i; ?>" class="sound_only">게시판 제목<strong class="sound_only"> 필수</strong></label>
<input type="text" name="bo_subject[<?php echo $i ?>]" value="<?php echo get_text($row['bo_subject']) ?>" id="bo_subject_<?php echo $i ?>" required class="required tbl_input bo_subject full_input" size="10">
</td>
<td class="td_numsmall">
<label for="bo_read_point_<?php echo $i; ?>" class="sound_only">읽기 포인트</label>
<input type="text" name="bo_read_point[<?php echo $i ?>]" value="<?php echo $row['bo_read_point'] ?>" id="bo_read_point_<?php echo $i; ?>" class="tbl_input" size="2">
</td>
<td class="td_numsmall">
<label for="bo_write_point_<?php echo $i; ?>" class="sound_only">쓰기 포인트</label>
<input type="text" name="bo_write_point[<?php echo $i ?>]" value="<?php echo $row['bo_write_point'] ?>" id="bo_write_point_<?php echo $i; ?>" class="tbl_input" size="2">
</td>
<td class="td_numsmall">
<label for="bo_comment_point_<?php echo $i; ?>" class="sound_only">댓글 포인트</label>
<input type="text" name="bo_comment_point[<?php echo $i ?>]" value="<?php echo $row['bo_comment_point'] ?>" id="bo_comment_point_<?php echo $i; ?>" class="tbl_input" size="2">
</td>
<td class="td_numsmall">
<label for="bo_download_point_<?php echo $i; ?>" class="sound_only">다운<br>포인트</label>
<input type="text" name="bo_download_point[<?php echo $i ?>]" value="<?php echo $row['bo_download_point'] ?>" id="bo_download_point_<?php echo $i; ?>" class="tbl_input" size="2">
</td>
<td class="td_numsmall">
<label for="bo_use_sns_<?php echo $i; ?>" class="sound_only">SNS<br>사용</label>
<input type="checkbox" name="bo_use_sns[<?php echo $i ?>]" value="1" id="bo_use_sns_<?php echo $i ?>" <?php echo $row['bo_use_sns']?"checked":"" ?>>
</td>
<td class="td_numsmall">
<label for="bo_use_search_<?php echo $i; ?>" class="sound_only">검색<br>사용</label>
<input type="checkbox" name="bo_use_search[<?php echo $i ?>]" value="1" id="bo_use_search_<?php echo $i ?>" <?php echo $row['bo_use_search']?"checked":"" ?>>
</td>
<td class="td_numsmall">
<label for="bo_order_<?php echo $i; ?>" class="sound_only">출력<br>순서</label>
<input type="text" name="bo_order[<?php echo $i ?>]" value="<?php echo $row['bo_order'] ?>" id="bo_order_<?php echo $i ?>" class="tbl_input" size="2">
</td>
<td class="td_mngsmall">
<label for="bo_device_<?php echo $i; ?>" class="sound_only">접속기기</label>
<select name="bo_device[<?php echo $i ?>]" id="bo_device_<?php echo $i ?>">
<option value="both"<?php echo get_selected($row['bo_device'], 'both', true); ?>>모두</option>
<option value="pc"<?php echo get_selected($row['bo_device'], 'pc'); ?>>PC</option>
<option value="mobile"<?php echo get_selected($row['bo_device'], 'mobile'); ?>>모바일</option>
</select>
</td>
<td class="td_mng td_mng_m">
<?php echo $one_update ?>
<?php echo $one_copy ?>
</td>
</tr>
<?php
}
if ($i == 0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo get_text($row['bo_subject']) ?></label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td>
<?php if ($is_admin == 'super') { ?>
<?php echo get_group_select("gr_id[$i]", $row['gr_id']) ?>
<?php } else { ?>
<input type="hidden" name="gr_id[<?php echo $i ?>]" value="<?php echo $row['gr_id'] ?>"><?php echo $row['gr_subject'] ?>
<?php } ?>
</td>
<td>
<input type="hidden" name="board_table[<?php echo $i ?>]" value="<?php echo $row['bo_table'] ?>">
<a href="<?php echo get_pretty_url($row['bo_table']) ?>"><?php echo $row['bo_table'] ?></a>
</td>
<td>
<label for="bo_skin_<?php echo $i; ?>" class="sound_only">스킨</label>
<?php echo get_skin_select('board', 'bo_skin_' . $i, "bo_skin[$i]", $row['bo_skin']); ?>
</td>
<td>
<label for="bo_mobile_skin_<?php echo $i; ?>" class="sound_only">모바일 스킨</label>
<?php echo get_mobile_skin_select('board', 'bo_mobile_skin_' . $i, "bo_mobile_skin[$i]", $row['bo_mobile_skin']); ?>
</td>
<td>
<label for="bo_subject_<?php echo $i; ?>" class="sound_only">게시판 제목<strong class="sound_only"> 필수</strong></label>
<input type="text" name="bo_subject[<?php echo $i ?>]" value="<?php echo get_text($row['bo_subject']) ?>" id="bo_subject_<?php echo $i ?>" required class="required tbl_input bo_subject full_input" size="10">
</td>
<td class="td_numsmall">
<label for="bo_read_point_<?php echo $i; ?>" class="sound_only">읽기 포인트</label>
<input type="text" name="bo_read_point[<?php echo $i ?>]" value="<?php echo $row['bo_read_point'] ?>" id="bo_read_point_<?php echo $i; ?>" class="tbl_input" size="2">
</td>
<td class="td_numsmall">
<label for="bo_write_point_<?php echo $i; ?>" class="sound_only">쓰기 포인트</label>
<input type="text" name="bo_write_point[<?php echo $i ?>]" value="<?php echo $row['bo_write_point'] ?>" id="bo_write_point_<?php echo $i; ?>" class="tbl_input" size="2">
</td>
<td class="td_numsmall">
<label for="bo_comment_point_<?php echo $i; ?>" class="sound_only">댓글 포인트</label>
<input type="text" name="bo_comment_point[<?php echo $i ?>]" value="<?php echo $row['bo_comment_point'] ?>" id="bo_comment_point_<?php echo $i; ?>" class="tbl_input" size="2">
</td>
<td class="td_numsmall">
<label for="bo_download_point_<?php echo $i; ?>" class="sound_only">다운<br>포인트</label>
<input type="text" name="bo_download_point[<?php echo $i ?>]" value="<?php echo $row['bo_download_point'] ?>" id="bo_download_point_<?php echo $i; ?>" class="tbl_input" size="2">
</td>
<td class="td_numsmall">
<label for="bo_use_sns_<?php echo $i; ?>" class="sound_only">SNS<br>사용</label>
<input type="checkbox" name="bo_use_sns[<?php echo $i ?>]" value="1" id="bo_use_sns_<?php echo $i ?>" <?php echo $row['bo_use_sns'] ? "checked" : "" ?>>
</td>
<td class="td_numsmall">
<label for="bo_use_search_<?php echo $i; ?>" class="sound_only">검색<br>사용</label>
<input type="checkbox" name="bo_use_search[<?php echo $i ?>]" value="1" id="bo_use_search_<?php echo $i ?>" <?php echo $row['bo_use_search'] ? "checked" : "" ?>>
</td>
<td class="td_numsmall">
<label for="bo_order_<?php echo $i; ?>" class="sound_only">출력<br>순서</label>
<input type="text" name="bo_order[<?php echo $i ?>]" value="<?php echo $row['bo_order'] ?>" id="bo_order_<?php echo $i ?>" class="tbl_input" size="2">
</td>
<td class="td_mngsmall">
<label for="bo_device_<?php echo $i; ?>" class="sound_only">접속기기</label>
<select name="bo_device[<?php echo $i ?>]" id="bo_device_<?php echo $i ?>">
<option value="both" <?php echo get_selected($row['bo_device'], 'both', true); ?>>모두</option>
<option value="pc" <?php echo get_selected($row['bo_device'], 'pc'); ?>>PC</option>
<option value="mobile" <?php echo get_selected($row['bo_device'], 'mobile'); ?>>모바일</option>
</select>
</td>
<td class="td_mng td_mng_m">
<?php echo $one_update ?>
<?php echo $one_copy ?>
</td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<input type="submit" name="act_button" value="선택수정" onclick="document.pressed=this.value" class="btn_02 btn">
<?php if ($is_admin == 'super') { ?>
<input type="submit" name="act_button" value="선택삭제" onclick="document.pressed=this.value" class="btn_02 btn">
<?php } ?>
<?php if ($is_admin == 'super') { ?>
<a href="./board_form.php" id="bo_add" class="btn_01 btn">게시판 추가</a>
<?php } ?>
</div>
<div class="btn_fixed_top">
<input type="submit" name="act_button" value="선택수정" onclick="document.pressed=this.value" class="btn_02 btn">
<?php if ($is_admin == 'super') { ?>
<input type="submit" name="act_button" value="선택삭제" onclick="document.pressed=this.value" class="btn_02 btn">
<a href="./board_form.php" id="bo_add" class="btn_01 btn">게시판 추가</a>
<?php } ?>
</div>
</form>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, $_SERVER['SCRIPT_NAME'].'?'.$qstr.'&amp;page='); ?>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, $_SERVER['SCRIPT_NAME'] . '?' . $qstr . '&amp;page='); ?>
<script>
function fboardlist_submit(f)
{
if (!is_checked("chk[]")) {
alert(document.pressed+" 하실 항목을 하나 이상 선택하세요.");
return false;
}
if(document.pressed == "선택삭제") {
if(!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
function fboardlist_submit(f) {
if (!is_checked("chk[]")) {
alert(document.pressed + " 하실 항목을 하나 이상 선택하세요.");
return false;
}
if (document.pressed == "선택삭제") {
if (!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
return false;
}
}
return true;
}
return true;
}
$(function(){
$(".board_copy").click(function(){
window.open(this.href, "win_board_copy", "left=100,top=100,width=550,height=450");
return false;
$(function() {
$(".board_copy").click(function() {
window.open(this.href, "win_board_copy", "left=100,top=100,width=550,height=450");
return false;
});
});
});
</script>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
+35 -36
View File
@@ -1,26 +1,24 @@
<?php
$sub_menu = "300100";
include_once('./_common.php');
require_once './_common.php';
check_demo();
$post_count_chk = (isset($_POST['chk']) && is_array($_POST['chk'])) ? count($_POST['chk']) : 0;
$chk = (isset($_POST['chk']) && is_array($_POST['chk'])) ? $_POST['chk'] : array();
$act_button = isset($_POST['act_button']) ? strip_tags($_POST['act_button']) : '';
$board_table = (isset($_POST['board_table']) && is_array($_POST['board_table'])) ? $_POST['board_table'] : array();
$chk = (isset($_POST['chk']) && is_array($_POST['chk'])) ? $_POST['chk'] : array();
$act_button = isset($_POST['act_button']) ? strip_tags($_POST['act_button']) : '';
$board_table = (isset($_POST['board_table']) && is_array($_POST['board_table'])) ? $_POST['board_table'] : array();
if (! $post_count_chk) {
alert($act_button." 하실 항목을 하나 이상 체크하세요.");
if (!$post_count_chk) {
alert($act_button . " 하실 항목을 하나 이상 체크하세요.");
}
check_admin_token();
if ($act_button === "선택수정") {
auth_check_menu($auth, $sub_menu, 'w');
for ($i=0; $i<$post_count_chk; $i++) {
for ($i = 0; $i < $post_count_chk; $i++) {
// 실제 번호를 넘김
$k = isset($_POST['chk'][$i]) ? (int) $_POST['chk'][$i] : 0;
@@ -39,59 +37,60 @@ if ($act_button === "선택수정") {
if ($is_admin != 'super') {
$sql = " select count(*) as cnt from {$g5['board_table']} a, {$g5['group_table']} b
where a.gr_id = '".sql_real_escape_string($post_gr_id)."'
where a.gr_id = '" . sql_real_escape_string($post_gr_id) . "'
and a.gr_id = b.gr_id
and b.gr_admin = '{$member['mb_id']}' ";
$row = sql_fetch($sql);
if (!$row['cnt'])
alert('최고관리자가 아닌 경우 다른 관리자의 게시판('.$board_table[$k].')은 수정이 불가합니다.');
if (!$row['cnt']) {
alert('최고관리자가 아닌 경우 다른 관리자의 게시판(' . $board_table[$k] . ')은 수정이 불가합니다.');
}
}
$p_bo_subject = is_array($_POST['bo_subject']) ? strip_tags(clean_xss_attributes($_POST['bo_subject'][$k])) : '';
$p_bo_subject = is_array($_POST['bo_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bo_subject'][$k])))) : '';
$sql = " update {$g5['board_table']}
set gr_id = '".sql_real_escape_string($post_gr_id)."',
bo_subject = '".$p_bo_subject."',
bo_device = '".sql_real_escape_string($post_bo_device)."',
bo_skin = '".sql_real_escape_string($post_bo_skin)."',
bo_mobile_skin = '".sql_real_escape_string($post_bo_mobile_skin)."',
bo_read_point = '".sql_real_escape_string($post_bo_read_point)."',
bo_write_point = '".sql_real_escape_string($post_bo_write_point)."',
bo_comment_point = '".sql_real_escape_string($post_bo_comment_point)."',
bo_download_point = '".sql_real_escape_string($post_bo_download_point)."',
bo_use_search = '".sql_real_escape_string($post_bo_use_search)."',
bo_use_sns = '".sql_real_escape_string($post_bo_use_sns)."',
bo_order = '".sql_real_escape_string($post_bo_order)."'
where bo_table = '".sql_real_escape_string($post_board_table)."' ";
set gr_id = '" . sql_real_escape_string($post_gr_id) . "',
bo_subject = '" . $p_bo_subject . "',
bo_device = '" . sql_real_escape_string($post_bo_device) . "',
bo_skin = '" . sql_real_escape_string($post_bo_skin) . "',
bo_mobile_skin = '" . sql_real_escape_string($post_bo_mobile_skin) . "',
bo_read_point = '" . sql_real_escape_string($post_bo_read_point) . "',
bo_write_point = '" . sql_real_escape_string($post_bo_write_point) . "',
bo_comment_point = '" . sql_real_escape_string($post_bo_comment_point) . "',
bo_download_point = '" . sql_real_escape_string($post_bo_download_point) . "',
bo_use_search = '" . sql_real_escape_string($post_bo_use_search) . "',
bo_use_sns = '" . sql_real_escape_string($post_bo_use_sns) . "',
bo_order = '" . sql_real_escape_string($post_bo_order) . "'
where bo_table = '" . sql_real_escape_string($post_board_table) . "' ";
sql_query($sql);
}
} else if ($act_button === "선택삭제") {
if ($is_admin != 'super')
} elseif ($act_button === "선택삭제") {
if ($is_admin != 'super') {
alert('게시판 삭제는 최고관리자만 가능합니다.');
}
auth_check_menu($auth, $sub_menu, 'd');
// _BOARD_DELETE_ 상수를 선언해야 board_delete.inc.php 가 정상 작동함
/* 확인필요 22.05.27
A file should declare new symbols (classes, functions, constants, etc.) and cause no other side effects,
or it should execute logic with side effects, but should not do both.*/
define('_BOARD_DELETE_', true);
for ($i=0; $i<$post_count_chk; $i++) {
for ($i = 0; $i < $post_count_chk; $i++) {
// 실제 번호를 넘김
$k = isset($_POST['chk'][$i]) ? (int) $_POST['chk'][$i] : 0;
// include 전에 $bo_table 값을 반드시 넘겨야 함
$tmp_bo_table = isset($_POST['board_table'][$k]) ? trim(clean_xss_tags($_POST['board_table'][$k], 1, 1)) : '';
if( preg_match("/^[A-Za-z0-9_]+$/", $tmp_bo_table) ){
include ('./board_delete.inc.php');
if (preg_match("/^[A-Za-z0-9_]+$/", $tmp_bo_table)) {
include './board_delete.inc.php';
}
}
}
run_event('admin_board_list_update', $act_button, $chk, $board_table, $qstr);
goto_url('./board_list.php?'.$qstr);
goto_url('./board_list.php?' . $qstr);
+15 -13
View File
@@ -1,14 +1,15 @@
<?php
$sub_menu = '300100';
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'w');
if(!$board['bo_table'])
if (!$board['bo_table']) {
alert('존재하지 않는 게시판입니다.');
}
$g5['title'] = $board['bo_subject'].' 게시판 썸네일 삭제';
include_once('./admin.head.php');
$g5['title'] = $board['bo_subject'] . ' 게시판 썸네일 삭제';
require_once './admin.head.php';
?>
<div class="local_desc02 local_desc">
@@ -18,28 +19,29 @@ include_once('./admin.head.php');
</div>
<?php
$dir = G5_DATA_PATH.'/file/'.$bo_table;
$dir = G5_DATA_PATH . '/file/' . $bo_table;
$cnt = 0;
if(is_dir($dir)) {
if (is_dir($dir)) {
echo '<ul>';
$files = glob($dir.'/thumb-*');
$files = glob($dir . '/thumb-*');
if (is_array($files)) {
foreach($files as $thumbnail) {
foreach ($files as $thumbnail) {
$cnt++;
@unlink($thumbnail);
echo '<li>'.$thumbnail.'</li>'.PHP_EOL;
echo '<li>' . $thumbnail . '</li>' . PHP_EOL;
flush();
if ($cnt%10==0)
if (($cnt % 10) == 0) {
echo PHP_EOL;
}
}
}
echo '<li>완료됨</li></ul>'.PHP_EOL;
echo '<div class="local_desc01 local_desc"><p><strong>썸네일 '.$cnt.'건의 삭제 완료됐습니다.</strong></p></div>'.PHP_EOL;
echo '<li>완료됨</li></ul>' . PHP_EOL;
echo '<div class="local_desc01 local_desc"><p><strong>썸네일 ' . $cnt . '건의 삭제 완료됐습니다.</strong></p></div>' . PHP_EOL;
} else {
echo '<p>첨부파일 디렉토리가 존재하지 않습니다.</p>';
}
@@ -48,4 +50,4 @@ if(is_dir($dir)) {
<div class="btn_confirm01 btn_confirm"><a href="./board_form.php?w=u&amp;bo_table=<?php echo $bo_table; ?>&amp;<?php echo $qstr; ?>">게시판 수정으로 돌아가기</a></div>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
+122 -112
View File
@@ -1,141 +1,152 @@
<?php
$sub_menu = "300200";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'w');
if ($is_admin != 'super' && $w == '') alert('최고관리자만 접근 가능합니다.');
if ($is_admin != 'super' && $w == '') {
alert('최고관리자만 접근 가능합니다.');
}
$html_title = '게시판그룹';
$gr_id_attr = '';
$sound_only = '';
if( ! isset($group['gr_id']) ){
if (!isset($group['gr_id'])) {
$group['gr_id'] = '';
$group['gr_subject'] = '';
$group['gr_device'] = '';
}
$gr = array('gr_use_access' => 0, 'gr_admin' => '');
if ($w == '') {
$gr_id_attr = 'required';
$sound_only = '<strong class="sound_only"> 필수</strong>';
$gr = array('gr_use_access' => 0, 'gr_admin'=>'');
$html_title .= ' 생성';
} else if ($w == 'u') {
} elseif ($w == 'u') {
$gr_id_attr = 'readonly';
$gr = sql_fetch(" select * from {$g5['group_table']} where gr_id = '$gr_id' ");
$html_title .= ' 수정';
}
else
} else {
alert('제대로 된 값이 넘어오지 않았습니다.');
if (!isset($group['gr_device'])) {
sql_query(" ALTER TABLE `{$g5['group_table']}` ADD `gr_device` ENUM('both','pc','mobile') NOT NULL DEFAULT 'both' AFTER `gr_subject` ", false);
}
// 접근회원수
$sql1 = " select count(*) as cnt from {$g5['group_member_table']} where gr_id = '{$gr_id}' ";
$row1 = sql_fetch($sql1);
$group_member_count = $row1['cnt'];
$g5['title'] = $html_title;
include_once('./admin.head.php');
require_once './admin.head.php';
?>
<form name="fboardgroup" id="fboardgroup" action="./boardgroup_form_update.php" onsubmit="return fboardgroup_check(this);" method="post" autocomplete="off">
<input type="hidden" name="w" value="<?php echo $w ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<input type="hidden" name="w" value="<?php echo $w ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="gr_id">그룹 ID<?php echo $sound_only ?></label></th>
<td><input type="text" name="gr_id" value="<?php echo $group['gr_id'] ?>" id="gr_id" <?php echo $gr_id_attr; ?> class="<?php echo $gr_id_attr; ?> alnum_ frm_input" maxlength="10">
<?php
if ($w=='')
echo '영문자, 숫자, _ 만 가능 (공백없이)';
else
echo '<a href="'.G5_BBS_URL.'/group.php?gr_id='.$group['gr_id'].'" class="btn_frmline">게시판그룹 바로가기</a>';
?>
</td>
</tr>
<tr>
<th scope="row"><label for="gr_subject">그룹 제목<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="gr_subject" value="<?php echo get_text($group['gr_subject']) ?>" id="gr_subject" required class="required frm_input" size="80">
<?php
if ($w == 'u')
echo '<a href="./board_form.php?gr_id='.$gr_id.'" class="btn_frmline">게시판생성</a>';
?>
</td>
</tr>
<tr>
<th scope="row"><label for="gr_device">접속기기</label></th>
<td>
<?php echo help("PC 와 모바일 사용을 구분합니다.") ?>
<select id="gr_device" name="gr_device">
<option value="both"<?php echo get_selected($group['gr_device'], 'both', true); ?>>PC와 모바일에서 모두 사용</option>
<option value="pc"<?php echo get_selected($group['gr_device'], 'pc'); ?>>PC 전용</option>
<option value="mobile"<?php echo get_selected($group['gr_device'], 'mobile'); ?>>모바일 전용</option>
</select>
</td>
</tr>
<tr>
<th scope="row"><?php if ($is_admin == 'super') { ?><label for="gr_admin"><?php } ?>그룹 관리자<?php if ($is_admin == 'super') { ?></label><?php } ?></th>
<td>
<?php
if ($is_admin == 'super')
echo '<input type="text" id="gr_admin" name="gr_admin" class="frm_input" value="'.$gr['gr_admin'].'" maxlength="20">';
else
echo '<input type="hidden" id="gr_admin" name="gr_admin" value="'.$gr['gr_admin'].'">'.$gr['gr_admin'];
?>
</td>
</tr>
<tr>
<th scope="row"><label for="gr_use_access">접근회원사용</label></th>
<td>
<?php echo help("사용에 체크하시면 이 그룹에 속한 게시판은 접근가능한 회원만 접근이 가능합니다.") ?>
<input type="checkbox" name="gr_use_access" value="1" id="gr_use_access" <?php echo $gr['gr_use_access']?'checked':''; ?>>
사용
</td>
</tr>
<tr>
<th scope="row">접근회원수</th>
<td>
<?php
// 접근회원수
$sql1 = " select count(*) as cnt from {$g5['group_member_table']} where gr_id = '{$gr_id}' ";
$row1 = sql_fetch($sql1);
echo '<a href="./boardgroupmember_list.php?gr_id='.$gr_id.'">'.$row1['cnt'].'</a>';
?>
</td>
</tr>
<?php for ($i=1;$i<=10;$i++) { ?>
<tr>
<th scope="row">여분필드<?php echo $i ?></th>
<td class="td_extra">
<label for="gr_<?php echo $i ?>_subj">여분필드 <?php echo $i ?> 제목</label>
<input type="text" name="gr_<?php echo $i ?>_subj" value="<?php echo isset($group['gr_'.$i.'_subj']) ? get_text($group['gr_'.$i.'_subj']) : ''; ?>" id="gr_<?php echo $i ?>_subj" class="frm_input">
<label for="gr_<?php echo $i ?>">여분필드 <?php echo $i ?> 내용</label>
<input type="text" name="gr_<?php echo $i ?>" value="<?php echo isset($gr['gr_'.$i]) ? get_sanitize_input($gr['gr_'.$i]) : ''; ?>" id="gr_<?php echo $i ?>" class="frm_input">
</td>
</tr>
<?php } ?>
</tbody>
</table>
</div>
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="gr_id">그룹 ID<?php echo $sound_only ?></label></th>
<td><input type="text" name="gr_id" value="<?php echo $group['gr_id'] ?>" id="gr_id" <?php echo $gr_id_attr; ?> class="<?php echo $gr_id_attr; ?> alnum_ frm_input" maxlength="10">
<?php
if ($w == '') {
echo '영문자, 숫자, _ 만 가능 (공백없이)';
} else {
echo '<a href="' . G5_BBS_URL . '/group.php?gr_id=' . $group['gr_id'] . '" class="btn_frmline">게시판그룹 바로가기</a>';
}
?>
</td>
</tr>
<tr>
<th scope="row"><label for="gr_subject">그룹 제목<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="gr_subject" value="<?php echo get_text($group['gr_subject']) ?>" id="gr_subject" required class="required frm_input" size="80">
<?php
if ($w == 'u') {
echo '<a href="./board_form.php?gr_id=' . $gr_id . '" class="btn_frmline">게시판생성</a>';
}
?>
</td>
</tr>
<tr>
<th scope="row"><label for="gr_device">접속기기</label></th>
<td>
<?php echo help("PC 와 모바일 사용을 구분합니다.") ?>
<select id="gr_device" name="gr_device">
<option value="both" <?php echo get_selected($group['gr_device'], 'both', true); ?>>PC와 모바일에서 모두 사용</option>
<option value="pc" <?php echo get_selected($group['gr_device'], 'pc'); ?>>PC 전용</option>
<option value="mobile" <?php echo get_selected($group['gr_device'], 'mobile'); ?>>모바일 전용</option>
</select>
</td>
</tr>
<tr>
<th scope="row">
<?php
if ($is_admin == 'super') {
echo '<label for="gr_admin">그룹 관리자</label>';
} else {
echo '그룹 관리자';
}
?>
</th>
<td>
<?php
if ($is_admin == 'super') {
echo '<input type="text" id="gr_admin" name="gr_admin" class="frm_input" value="' . $gr['gr_admin'] . '" maxlength="20">';
} else {
echo '<input type="hidden" id="gr_admin" name="gr_admin" value="' . $gr['gr_admin'] . '">' . $gr['gr_admin'];
}
?>
</td>
</tr>
<tr>
<th scope="row"><label for="gr_use_access">접근회원사용</label></th>
<td>
<?php echo help("사용에 체크하시면 이 그룹에 속한 게시판은 접근가능한 회원만 접근이 가능합니다.") ?>
<input type="checkbox" name="gr_use_access" value="1" id="gr_use_access" <?php echo $gr['gr_use_access'] ? 'checked' : ''; ?>>
사용
</td>
</tr>
<tr>
<th scope="row">접근회원수</th>
<td>
<?php
echo '<a href="./boardgroupmember_list.php?gr_id=' . $gr_id . '">' . $group_member_count . '</a>';
?>
</td>
</tr>
<?php for ($i = 1; $i <= 10; $i++) { ?>
<tr>
<th scope="row">여분필드<?php echo $i ?></th>
<td class="td_extra">
<label for="gr_<?php echo $i ?>_subj">여분필드 <?php echo $i ?> 제목</label>
<input type="text" name="gr_<?php echo $i ?>_subj" value="<?php echo isset($group['gr_' . $i . '_subj']) ? get_text($group['gr_' . $i . '_subj']) : ''; ?>" id="gr_<?php echo $i ?>_subj" class="frm_input">
<label for="gr_<?php echo $i ?>">여분필드 <?php echo $i ?> 내용</label>
<input type="text" name="gr_<?php echo $i ?>" value="<?php echo isset($gr['gr_' . $i]) ? get_sanitize_input($gr['gr_' . $i]) : ''; ?>" id="gr_<?php echo $i ?>" class="frm_input">
</td>
</tr>
<?php } ?>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<a href="./boardgroup_list.php?<?php echo $qstr ?>" class="btn btn_02">목록</a>
<input type="submit" class="btn_submit btn" accesskey="s" value="확인">
</div>
<div class="btn_fixed_top">
<a href="./boardgroup_list.php?<?php echo $qstr ?>" class="btn btn_02">목록</a>
<input type="submit" class="btn_submit btn" accesskey="s" value="확인">
</div>
</form>
@@ -147,12 +158,11 @@ include_once('./admin.head.php');
</div>
<script>
function fboardgroup_check(f)
{
f.action = './boardgroup_form_update.php';
return true;
}
function fboardgroup_check(f) {
f.action = './boardgroup_form_update.php';
return true;
}
</script>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+27 -23
View File
@@ -1,39 +1,45 @@
<?php
$sub_menu = "300200";
include_once('./_common.php');
require_once './_common.php';
if ($w == 'u')
if ($w == 'u') {
check_demo();
}
auth_check_menu($auth, $sub_menu, 'w');
if ($is_admin != 'super' && $w == '') alert('최고관리자만 접근 가능합니다.');
if ($is_admin != 'super' && $w == '') {
alert('최고관리자만 접근 가능합니다.');
}
check_admin_token();
$gr_id = isset($_POST['gr_id']) ? $_POST['gr_id'] : '';
if (!preg_match("/^([A-Za-z0-9_]{1,10})$/", $gr_id))
if (!preg_match("/^([A-Za-z0-9_]{1,10})$/", $gr_id)) {
alert('그룹 ID는 공백없이 영문자, 숫자, _ 만 사용 가능합니다. (10자 이내)');
}
if (!$gr_subject) alert('그룹 제목을 입력하세요.');
if (empty($gr_subject)) {
alert('그룹 제목을 입력하세요.');
}
$posts = array();
$check_keys = array(
'gr_subject'=>'',
'gr_device'=>'',
'gr_admin'=>'',
'gr_subject' => '',
'gr_device' => '',
'gr_admin' => '',
);
for($i=1;$i<=10;$i++){
$check_keys['gr_'.$i.'_subj'] = isset($_POST['gr_'.$i.'_subj']) ? $_POST['gr_'.$i.'_subj'] : '';
$check_keys['gr_'.$i] = isset($_POST['gr_'.$i]) ? $_POST['gr_'.$i] : '';
for ($i = 1; $i <= 10; $i++) {
$check_keys['gr_' . $i . '_subj'] = isset($_POST['gr_' . $i . '_subj']) ? $_POST['gr_' . $i . '_subj'] : '';
$check_keys['gr_' . $i] = isset($_POST['gr_' . $i]) ? $_POST['gr_' . $i] : '';
}
foreach( $check_keys as $key=>$value ){
if( $key === 'gr_subject' ){
$posts[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
foreach ($check_keys as $key => $value) {
if ($key === 'gr_subject') {
$posts[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
} else {
$posts[$key] = isset($_POST[$key]) ? $_POST[$key] : '';
}
@@ -62,34 +68,32 @@ $sql_common = " gr_subject = '{$posts['gr_subject']}',
gr_8 = '{$posts['gr_8']}',
gr_9 = '{$posts['gr_9']}',
gr_10 = '{$posts['gr_10']}' ";
if (isset($_POST['gr_use_access']))
if (isset($_POST['gr_use_access'])) {
$sql_common .= ", gr_use_access = '{$_POST['gr_use_access']}' ";
else
} else {
$sql_common .= ", gr_use_access = '' ";
}
if ($w == '') {
$sql = " select count(*) as cnt from {$g5['group_table']} where gr_id = '{$gr_id}' ";
$row = sql_fetch($sql);
if ($row['cnt'])
if ($row['cnt']) {
alert('이미 존재하는 그룹 ID 입니다.');
}
$sql = " insert into {$g5['group_table']}
set gr_id = '{$gr_id}',
{$sql_common} ";
sql_query($sql);
} else if ($w == "u") {
} elseif ($w == "u") {
$sql = " update {$g5['group_table']}
set {$sql_common}
where gr_id = '{$gr_id}' ";
sql_query($sql);
} else {
alert('제대로 된 값이 넘어오지 않았습니다.');
}
run_event('admin_boardgroup_form_update', $gr_id, $w);
goto_url('./boardgroup_form.php?w=u&amp;gr_id='.$gr_id.'&amp;'.$qstr);
goto_url('./boardgroup_form.php?w=u&amp;gr_id=' . $gr_id . '&amp;' . $qstr);
+135 -133
View File
@@ -1,42 +1,44 @@
<?php
$sub_menu = "300200";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
if (!isset($group['gr_device'])) {
// 게시판 그룹 사용 필드 추가
// both : pc, mobile 둘다 사용
// pc : pc 전용 사용
// mobile : mobile 전용 사용
// none : 사용 안함
sql_query(" ALTER TABLE `{$g5['group_table']}` ADD `gr_device` ENUM( 'both', 'pc', 'mobile' ) NOT NULL DEFAULT 'both' AFTER `gr_subject` ", false);
}
$sql_common = " from {$g5['group_table']} ";
$sql_search = " where (1) ";
if ($is_admin != 'super')
if ($is_admin != 'super') {
$sql_search .= " and (gr_admin = '{$member['mb_id']}') ";
}
$allowed_sfl = array('gr_subject', 'gr_id', 'gr_admin');
if (!in_array($sfl, $allowed_sfl)) {
$sfl = 'gr_subject';
}
if ($stx) {
$sql_search .= " and ( ";
switch ($sfl) {
case "gr_id" :
case "gr_admin" :
case "gr_id":
case "gr_admin":
$sql_search .= " ({$sfl} = '{$stx}') ";
break;
default :
default:
$sql_search .= " ({$sfl} like '%{$stx}%') ";
break;
}
$sql_search .= " ) ";
}
if ($sst)
$allowed_sst = array('gr_id', 'gr_subject', 'gr_admin', 'gr_order');
if ($sst && !in_array($sst, $allowed_sst)) $sst = '';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
if ($sst) {
$sql_order = " order by {$sst} {$sod} ";
else
} else {
$sql_order = " order by gr_id asc ";
}
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
@@ -44,136 +46,137 @@ $total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) $page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
if ($page < 1) {
$page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
}
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select * {$sql_common} {$sql_search} {$sql_order} limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">처음</a>';
$listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall">처음</a>';
$g5['title'] = '게시판그룹설정';
include_once('./admin.head.php');
require_once './admin.head.php';
$colspan = 10;
?>
<div class="local_ov01 local_ov">
<?php echo $listall ?>
<span class="btn_ov01"><span class="ov_txt">전체그룹</span><span class="ov_num"> <?php echo number_format($total_count) ?>개</span></span>
<span class="btn_ov01"><span class="ov_txt">전체그룹</span><span class="ov_num"> <?php echo number_format($total_count) ?>개</span></span>
</div>
<form name="fsearch" id="fsearch" class="local_sch01 local_sch" method="get">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="gr_subject"<?php echo get_selected($sfl, "gr_subject"); ?>>제목</option>
<option value="gr_id"<?php echo get_selected($sfl, "gr_id"); ?>>ID</option>
<option value="gr_admin"<?php echo get_selected($sfl, "gr_admin"); ?>>그룹관리자</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" id="stx" value="<?php echo $stx ?>" required class="required frm_input">
<input type="submit" value="검색" class="btn_submit">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="gr_subject" <?php echo get_selected($sfl, "gr_subject"); ?>>제목</option>
<option value="gr_id" <?php echo get_selected($sfl, "gr_id"); ?>>ID</option>
<option value="gr_admin" <?php echo get_selected($sfl, "gr_admin"); ?>>그룹관리자</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" id="stx" value="<?php echo $stx ?>" required class="required frm_input">
<input type="submit" value="검색" class="btn_submit">
</form>
<form name="fboardgrouplist" id="fboardgrouplist" action="./boardgroup_list_update.php" onsubmit="return fboardgrouplist_submit(this);" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">그룹 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('gr_id') ?>그룹아이디</a></th>
<th scope="col"><?php echo subject_sort_link('gr_subject') ?>제목</a></th>
<th scope="col"><?php echo subject_sort_link('gr_admin') ?>그룹관리자</a></th>
<th scope="col">게시판</th>
<th scope="col">접근<br>사용</th>
<th scope="col">접근<br>회원수</th>
<th scope="col"><?php echo subject_sort_link('gr_order') ?>출력<br>순서</a></th>
<th scope="col">접속기기</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++)
{
// 접근회원수
$sql1 = " select count(*) as cnt from {$g5['group_member_table']} where gr_id = '{$row['gr_id']}' ";
$row1 = sql_fetch($sql1);
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">그룹 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('gr_id') ?>그룹아이디</a></th>
<th scope="col"><?php echo subject_sort_link('gr_subject') ?>제목</a></th>
<th scope="col"><?php echo subject_sort_link('gr_admin') ?>그룹관리자</a></th>
<th scope="col">게시판</th>
<th scope="col">접근<br>사용</th>
<th scope="col">접근<br>회원수</th>
<th scope="col"><?php echo subject_sort_link('gr_order') ?>출력<br>순서</a></th>
<th scope="col">접속기기</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
// 접근회원수
$sql1 = " select count(*) as cnt from {$g5['group_member_table']} where gr_id = '{$row['gr_id']}' ";
$row1 = sql_fetch($sql1);
// 게시판수
$sql2 = " select count(*) as cnt from {$g5['board_table']} where gr_id = '{$row['gr_id']}' ";
$row2 = sql_fetch($sql2);
// 게시판수
$sql2 = " select count(*) as cnt from {$g5['board_table']} where gr_id = '{$row['gr_id']}' ";
$row2 = sql_fetch($sql2);
$s_upd = '<a href="./boardgroup_form.php?'.$qstr.'&amp;w=u&amp;gr_id='.$row['gr_id'].'" class="btn_03 btn">수정</a>';
$s_upd = '<a href="./boardgroup_form.php?' . $qstr . '&amp;w=u&amp;gr_id=' . $row['gr_id'] . '" class="btn_03 btn">수정</a>';
$bg = 'bg'.($i%2);
?>
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<input type="hidden" name="group_id[<?php echo $i ?>]" value="<?php echo $row['gr_id'] ?>">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo get_text($row['gr_subject']); ?> 그룹</label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_left"><a href="<?php echo G5_BBS_URL ?>/group.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo $row['gr_id'] ?></a></td>
<td class="td_input">
<label for="gr_subject_<?php echo $i; ?>" class="sound_only">그룹제목</label>
<input type="text" name="gr_subject[<?php echo $i ?>]" value="<?php echo get_text($row['gr_subject']) ?>" id="gr_subject_<?php echo $i ?>" class="tbl_input">
</td>
<td class="td_mng td_input">
<?php if ($is_admin == 'super'){ ?>
<label for="gr_admin_<?php echo $i; ?>" class="sound_only">그룹관리자</label>
<input type="text" name="gr_admin[<?php echo $i ?>]" value="<?php echo get_sanitize_input($row['gr_admin']); ?>" id="gr_admin_<?php echo $i ?>" class="tbl_input" size="10" maxlength="20">
<?php }else{ ?>
<input type="hidden" name="gr_admin[<?php echo $i ?>]" value="<?php echo get_sanitize_input($row['gr_admin']); ?>"><?php echo get_text($row['gr_admin']); ?>
<?php } ?>
</td>
<td class="td_num"><a href="./board_list.php?sfl=a.gr_id&amp;stx=<?php echo $row['gr_id'] ?>"><?php echo $row2['cnt'] ?></a></td>
<td class="td_numsmall">
<label for="gr_use_access_<?php echo $i; ?>" class="sound_only">접근회원 사용</label>
<input type="checkbox" name="gr_use_access[<?php echo $i ?>]" <?php echo $row['gr_use_access']?'checked':'' ?> value="1" id="gr_use_access_<?php echo $i ?>">
</td>
<td class="td_num"><a href="./boardgroupmember_list.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo $row1['cnt'] ?></a></td>
<td class="td_numsmall">
<label for="gr_order_<?php echo $i; ?>" class="sound_only">메인메뉴 출력순서</label>
<input type="text" name="gr_order[<?php echo $i ?>]" value="<?php echo $row['gr_order'] ?>" id="gr_order_<?php echo $i ?>" class="tbl_input" size="2">
</td>
<td class="td_mng">
<label for="gr_device_<?php echo $i; ?>" class="sound_only">접속기기</label>
<select name="gr_device[<?php echo $i ?>]" id="gr_device_<?php echo $i ?>">
<option value="both"<?php echo get_selected($row['gr_device'], 'both'); ?>>모두</option>
<option value="pc"<?php echo get_selected($row['gr_device'], 'pc'); ?>>PC</option>
<option value="mobile"<?php echo get_selected($row['gr_device'], 'mobile'); ?>>모바일</option>
</select>
</td>
<td class="td_mng td_mng_s"><?php echo $s_upd ?></td>
</tr>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<input type="hidden" name="group_id[<?php echo $i ?>]" value="<?php echo $row['gr_id'] ?>">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo get_text($row['gr_subject']); ?> 그룹</label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_left"><a href="<?php echo G5_BBS_URL ?>/group.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo $row['gr_id'] ?></a></td>
<td class="td_input">
<label for="gr_subject_<?php echo $i; ?>" class="sound_only">그룹제목</label>
<input type="text" name="gr_subject[<?php echo $i ?>]" value="<?php echo get_text($row['gr_subject']) ?>" id="gr_subject_<?php echo $i ?>" class="tbl_input">
</td>
<td class="td_mng td_input">
<?php if ($is_admin == 'super') { ?>
<label for="gr_admin_<?php echo $i; ?>" class="sound_only">그룹관리자</label>
<input type="text" name="gr_admin[<?php echo $i ?>]" value="<?php echo get_sanitize_input($row['gr_admin']); ?>" id="gr_admin_<?php echo $i ?>" class="tbl_input" size="10" maxlength="20">
<?php } else { ?>
<input type="hidden" name="gr_admin[<?php echo $i ?>]" value="<?php echo get_sanitize_input($row['gr_admin']); ?>"><?php echo get_text($row['gr_admin']); ?>
<?php } ?>
</td>
<td class="td_num"><a href="./board_list.php?sfl=a.gr_id&amp;stx=<?php echo $row['gr_id'] ?>"><?php echo $row2['cnt'] ?></a></td>
<td class="td_numsmall">
<label for="gr_use_access_<?php echo $i; ?>" class="sound_only">접근회원 사용</label>
<input type="checkbox" name="gr_use_access[<?php echo $i ?>]" <?php echo $row['gr_use_access'] ? 'checked' : '' ?> value="1" id="gr_use_access_<?php echo $i ?>">
</td>
<td class="td_num"><a href="./boardgroupmember_list.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo $row1['cnt'] ?></a></td>
<td class="td_numsmall">
<label for="gr_order_<?php echo $i; ?>" class="sound_only">메인메뉴 출력순서</label>
<input type="text" name="gr_order[<?php echo $i ?>]" value="<?php echo $row['gr_order'] ?>" id="gr_order_<?php echo $i ?>" class="tbl_input" size="2">
</td>
<td class="td_mng">
<label for="gr_device_<?php echo $i; ?>" class="sound_only">접속기기</label>
<select name="gr_device[<?php echo $i ?>]" id="gr_device_<?php echo $i ?>">
<option value="both" <?php echo get_selected($row['gr_device'], 'both'); ?>>모두</option>
<option value="pc" <?php echo get_selected($row['gr_device'], 'pc'); ?>>PC</option>
<option value="mobile" <?php echo get_selected($row['gr_device'], 'mobile'); ?>>모바일</option>
</select>
</td>
<td class="td_mng td_mng_s"><?php echo $s_upd ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</table>
</div>
<?php
}
if ($i == 0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</table>
</div>
<div class="btn_fixed_top">
<input type="submit" name="act_button" onclick="document.pressed=this.value" value="선택수정" class="btn btn_02">
<input type="submit" name="act_button" onclick="document.pressed=this.value" value="선택삭제" class="btn btn_02">
<a href="./boardgroup_form.php" class="btn btn_01">게시판그룹 추가</a>
</div>
<div class="btn_fixed_top">
<input type="submit" name="act_button" onclick="document.pressed=this.value" value="선택수정" class="btn btn_02">
<input type="submit" name="act_button" onclick="document.pressed=this.value" value="선택삭제" class="btn btn_02">
<a href="./boardgroup_form.php" class="btn btn_01">게시판그룹 추가</a>
</div>
</form>
<div class="local_desc01 local_desc">
@@ -184,27 +187,26 @@ $colspan = 10;
</div>
<?php
$pagelist = get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, $_SERVER['SCRIPT_NAME'].'?'.$qstr.'&amp;page=');
$pagelist = get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, $_SERVER['SCRIPT_NAME'] . '?' . $qstr . '&amp;page=');
echo $pagelist;
?>
<script>
function fboardgrouplist_submit(f)
{
if (!is_checked("chk[]")) {
alert(document.pressed+" 하실 항목을 하나 이상 선택하세요.");
return false;
}
if(document.pressed == "선택삭제") {
if(!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
function fboardgrouplist_submit(f) {
if (!is_checked("chk[]")) {
alert(document.pressed + " 하실 항목을 하나 이상 선택하세요.");
return false;
}
}
return true;
}
if (document.pressed == "선택삭제") {
if (!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
return false;
}
}
return true;
}
</script>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
+30 -30
View File
@@ -1,8 +1,6 @@
<?php
$sub_menu = "300200";
include_once('./_common.php');
//print_r2($_POST); exit;
require_once './_common.php';
check_demo();
@@ -10,40 +8,42 @@ auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
$post_chk = isset($_POST['chk']) ? (array) $_POST['chk'] : array();
$post_group_id = isset($_POST['group_id']) ? (array) $_POST['group_id'] : array();
$act_button = isset($_POST['act_button']) ? $_POST['act_button'] : '';
$post_chk = isset($_POST['chk']) ? (array) $_POST['chk'] : array();
$post_group_id = isset($_POST['group_id']) ? (array) $_POST['group_id'] : array();
$act_button = isset($_POST['act_button']) ? $_POST['act_button'] : '';
$count = count($post_chk);
$chk_count = count($post_chk);
if(!$count)
alert($act_button.'할 게시판그룹을 1개이상 선택해 주세요.');
if (!$chk_count) {
alert($act_button . '할 게시판그룹을 1개이상 선택해 주세요.');
}
for ($i=0; $i<$count; $i++)
{
$k = isset($post_chk[$i]) ? (int) $post_chk[$i] : 0;
$gr_id = preg_replace('/[^a-z0-9_]/i', '', $post_group_id[$k]);
$gr_subject = isset($_POST['gr_subject'][$k]) ? strip_tags(clean_xss_attributes($_POST['gr_subject'][$k])) : '';
$gr_admin = isset($_POST['gr_admin'][$k]) ? strip_tags(clean_xss_attributes($_POST['gr_admin'][$k])) : '';
$gr_device = isset($_POST['gr_device'][$k]) ? clean_xss_tags($_POST['gr_device'][$k], 1, 1, 10) : '';
$gr_use_access = isset($_POST['gr_use_access'][$k]) ? (int) $_POST['gr_use_access'][$k] : 0;
$gr_order = isset($_POST['gr_order'][$k]) ? (int) $_POST['gr_order'][$k] : 0;
for ($i = 0; $i < $chk_count; $i++) {
$k = isset($post_chk[$i]) ? (int) $post_chk[$i] : 0;
$gr_id = preg_replace('/[^a-z0-9_]/i', '', $post_group_id[$k]);
$gr_subject = isset($_POST['gr_subject'][$k]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['gr_subject'][$k])))) : '';
$gr_admin = isset($_POST['gr_admin'][$k]) ? strip_tags(clean_xss_attributes($_POST['gr_admin'][$k])) : '';
$gr_device = isset($_POST['gr_device'][$k]) ? clean_xss_tags($_POST['gr_device'][$k], 1, 1, 10) : '';
$gr_use_access = isset($_POST['gr_use_access'][$k]) ? (int) $_POST['gr_use_access'][$k] : 0;
$gr_order = isset($_POST['gr_order'][$k]) ? (int) $_POST['gr_order'][$k] : 0;
if($act_button == '선택수정') {
if ($act_button == '선택수정') {
$sql = " update {$g5['group_table']}
set gr_subject = '{$gr_subject}',
gr_device = '".sql_real_escape_string($gr_device)."',
gr_admin = '".sql_real_escape_string($gr_admin)."',
gr_use_access = '".$gr_use_access."',
gr_order = '".$gr_order."'
gr_device = '" . sql_real_escape_string($gr_device) . "',
gr_admin = '" . sql_real_escape_string($gr_admin) . "',
gr_use_access = '" . $gr_use_access . "',
gr_order = '" . $gr_order . "'
where gr_id = '{$gr_id}' ";
if ($is_admin != 'super')
$sql .= " and gr_admin = '{$gr_admin}' ";
if ($is_admin != 'super') {
$sql .= " and gr_admin = '" . sql_real_escape_string($gr_admin) . "' ";
}
sql_query($sql);
} else if($act_button == '선택삭제') {
} elseif ($act_button == '선택삭제') {
$row = sql_fetch(" select count(*) as cnt from {$g5['board_table']} where gr_id = '$gr_id' ");
if ($row['cnt'])
alert("이 그룹에 속한 게시판이 존재하여 게시판 그룹을 삭제할 수 없습니다.\\n\\n이 그룹에 속한 게시판을 먼저 삭제하여 주십시오.", './board_list.php?sfl=gr_id&amp;stx='.$gr_id);
if ($row['cnt']) {
alert("이 그룹에 속한 게시판이 존재하여 게시판 그룹을 삭제할 수 없습니다.\\n\\n이 그룹에 속한 게시판을 먼저 삭제하여 주십시오.", './board_list.php?sfl=a.gr_id&amp;stx=' . $gr_id);
}
// 그룹 삭제
sql_query(" delete from {$g5['group_table']} where gr_id = '$gr_id' ");
@@ -53,6 +53,6 @@ for ($i=0; $i<$count; $i++)
}
}
run_event('admin_boardgroup_list_update', $act_button, $chk, $post_group_id, $qstr);
run_event('admin_boardgroup_list_update', $act_button, $post_chk, $post_group_id, $qstr);
goto_url('./boardgroup_list.php?'.$qstr);
goto_url('./boardgroup_list.php?' . $qstr);
+101 -100
View File
@@ -1,133 +1,134 @@
<?php
$sub_menu = "300200";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'w');
$mb = get_member($mb_id);
$token = isset($token) ? $token : '';
if (! (isset($mb['mb_id']) && $mb['mb_id']))
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
alert('존재하지 않는 회원입니다.');
}
$g5['title'] = '접근가능그룹';
include_once('./admin.head.php');
require_once './admin.head.php';
$colspan = 4;
?>
<form name="fboardgroupmember_form" id="fboardgroupmember_form" action="./boardgroupmember_update.php" onsubmit="return boardgroupmember_form_check(this)" method="post">
<input type="hidden" name="mb_id" value="<?php echo $mb['mb_id'] ?>" id="mb_id">
<input type="hidden" name="token" value="" id="token">
<div class="local_ov01 local_ov">
<span class="btn_ov01"><span class="ov_txt"> 아이디</span><span class="ov_num"><?php echo $mb['mb_id'] ?></span></span>
<span class="btn_ov01"><span class="ov_txt"> 이름</span><span class="ov_num"><?php echo get_text($mb['mb_name']); ?></span></span>
<span class="btn_ov01"><span class="ov_txt"> 닉네임</span><span class="ov_num"><?php echo $mb['mb_nick'] ?></span></span>
</div>
<div class="local_cmd01 local_cmd">
<input type="hidden" name="mb_id" value="<?php echo $mb['mb_id'] ?>" id="mb_id">
<input type="hidden" name="token" value="" id="token">
<label for="gr_id">그룹지정</label>
<select name="gr_id" id="gr_id">
<option value="">접근가능 그룹을 선택하세요.</option>
<?php
$sql = " select *
from {$g5['group_table']}
where gr_use_access = 1 ";
//if ($is_admin == 'group') {
if ($is_admin != 'super')
$sql .= " and gr_admin = '{$member['mb_id']}' ";
$sql .= " order by gr_id ";
$result = sql_query($sql);
for ($i=0; $row=sql_fetch_array($result); $i++) {
echo "<option value=\"".$row['gr_id']."\">".$row['gr_subject']."</option>";
}
?>
</select>
<input type="submit" value="선택" class="btn_submit btn" accesskey="s">
</div>
<div class="local_ov01 local_ov">
<span class="btn_ov01"><span class="ov_txt"> 아이디</span><span class="ov_num"><?php echo $mb['mb_id'] ?></span></span>
<span class="btn_ov01"><span class="ov_txt"> 이름</span><span class="ov_num"><?php echo get_text($mb['mb_name']); ?></span></span>
<span class="btn_ov01"><span class="ov_txt"> 닉네임</span><span class="ov_num"><?php echo $mb['mb_nick'] ?></span></span>
</div>
<div class="local_cmd01 local_cmd">
<label for="gr_id">그룹지정</label>
<select name="gr_id" id="gr_id">
<option value="">접근가능 그룹을 선택하세요.</option>
<?php
$sql = " select *
from {$g5['group_table']}
where gr_use_access = 1 ";
if ($is_admin != 'super') {
$sql .= " and gr_admin = '{$member['mb_id']}' ";
}
$sql .= " order by gr_id ";
$result = sql_query($sql);
for ($i = 0; $row = sql_fetch_array($result); $i++) {
echo "<option value=\"" . $row['gr_id'] . "\">" . $row['gr_subject'] . "</option>";
}
?>
</select>
<input type="submit" value="선택" class="btn_submit btn" accesskey="s">
</div>
</form>
<form name="fboardgroupmember" id="fboardgroupmember" action="./boardgroupmember_update.php" onsubmit="return fboardgroupmember_submit(this);" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>" id="sst">
<input type="hidden" name="sod" value="<?php echo $sod ?>" id="sod">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>" id="sfl">
<input type="hidden" name="stx" value="<?php echo $stx ?>" id="stx">
<input type="hidden" name="page" value="<?php echo $page ?>" id="page">
<input type="hidden" name="token" value="<?php echo get_sanitize_input($token); ?>" id="token">
<input type="hidden" name="mb_id" value="<?php echo $mb['mb_id'] ?>" id="mb_id">
<input type="hidden" name="w" value="d" id="w">
<input type="hidden" name="sst" value="<?php echo $sst ?>" id="sst">
<input type="hidden" name="sod" value="<?php echo $sod ?>" id="sod">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>" id="sfl">
<input type="hidden" name="stx" value="<?php echo $stx ?>" id="stx">
<input type="hidden" name="page" value="<?php echo $page ?>" id="page">
<input type="hidden" name="token" value="<?php echo get_sanitize_input($token); ?>" id="token">
<input type="hidden" name="mb_id" value="<?php echo $mb['mb_id'] ?>" id="mb_id">
<input type="hidden" name="w" value="d" id="w">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">접근가능그룹 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col">그룹아이디</th>
<th scope="col">그룹</th>
<th scope="col">처리일시</th>
</tr>
</thead>
<tbody>
<?php
$sql = " select * from {$g5['group_member_table']} a, {$g5['group_table']} b
where a.mb_id = '{$mb['mb_id']}'
and a.gr_id = b.gr_id ";
if ($is_admin != 'super')
$sql .= " and b.gr_admin = '{$member['mb_id']}' ";
$sql .= " order by a.gr_id desc ";
$result = sql_query($sql);
for ($i=0; $row=sql_fetch_array($result); $i++) {
?>
<tr>
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['gr_subject'] ?> 그룹</label>
<input type="checkbox" name="chk[]" value="<?php echo $row['gm_id'] ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_grid"><a href="<?php echo G5_BBS_URL; ?>/group.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo $row['gr_id'] ?></a></td>
<td class="td_category"><?php echo $row['gr_subject'] ?></td>
<td class="td_datetime"><?php echo $row['gm_datetime'] ?></td>
</tr>
<?php
}
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">접근가능그룹 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col">그룹아이디</th>
<th scope="col">그룹</th>
<th scope="col">처리일시</th>
</tr>
</thead>
<tbody>
<?php
$sql = " select * from {$g5['group_member_table']} a, {$g5['group_table']} b
where a.mb_id = '{$mb['mb_id']}'
and a.gr_id = b.gr_id ";
if ($is_admin != 'super') {
$sql .= " and b.gr_admin = '{$member['mb_id']}' ";
}
$sql .= " order by a.gr_id desc ";
$result = sql_query($sql);
for ($i = 0; $row = sql_fetch_array($result); $i++) {
?>
<tr>
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['gr_subject'] ?> 그룹</label>
<input type="checkbox" name="chk[]" value="<?php echo $row['gm_id'] ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_grid"><a href="<?php echo G5_BBS_URL; ?>/group.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo $row['gr_id'] ?></a></td>
<td class="td_category"><?php echo $row['gr_subject'] ?></td>
<td class="td_datetime"><?php echo $row['gm_datetime'] ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="'.$colspan.'" class="empty_table">접근가능한 그룹이 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">접근가능한 그룹이 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list01 btn_list">
<input type="submit" name="" value="선택삭제" class="btn btn_02">
</div>
<div class="btn_list01 btn_list">
<input type="submit" name="" value="선택삭제" class="btn btn_02">
</div>
</form>
<script>
function fboardgroupmember_submit(f)
{
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
return false;
function fboardgroupmember_submit(f) {
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
return false;
}
return true;
}
return true;
}
function boardgroupmember_form_check(f) {
if (f.gr_id.value == '') {
alert('접근가능 그룹을 선택하세요.');
return false;
}
function boardgroupmember_form_check(f)
{
if (f.gr_id.value == '') {
alert('접근가능 그룹을 선택하세요.');
return false;
return true;
}
return true;
}
</script>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
+98 -88
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = "300200";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
@@ -11,13 +11,18 @@ if (!$gr['gr_id']) {
$sql_common = " from {$g5['group_member_table']} a
left outer join {$g5['member_table']} b on (a.mb_id = b.mb_id) ";
$sql_search = " where gr_id = '{$gr_id}' ";
$allowed_sfl = array('a.mb_id');
if (!in_array($sfl, $allowed_sfl)) {
$sfl = 'a.mb_id';
}
// 회원아이디로 검색되지 않던 오류를 수정
if (isset($stx) && $stx) {
$sql_search .= " and ( ";
switch ($sfl) {
default :
default:
$sql_search .= " ($sfl like '%$stx%') ";
break;
}
@@ -25,9 +30,12 @@ if (isset($stx) && $stx) {
}
if (!$sst) {
$sst = "gm_datetime";
$sst = "gm_datetime";
$sod = "desc";
}
$allowed_sst = array('gm_datetime', 'b.mb_id', 'b.mb_name', 'b.mb_nick', 'b.mb_today_login', 'a.gm_datetime');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'gm_datetime';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
@@ -39,7 +47,9 @@ $total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) $page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
if ($page < 1) {
$page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
}
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select *
@@ -49,107 +59,107 @@ $sql = " select *
limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$g5['title'] = $gr['gr_subject'].' 그룹 접근가능회원 (그룹아이디:'.$gr['gr_id'].')';
include_once('./admin.head.php');
$g5['title'] = $gr['gr_subject'] . ' 그룹 접근가능회원 (그룹아이디:' . $gr['gr_id'] . ')';
require_once './admin.head.php';
$colspan = 7;
?>
<form name="fsearch" id="fsearch" class="local_sch01 local_sch" method="get">
<input type="hidden" name="gr_id" value="<?php echo $gr_id ?>">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="a.mb_id"<?php echo get_selected($sfl, "a.mb_id") ?>>회원아이디</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" value="검색" class="btn_submit">
<input type="hidden" name="gr_id" value="<?php echo $gr_id ?>">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="a.mb_id" <?php echo get_selected($sfl, "a.mb_id") ?>>회원아이디</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" value="검색" class="btn_submit">
</form>
<form name="fboardgroupmember" id="fboardgroupmember" action="./boardgroupmember_update.php" onsubmit="return fboardgroupmember_submit(this);" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo $token ?>">
<input type="hidden" name="gr_id" value="<?php echo $gr_id ?>">
<input type="hidden" name="w" value="ld">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo $token ?>">
<input type="hidden" name="gr_id" value="<?php echo $gr_id ?>">
<input type="hidden" name="w" value="ld">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">접근가능회원 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col">그룹</th>
<th scope="col"><?php echo subject_sort_link('b.mb_id', 'gr_id='.$gr_id) ?>회원아이디</a></th>
<th scope="col"><?php echo subject_sort_link('b.mb_name', 'gr_id='.$gr_id) ?>이름</a></th>
<th scope="col"><?php echo subject_sort_link('b.mb_nick', 'gr_id='.$gr_id) ?>별명</a></th>
<th scope="col"><?php echo subject_sort_link('b.mb_today_login', 'gr_id='.$gr_id) ?>최종접속</a></th>
<th scope="col"><?php echo subject_sort_link('a.gm_datetime', 'gr_id='.$gr_id) ?>처리일시</a></th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++)
{
// 접근가능한 그룹수
$sql2 = " select count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
$group = "";
if ($row2['cnt'])
$group = '<a href="./boardgroupmember_form.php?mb_id='.$row['mb_id'].'">'.$row2['cnt'].'</a>';
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">접근가능회원 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col">그룹</th>
<th scope="col"><?php echo subject_sort_link('b.mb_id', 'gr_id=' . $gr_id) ?>회원아이디</a></th>
<th scope="col"><?php echo subject_sort_link('b.mb_name', 'gr_id=' . $gr_id) ?>이름</a></th>
<th scope="col"><?php echo subject_sort_link('b.mb_nick', 'gr_id=' . $gr_id) ?>별명</a></th>
<th scope="col"><?php echo subject_sort_link('b.mb_today_login', 'gr_id=' . $gr_id) ?>최종접속</a></th>
<th scope="col"><?php echo subject_sort_link('a.gm_datetime', 'gr_id=' . $gr_id) ?>처리일시</a></th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
// 접근가능한 그룹수
$sql2 = " select count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
$group = "";
if ($row2['cnt']) {
$group = '<a href="./boardgroupmember_form.php?mb_id=' . $row['mb_id'] . '">' . $row2['cnt'] . '</a>';
}
$mb_nick = get_sideview($row['mb_id'], $row['mb_nick'], $row['mb_email'], $row['mb_homepage']);
$mb_nick = get_sideview($row['mb_id'], $row['mb_nick'], $row['mb_email'], $row['mb_homepage']);
$bg = 'bg'.($i%2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['mb_nick'] ?> 회원</label>
<input type="checkbox" name="chk[]" value="<?php echo $row['gm_id'] ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_grid"><?php echo $group ?></td>
<td class="td_mbid"><?php echo $row['mb_id'] ?></td>
<td class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td class="td_name sv_use"><?php echo $mb_nick ?></td>
<td class="td_datetime"><?php echo substr($row['mb_today_login'],2,8) ?></td>
<td class="td_datetime"><?php echo $row['gm_datetime'] ?></td>
</tr>
<?php
}
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['mb_nick'] ?> 회원</label>
<input type="checkbox" name="chk[]" value="<?php echo $row['gm_id'] ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_grid"><?php echo $group ?></td>
<td class="td_mbid"><?php echo $row['mb_id'] ?></td>
<td class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td class="td_name sv_use"><?php echo $mb_nick ?></td>
<td class="td_datetime"><?php echo substr($row['mb_today_login'], 2, 8) ?></td>
<td class="td_datetime"><?php echo $row['gm_datetime'] ?></td>
</tr>
<?php
}
if ($i == 0)
{
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list01 btn_list">
<input type="submit" name="" value="선택삭제">
</div>
<div class="btn_list01 btn_list">
<input type="submit" name="" value="선택삭제">
</div>
</form>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;gr_id=$gr_id&page="); ?>
<?php
echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;gr_id=$gr_id&page=");
?>
<script>
function fboardgroupmember_submit(f)
{
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
return false;
}
function fboardgroupmember_submit(f) {
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
return false;
}
return true;
}
return true;
}
</script>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
+18 -21
View File
@@ -1,20 +1,18 @@
<?php
$sub_menu = "300200";
include_once('./_common.php');
require_once './_common.php';
sql_query(" ALTER TABLE {$g5['group_member_table']} CHANGE `gm_id` `gm_id` INT( 11 ) DEFAULT '0' NOT NULL AUTO_INCREMENT ", false);
if ($w == '')
{
if ($w == '') {
auth_check_menu($auth, $sub_menu, 'w');
$mb = get_member($mb_id);
if (!$mb['mb_id']) {
if (empty($mb['mb_id'])) {
alert('존재하지 않는 회원입니다.');
}
$gr = get_group($gr_id);
if (!$gr['gr_id']) {
if (empty($gr['gr_id'])) {
alert('존재하지 않는 그룹입니다.');
}
@@ -25,37 +23,35 @@ if ($w == '')
$row = sql_fetch($sql);
if ($row['cnt']) {
alert('이미 등록되어 있는 자료입니다.');
}
else
{
} else {
check_admin_token();
$sql = " insert into {$g5['group_member_table']}
set gr_id = '{$_POST['gr_id']}',
mb_id = '{$_POST['mb_id']}',
gm_datetime = '".G5_TIME_YMDHIS."' ";
gm_datetime = '" . G5_TIME_YMDHIS . "' ";
sql_query($sql);
}
}
else if ($w == 'd' || $w == 'ld')
{
} elseif ($w == 'd' || $w == 'ld') {
auth_check_menu($auth, $sub_menu, 'd');
$count = count($_POST['chk']);
if(!$count)
if (!$count) {
alert('삭제할 목록을 하나이상 선택해 주세요.');
}
check_admin_token();
for($i=0; $i<$count; $i++) {
for ($i = 0; $i < $count; $i++) {
$gm_id = (int) $_POST['chk'][$i];
$sql = " select * from {$g5['group_member_table']} where gm_id = '$gm_id' ";
$gm = sql_fetch($sql);
if (!$gm['gm_id']) {
if($count == 1)
if ($count == 1) {
alert('존재하지 않는 자료입니다.');
else
} else {
continue;
}
}
$sql = " delete from {$g5['group_member_table']} where gm_id = '$gm_id' ";
@@ -63,7 +59,8 @@ else if ($w == 'd' || $w == 'ld')
}
}
if ($w == 'ld')
goto_url('./boardgroupmember_list.php?gr_id='.$gr_id);
else
goto_url('./boardgroupmember_form.php?mb_id='.$mb_id);
if ($w == 'ld') {
goto_url('./boardgroupmember_list.php?gr_id=' . $gr_id);
} else {
goto_url('./boardgroupmember_form.php?mb_id=' . $mb_id);
}
+23 -21
View File
@@ -1,15 +1,17 @@
<?php
$sub_menu = "100510";
include_once('./_common.php');
require_once './_common.php';
if(!(version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE))
if (!(version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE)) {
alert('사용할 수 없는 기능입니다.', correct_goto_url(G5_ADMIN_URL));
}
if ($is_admin != 'super')
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
$g5['title'] = 'Browscap 업데이트';
include_once('./admin.head.php');
require_once './admin.head.php';
?>
<div id="processing">
@@ -18,27 +20,27 @@ include_once('./admin.head.php');
</div>
<script>
$(function() {
$("#run_update").on("click", function() {
$("#processing").html('<div class="update_processing"></div><p>Browscap 정보를 업데이트 중입니다.</p>');
$(function() {
$("#run_update").on("click", function() {
$("#processing").html('<div class="update_processing"></div><p>Browscap 정보를 업데이트 중입니다.</p>');
$.ajax({
url: "./browscap_update.php",
async: true,
cache: false,
dataType: "html",
success: function(data) {
if(data != "") {
alert(data);
return false;
$.ajax({
url: "./browscap_update.php",
async: true,
cache: false,
dataType: "html",
success: function(data) {
if (data != "") {
alert(data);
return false;
}
$("#processing").html("<div class='check_processing'></div><p>Browscap 정보를 업데이트 했습니다.</p>");
}
$("#processing").html("<div class='check_processing'></div><p>Browscap 정보를 업데이트 했습니다.</p>");
}
});
});
});
});
</script>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
+25 -20
View File
@@ -1,19 +1,22 @@
<?php
$sub_menu = "100520";
include_once('./_common.php');
require_once './_common.php';
if(!(version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE))
if (!(version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE)) {
alert('사용할 수 없는 기능입니다.', correct_goto_url(G5_ADMIN_URL));
}
if ($is_admin != 'super')
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
$rows = isset($_GET['rows']) ? preg_replace('#[^0-9]#', '', $_GET['rows']) : 0;
if(!$rows)
if (!$rows) {
$rows = 100;
}
$g5['title'] = '접속로그 변환';
include_once('./admin.head.php');
require_once './admin.head.php';
?>
<div id="processing">
@@ -22,24 +25,26 @@ include_once('./admin.head.php');
</div>
<script>
$(function() {
$(document).on("click", "#run_update", function() {
$("#processing").html('<div class="update_processing"></div><p>Browscap 정보로 변환 중입니다.</p>');
$(function() {
$(document).on("click", "#run_update", function() {
$("#processing").html('<div class="update_processing"></div><p>Browscap 정보로 변환 중입니다.</p>');
$.ajax({
method: "GET",
url: "./browscap_converter.php",
data: { rows: "<?php echo $rows; ?>" },
async: true,
cache: false,
dataType: "html",
success: function(data) {
$("#processing").html(data);
}
$.ajax({
method: "GET",
url: "./browscap_converter.php",
data: {
rows: "<?php echo strval($rows); ?>"
},
async: true,
cache: false,
dataType: "html",
success: function(data) {
$("#processing").html(data);
}
});
});
});
});
</script>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
+25 -18
View File
@@ -1,36 +1,39 @@
<?php
ini_set('memory_limit', '-1');
include_once('./_common.php');
require_once './_common.php';
// clean the output buffer
ob_end_clean();
if(!(version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE))
if (!(version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE)) {
die('사용할 수 없는 기능입니다.');
}
if($is_admin != 'super')
if ($is_admin != 'super') {
die('최고관리자로 로그인 후 실행해 주세요.');
}
// browscap cache 파일 체크
if(!is_file(G5_DATA_PATH.'/cache/browscap_cache.php')) {
echo '<p>Browscap 정보가 없습니다. 아래 링크로 이동해 Browscap 정보를 업데이트 하세요.</p>'.PHP_EOL;
echo '<p><a href="'.G5_ADMIN_URL.'/browscap.php">Browscap 업데이트</a></p>'.PHP_EOL;
if (!is_file(G5_DATA_PATH . '/cache/browscap_cache.php')) {
echo '<p>Browscap 정보가 없습니다. 아래 링크로 이동해 Browscap 정보를 업데이트 하세요.</p>' . PHP_EOL;
echo '<p><a href="' . G5_ADMIN_URL . '/browscap.php">Browscap 업데이트</a></p>' . PHP_EOL;
exit;
}
include_once(G5_PLUGIN_PATH.'/browscap/Browscap.php');
$browscap = new phpbrowscap\Browscap(G5_DATA_PATH.'/cache');
require_once G5_PLUGIN_PATH . '/browscap/Browscap.php';
$browscap = new Browscap(G5_DATA_PATH . '/cache');
$browscap->doAutoUpdate = false;
$browscap->cacheFilename = 'browscap_cache.php';
// 데이터 변환
$rows = preg_replace('#[^0-9]#', '', $_GET['rows']);
if(!$rows)
$rows = isset($_GET['rows']) ? preg_replace('#[^0-9]#', '', $_GET['rows']) : 0;
if (!$rows) {
$rows = 100;
}
$sql_common = " from {$g5['visit_table']} where vi_agent <> '' and ( vi_browser = '' or vi_os = '' or vi_device = '' ) ";
$sql_order = " order by vi_id desc ";
$sql_limit = " limit 0, $rows ";
$sql_limit = " limit 0, " . strval($rows) . " ";
$sql = " select count(vi_id) as cnt $sql_common ";
$row = sql_fetch($sql);
@@ -43,20 +46,23 @@ $sql = " select vi_id, vi_agent, vi_browser, vi_os, vi_device
$result = sql_query($sql);
$cnt = 0;
for($i=0; $row=sql_fetch_array($result); $i++) {
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$info = $browscap->getBrowser($row['vi_agent']);
$brow = $row['vi_browser'];
if(!$brow)
if (!$brow) {
$brow = $info->Comment;
}
$os = $row['vi_os'];
if(!$os)
if (!$os) {
$os = $info->Platform;
}
$device = $row['vi_device'];
if(!$device)
if (!$device) {
$device = $info->Device_Type;
}
$sql2 = " update {$g5['visit_table']}
set vi_browser = '$brow',
@@ -68,7 +74,8 @@ for($i=0; $row=sql_fetch_array($result); $i++) {
$cnt++;
}
if(($total_count - $cnt) == 0 || $total_count == 0)
if (($total_count - $cnt) == 0 || $total_count == 0) {
echo '<div class="check_processing"></div><p>변환완료</p>';
else
echo '<p>총 '.number_format($total_count).'건 중 '.number_format($cnt).'건 변환완료<br><br>접속로그를 추가로 변환하시려면 아래 업데이트 버튼을 클릭해 주세요.</p><button type="button" id="run_update">업데이트</button>';
} else {
echo '<p>총 ' . number_format($total_count) . '건 중 ' . number_format($cnt) . '건 변환완료<br><br>접속로그를 추가로 변환하시려면 아래 업데이트 버튼을 클릭해 주세요.</p><button type="button" id="run_update">업데이트</button>';
}
+8 -6
View File
@@ -2,22 +2,24 @@
ini_set('memory_limit', '-1');
$sub_menu = "100510";
include_once('./_common.php');
require_once './_common.php';
// clean the output buffer
ob_end_clean();
if(!(version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE))
if (!(version_compare(phpversion(), '5.3.0', '>=') && defined('G5_BROWSCAP_USE') && G5_BROWSCAP_USE)) {
die('사용할 수 없는 기능입니다.');
}
if ($is_admin != 'super')
if ($is_admin != 'super') {
die('최고관리자만 접근 가능합니다.');
}
include_once(G5_PLUGIN_PATH.'/browscap/Browscap.php');
require_once G5_PLUGIN_PATH . '/browscap/Browscap.php';
$browscap = new phpbrowscap\Browscap(G5_DATA_PATH.'/cache');
$browscap = new Browscap(G5_DATA_PATH . '/cache');
$browscap->updateMethod = 'cURL';
$browscap->cacheFilename = 'browscap_cache.php';
$browscap->updateCache();
die('');
die('');
+61 -59
View File
@@ -1,59 +1,61 @@
<?php
$sub_menu = '100900';
include_once('./_common.php');
if ($is_admin != 'super')
alert('최고관리자만 접근 가능합니다.', G5_URL);
@include_once('./safe_check.php');
if(function_exists('social_log_file_delete')){
social_log_file_delete();
}
run_event('adm_cache_file_delete_before');
$g5['title'] = '캐시파일 일괄삭제';
include_once('./admin.head.php');
?>
<div class="local_desc02 local_desc">
<p>
완료 메세지가 나오기 전에 프로그램의 실행을 중지하지 마십시오.
</p>
</div>
<?php
flush();
if (!$dir=@opendir(G5_DATA_PATH.'/cache')) {
echo '<p>캐시디렉토리를 열지못했습니다.</p>';
}
$cnt=0;
echo '<ul class="session_del">'.PHP_EOL;
$files = glob(G5_DATA_PATH.'/cache/latest-*');
$content_files = glob(G5_DATA_PATH.'/cache/content-*');
$files = array_merge($files, $content_files);
if (is_array($files)) {
foreach ($files as $cache_file) {
$cnt++;
unlink($cache_file);
echo '<li>'.$cache_file.'</li>'.PHP_EOL;
flush();
if ($cnt%10==0)
echo PHP_EOL;
}
}
run_event('adm_cache_file_delete');
echo '<li>완료됨</li></ul>'.PHP_EOL;
echo '<div class="local_desc01 local_desc"><p><strong>최신글 캐시파일 '.$cnt.'건 삭제 완료됐습니다.</strong><br>프로그램의 실행을 끝마치셔도 좋습니다.</p></div>'.PHP_EOL;
?>
<?php
include_once('./admin.tail.php');
<?php
$sub_menu = '100900';
require_once './_common.php';
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.', G5_URL);
}
@require_once './safe_check.php';
if (function_exists('social_log_file_delete')) {
social_log_file_delete();
}
run_event('adm_cache_file_delete_before');
$g5['title'] = '캐시파일 일괄삭제';
require_once './admin.head.php';
?>
<div class="local_desc02 local_desc">
<p>
완료 메세지가 나오기 전에 프로그램의 실행을 중지하지 마십시오.
</p>
</div>
<?php
flush();
if (!$dir = @opendir(G5_DATA_PATH . '/cache')) {
echo '<p>캐시디렉토리를 열지못했습니다.</p>';
}
$cnt = 0;
echo '<ul class="session_del">' . PHP_EOL;
$files = glob(G5_DATA_PATH . '/cache/latest-*');
$content_files = glob(G5_DATA_PATH . '/cache/content-*');
$files = array_merge($files, $content_files);
if (is_array($files)) {
foreach ($files as $cache_file) {
$cnt++;
unlink($cache_file);
echo '<li>' . $cache_file . '</li>' . PHP_EOL;
flush();
if ($cnt % 10 == 0) {
echo PHP_EOL;
}
}
}
run_event('adm_cache_file_delete');
echo '<li>완료됨</li></ul>' . PHP_EOL;
echo '<div class="local_desc01 local_desc"><p><strong>최신글 캐시파일 ' . $cnt . '건 삭제 완료됐습니다.</strong><br>프로그램의 실행을 끝마치셔도 좋습니다.</p></div>' . PHP_EOL;
?>
<?php
require_once './admin.tail.php';
+56 -52
View File
@@ -1,52 +1,56 @@
<?php
$sub_menu = '100910';
include_once('./_common.php');
if ($is_admin != 'super')
alert('최고관리자만 접근 가능합니다.', G5_URL);
$g5['title'] = '캡챠파일 일괄삭제';
include_once('./admin.head.php');
?>
<div class="local_desc02 local_desc">
<p>
완료 메세지가 나오기 전에 프로그램의 실행을 중지하지 마십시오.
</p>
</div>
<?php
flush();
if (!$dir=@opendir(G5_DATA_PATH.'/cache')) {
echo '<p>캐시디렉토리를 열지못했습니다.</p>';
}
$cnt=0;
echo '<ul class="session_del">'.PHP_EOL;
$files = glob(G5_DATA_PATH.'/cache/?captcha-*');
if (is_array($files)) {
$before_time = G5_SERVER_TIME - 3600; // 한시간전
foreach ($files as $gcaptcha_file) {
$modification_time = filemtime($gcaptcha_file); // 파일접근시간
if ($modification_time > $before_time) continue;
$cnt++;
unlink($gcaptcha_file);
echo '<li>'.$gcaptcha_file.'</li>'.PHP_EOL;
flush();
if ($cnt%10==0)
echo PHP_EOL;
}
}
echo '<li>완료됨</li></ul>'.PHP_EOL;
echo '<div class="local_desc01 local_desc"><p><strong>캡챠파일 '.$cnt.'건의 삭제 완료됐습니다.</strong><br>프로그램의 실행을 끝마치셔도 좋습니다.</p></div>'.PHP_EOL;
?>
<?php
include_once('./admin.tail.php');
<?php
$sub_menu = '100910';
require_once './_common.php';
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.', G5_URL);
}
$g5['title'] = '캡챠파일 일괄삭제';
require_once './admin.head.php';
?>
<div class="local_desc02 local_desc">
<p>
완료 메세지가 나오기 전에 프로그램의 실행을 중지하지 마십시오.
</p>
</div>
<?php
flush();
if (!$dir = @opendir(G5_DATA_PATH . '/cache')) {
echo '<p>캐시디렉토리를 열지못했습니다.</p>';
}
$cnt = 0;
echo '<ul class="session_del">' . PHP_EOL;
$files = glob(G5_DATA_PATH . '/cache/?captcha-*');
if (is_array($files)) {
$before_time = G5_SERVER_TIME - 3600; // 한시간전
foreach ($files as $gcaptcha_file) {
$modification_time = filemtime($gcaptcha_file); // 파일접근시간
if ($modification_time > $before_time) {
continue;
}
$cnt++;
unlink($gcaptcha_file);
echo '<li>' . $gcaptcha_file . '</li>' . PHP_EOL;
flush();
if ($cnt % 10 == 0) {
echo PHP_EOL;
}
}
}
echo '<li>완료됨</li></ul>' . PHP_EOL;
echo '<div class="local_desc01 local_desc"><p><strong>캡챠파일 ' . $cnt . '건의 삭제 완료됐습니다.</strong><br>프로그램의 실행을 끝마치셔도 좋습니다.</p></div>' . PHP_EOL;
?>
<?php
require_once './admin.tail.php';
+1370 -1441
View File
File diff suppressed because it is too large Load Diff
+188 -138
View File
@@ -1,182 +1,222 @@
<?php
$sub_menu = "100100";
include_once('./_common.php');
require_once './_common.php';
check_demo();
auth_check_menu($auth, $sub_menu, 'w');
if ($is_admin != 'super')
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
$cf_title = isset($_POST['cf_title']) ? strip_tags(clean_xss_attributes($_POST['cf_title'])) : '';
$cf_admin = isset($_POST['cf_admin']) ? clean_xss_tags($_POST['cf_admin'], 1, 1) : '';
$posts = array();
$sql = " select * from {$g5['config_table']} limit 1";
$ori_config = sql_fetch($sql);
$cf_title = isset($_POST['cf_title']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['cf_title'])))) : '';
$cf_admin = isset($_POST['cf_admin']) ? safe_replace_regex($_POST['cf_admin']) : '';
$mb = get_member($cf_admin);
if (! (isset($mb['mb_id']) && $mb['mb_id']))
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
alert('최고관리자 회원아이디가 존재하지 않습니다.');
}
check_admin_token();
$cf_social_servicelist = !empty($_POST['cf_social_servicelist']) ? implode(',', $_POST['cf_social_servicelist']) : '';
$check_keys = array('cf_lg_mid', 'cf_lg_mert_key', 'cf_cert_kcb_cd', 'cf_cert_kcp_cd', 'cf_editor', 'cf_recaptcha_site_key', 'cf_recaptcha_secret_key', 'cf_naver_clientid', 'cf_naver_secret', 'cf_facebook_appid', 'cf_facebook_secret', 'cf_twitter_key', 'cf_twitter_secret', 'cf_google_clientid', 'cf_google_secret', 'cf_googl_shorturl_apikey', 'cf_kakao_rest_key', 'cf_kakao_client_secret', 'cf_kakao_js_apikey', 'cf_payco_clientid', 'cf_payco_secret');
$check_keys = array('cf_cert_kcb_cd', 'cf_cert_kcp_cd', 'cf_cert_kcp_enckey', 'cf_editor', 'cf_recaptcha_site_key', 'cf_recaptcha_secret_key', 'cf_naver_clientid', 'cf_naver_secret', 'cf_facebook_appid', 'cf_facebook_secret', 'cf_twitter_key', 'cf_twitter_secret', 'cf_google_clientid', 'cf_google_secret', 'cf_googl_shorturl_apikey', 'cf_kakao_rest_key', 'cf_kakao_client_secret', 'cf_kakao_js_apikey', 'cf_payco_clientid', 'cf_payco_secret', 'cf_cert_kg_cd', 'cf_cert_kg_mid');
foreach( $check_keys as $key ){
if ( isset($_POST[$key]) && $_POST[$key] ){
$posts[$key] = $_POST[$key] = preg_replace('/[^a-z0-9_\-\.]/i', '', $_POST[$key]);
foreach ($check_keys as $key) {
if (isset($_POST[$key]) && $_POST[$key]) {
$_POST[$key] = preg_replace('/[^a-z0-9_\-\.]/i', '', $_POST[$key]);
}
}
$posts['cf_icode_server_port'] = $_POST['cf_icode_server_port'] = isset($_POST['cf_icode_server_port']) ? preg_replace('/[^0-9]/', '', $_POST['cf_icode_server_port']) : '7295';
if(isset($_POST['cf_intercept_ip']) && $_POST['cf_intercept_ip']){
$_POST['cf_icode_server_port'] = isset($_POST['cf_icode_server_port']) ? preg_replace('/[^0-9]/', '', $_POST['cf_icode_server_port']) : '7295';
if (isset($_POST['cf_intercept_ip']) && $_POST['cf_intercept_ip']) {
$pattern = explode("\n", trim($_POST['cf_intercept_ip']));
for ($i=0; $i<count($pattern); $i++) {
for ($i = 0; $i < count($pattern); $i++) {
$pattern[$i] = trim($pattern[$i]);
if (empty($pattern[$i]))
if (empty($pattern[$i])) {
continue;
}
$pattern[$i] = str_replace(".", "\.", $pattern[$i]);
$pattern[$i] = str_replace("+", "[0-9\.]+", $pattern[$i]);
$pat = "/^{$pattern[$i]}$/";
if( preg_match($pat, $_SERVER['REMOTE_ADDR']) ){
alert("현재 접속 IP : ".$_SERVER['REMOTE_ADDR']." 가 차단될수 있기 때문에, 다른 IP를 입력해 주세요.");
if (preg_match($pat, $_SERVER['REMOTE_ADDR'])) {
alert("현재 접속 IP : " . $_SERVER['REMOTE_ADDR'] . " 가 차단될수 있기 때문에, 다른 IP를 입력해 주세요.");
}
}
}
$check_keys = array(
'cf_use_email_certify' => 'int',
'cf_use_homepage' => 'int',
'cf_req_homepage' => 'int',
'cf_use_tel' => 'int',
'cf_req_tel' => 'int',
'cf_use_hp' => 'int',
'cf_req_hp' => 'int',
'cf_use_addr' => 'int',
'cf_req_addr' => 'int',
'cf_use_signature' => 'int',
'cf_req_signature' => 'int',
'cf_use_profile' => 'int',
'cf_req_profile' => 'int',
'cf_register_level' => 'int',
'cf_register_point' => 'int',
'cf_icon_level' => 'int',
'cf_use_recommend' => 'int',
'cf_leave_day' => 'int',
'cf_search_part' => 'int',
'cf_email_use' => 'int',
'cf_email_wr_super_admin' => 'int',
'cf_email_wr_group_admin' => 'int',
'cf_email_wr_board_admin' => 'int',
'cf_email_wr_write' => 'int',
'cf_email_wr_comment_all' => 'int',
'cf_email_mb_super_admin' => 'int',
'cf_email_mb_member' => 'int',
'cf_email_po_super_admin' => 'int',
'cf_prohibit_id' => 'text',
'cf_prohibit_email' => 'text',
'cf_new_del' => 'int',
'cf_memo_del' => 'int',
'cf_visit_del' => 'int',
'cf_popular_del' => 'int',
'cf_use_member_icon' => 'int',
'cf_member_icon_size' => 'int',
'cf_member_icon_width' => 'int',
'cf_member_icon_height' => 'int',
'cf_member_img_size' => 'int',
'cf_member_img_width' => 'int',
'cf_member_img_height' => 'int',
'cf_login_minutes' => 'int',
'cf_formmail_is_member' => 'int',
'cf_page_rows' => 'int',
'cf_mobile_page_rows' => 'int',
'cf_social_login_use' => 'int',
'cf_cert_req' => 'int',
'cf_cert_use' => 'int',
'cf_cert_ipin' => 'char',
'cf_cert_hp' => 'char',
'cf_admin_email' => 'char',
'cf_admin_email_name' => 'char',
'cf_add_script' => 'text',
'cf_use_point' => 'int',
'cf_point_term' => 'int',
'cf_use_copy_log' => 'int',
'cf_login_point' => 'int',
'cf_cut_name' => 'int',
'cf_nick_modify' => 'int',
'cf_new_skin' => 'char',
'cf_new_rows' => 'int',
'cf_search_skin' => 'char',
'cf_connect_skin' => 'char',
'cf_faq_skin' => 'char',
'cf_read_point' => 'int',
'cf_write_point' => 'int',
'cf_comment_point' => 'int',
'cf_download_point' => 'int',
'cf_write_pages' => 'int',
'cf_mobile_pages' => 'int',
'cf_link_target' => 'char',
'cf_delay_sec' => 'int',
'cf_filter' => 'text',
'cf_possible_ip' => 'text',
'cf_analytics' => 'text',
'cf_add_meta' => 'text',
'cf_member_skin' => 'char',
'cf_image_extension' => 'char',
'cf_flash_extension' => 'char',
'cf_movie_extension' => 'char',
'cf_visit' => 'char',
'cf_stipulation' => 'text',
'cf_privacy' => 'text',
'cf_open_modify' => 'int',
'cf_memo_send_point' => 'int',
'cf_mobile_new_skin' => 'char',
'cf_mobile_search_skin' => 'char',
'cf_mobile_connect_skin' => 'char',
'cf_mobile_faq_skin' => 'char',
'cf_mobile_member_skin' => 'char',
'cf_captcha_mp3' => 'char',
'cf_cert_limit' => 'int',
'cf_sms_use' => 'char',
'cf_sms_type' => 'char',
'cf_icode_id' => 'char',
'cf_icode_pw' => 'char',
'cf_icode_server_ip' => 'char',
'cf_captcha' => 'char',
'cf_syndi_token' => '',
'cf_syndi_except' => ''
'cf_use_email_certify' => 'int',
'cf_email_certify_minutes' => 'int',
'cf_use_homepage' => 'int',
'cf_req_homepage' => 'int',
'cf_use_tel' => 'int',
'cf_req_tel' => 'int',
'cf_use_hp' => 'int',
'cf_req_hp' => 'int',
'cf_use_addr' => 'int',
'cf_req_addr' => 'int',
'cf_use_signature' => 'int',
'cf_req_signature' => 'int',
'cf_use_profile' => 'int',
'cf_req_profile' => 'int',
'cf_register_level' => 'int',
'cf_register_point' => 'int',
'cf_icon_level' => 'int',
'cf_use_recommend' => 'int',
'cf_leave_day' => 'int',
'cf_search_part' => 'int',
'cf_email_use' => 'int',
'cf_email_wr_super_admin' => 'int',
'cf_email_wr_group_admin' => 'int',
'cf_email_wr_board_admin' => 'int',
'cf_email_wr_write' => 'int',
'cf_email_wr_comment_all' => 'int',
'cf_email_mb_super_admin' => 'int',
'cf_email_mb_member' => 'int',
'cf_email_po_super_admin' => 'int',
'cf_prohibit_id' => 'text',
'cf_prohibit_email' => 'text',
'cf_new_del' => 'int',
'cf_memo_del' => 'int',
'cf_visit_del' => 'int',
'cf_popular_del' => 'int',
'cf_use_member_icon' => 'int',
'cf_member_icon_size' => 'int',
'cf_member_icon_width' => 'int',
'cf_member_icon_height' => 'int',
'cf_member_img_size' => 'int',
'cf_member_img_width' => 'int',
'cf_member_img_height' => 'int',
'cf_login_minutes' => 'int',
'cf_formmail_is_member' => 'int',
'cf_page_rows' => 'int',
'cf_mobile_page_rows' => 'int',
'cf_social_login_use' => 'int',
'cf_cert_req' => 'int',
'cf_cert_use' => 'int',
'cf_cert_find' => 'int',
'cf_cert_ipin' => 'char',
'cf_cert_hp' => 'char',
'cf_cert_simple' => 'char',
'cf_cert_use_seed' => 'int',
'cf_admin_email' => 'char',
'cf_admin_email_name' => 'char',
'cf_add_script' => 'text',
'cf_use_point' => 'int',
'cf_point_term' => 'int',
'cf_use_copy_log' => 'int',
'cf_login_point' => 'int',
'cf_cut_name' => 'int',
'cf_nick_modify' => 'int',
'cf_new_skin' => 'char',
'cf_new_rows' => 'int',
'cf_search_skin' => 'char',
'cf_connect_skin' => 'char',
'cf_faq_skin' => 'char',
'cf_read_point' => 'int',
'cf_write_point' => 'int',
'cf_comment_point' => 'int',
'cf_download_point' => 'int',
'cf_write_pages' => 'int',
'cf_mobile_pages' => 'int',
'cf_link_target' => 'char',
'cf_delay_sec' => 'int',
'cf_filter' => 'text',
'cf_possible_ip' => 'text',
'cf_analytics' => 'text',
'cf_add_meta' => 'text',
'cf_member_skin' => 'char',
'cf_image_extension' => 'char',
'cf_flash_extension' => 'char',
'cf_movie_extension' => 'char',
'cf_visit' => 'char',
'cf_stipulation' => 'text',
'cf_privacy' => 'text',
'cf_use_promotion' => 'int',
'cf_open_modify' => 'int',
'cf_memo_send_point' => 'int',
'cf_mobile_new_skin' => 'char',
'cf_mobile_search_skin' => 'char',
'cf_mobile_connect_skin' => 'char',
'cf_mobile_faq_skin' => 'char',
'cf_mobile_member_skin' => 'char',
'cf_captcha_mp3' => 'char',
'cf_cert_limit' => 'int',
'cf_sms_use' => 'char',
'cf_sms_type' => 'char',
'cf_icode_id' => 'char',
'cf_icode_pw' => 'char',
'cf_icode_server_ip' => 'char',
'cf_captcha' => 'char',
'cf_syndi_token' => '',
'cf_syndi_except' => ''
);
for($i=1;$i<=10;$i++){
$check_keys['cf_'.$i.'_subj'] = isset($_POST['cf_'.$i.'_subj']) ? $_POST['cf_'.$i.'_subj'] : '';
$check_keys['cf_'.$i] = isset($_POST['cf_'.$i]) ? $_POST['cf_'.$i] : '';
for ($i = 1; $i <= 10; $i++) {
$check_keys['cf_' . $i . '_subj'] = isset($_POST['cf_' . $i . '_subj']) ? $_POST['cf_' . $i . '_subj'] : '';
$check_keys['cf_' . $i] = isset($_POST['cf_' . $i]) ? $_POST['cf_' . $i] : '';
}
foreach( $check_keys as $k => $v ){
if( $v === 'int' ){
$posts[$key] = $_POST[$k] = isset($_POST[$k]) ? (int) $_POST[$k] : 0;
foreach ($check_keys as $k => $v) {
if ($v === 'int') {
$_POST[$k] = isset($_POST[$k]) ? (int) $_POST[$k] : 0;
} else {
if(in_array($k, array('cf_analytics', 'cf_add_meta', 'cf_add_script', 'cf_stipulation', 'cf_privacy'))){
$posts[$key] = $_POST[$k] = isset($_POST[$k]) ? $_POST[$k] : '';
if (in_array($k, array('cf_analytics', 'cf_add_meta', 'cf_add_script', 'cf_stipulation', 'cf_privacy'))) {
$_POST[$k] = isset($_POST[$k]) ? $_POST[$k] : '';
} else {
$posts[$key] = $_POST[$k] = isset($_POST[$k]) ? strip_tags(clean_xss_attributes($_POST[$k])) : '';
$_POST[$k] = isset($_POST[$k]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$k])))) : '';
}
}
}
// 본인확인을 사용할 경우 아이핀, 휴대폰인증 중 하나는 선택되어야 함
if($_POST['cf_cert_use'] && !$_POST['cf_cert_ipin'] && !$_POST['cf_cert_hp'])
alert('본인확인을 위해 아이핀 또는 휴대폰 본인학인 서비스를 하나이상 선택해 주십시오');
$_POST['cf_email_certify_minutes'] = max(0, $_POST['cf_email_certify_minutes']);
if(!$_POST['cf_cert_use']) {
$posts[$key] = $_POST['cf_cert_ipin'] = '';
$posts[$key] = $_POST['cf_cert_hp'] = '';
// 본인확인을 사용할 경우 아이핀, 휴대폰인증 중 하나는 선택되어야 함
if ($_POST['cf_cert_use'] && !$_POST['cf_cert_ipin'] && !$_POST['cf_cert_hp'] && !$_POST['cf_cert_simple']) {
alert('본인확인을 위해 아이핀, 휴대폰 본인확인, KG이니시스 간편인증 서비스 중 하나 이상 선택해 주십시오.');
}
if (!$_POST['cf_cert_use']) {
$_POST['cf_cert_ipin'] = '';
$_POST['cf_cert_hp'] = '';
$_POST['cf_cert_simple'] = '';
}
// 관리자가 자동등록방지를 사용해야 할 경우 ( 기본환경설정에서 최고관리자, 방문자분석 스크립트, 추가 메타태그, 추가 script, css 변경시 )
$check_captcha = 0;
if ($cf_admin && $ori_config['cf_admin'] !== $cf_admin) {
$check_captcha = 1;
}
if ($_POST['cf_analytics'] && $ori_config['cf_analytics'] !== stripslashes($_POST['cf_analytics'])) {
$check_captcha = 1;
}
if ($_POST['cf_add_meta'] && $ori_config['cf_add_meta'] !== stripslashes($_POST['cf_add_meta'])) {
$check_captcha = 1;
}
if ($_POST['cf_add_script'] && $ori_config['cf_add_script'] !== stripslashes($_POST['cf_add_script'])) {
$check_captcha = 1;
}
if ($check_captcha) {
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
}
$sql = " update {$g5['config_table']}
@@ -189,6 +229,7 @@ $sql = " update {$g5['config_table']}
cf_point_term = '{$_POST['cf_point_term']}',
cf_use_copy_log = '{$_POST['cf_use_copy_log']}',
cf_use_email_certify = '{$_POST['cf_use_email_certify']}',
cf_email_certify_minutes = '{$_POST['cf_email_certify_minutes']}',
cf_login_point = '{$_POST['cf_login_point']}',
cf_cut_name = '{$_POST['cf_cut_name']}',
cf_nick_modify = '{$_POST['cf_nick_modify']}',
@@ -206,8 +247,8 @@ $sql = " update {$g5['config_table']}
cf_link_target = '{$_POST['cf_link_target']}',
cf_delay_sec = '{$_POST['cf_delay_sec']}',
cf_filter = '{$_POST['cf_filter']}',
cf_possible_ip = '".trim($_POST['cf_possible_ip'])."',
cf_intercept_ip = '".trim($_POST['cf_intercept_ip'])."',
cf_possible_ip = '" . trim($_POST['cf_possible_ip']) . "',
cf_intercept_ip = '" . trim($_POST['cf_intercept_ip']) . "',
cf_analytics = '{$_POST['cf_analytics']}',
cf_add_meta = '{$_POST['cf_add_meta']}',
cf_syndi_token = '{$_POST['cf_syndi_token']}',
@@ -264,6 +305,7 @@ $sql = " update {$g5['config_table']}
cf_mobile_page_rows = '{$_POST['cf_mobile_page_rows']}',
cf_stipulation = '{$_POST['cf_stipulation']}',
cf_privacy = '{$_POST['cf_privacy']}',
cf_use_promotion = '{$_POST['cf_use_promotion']}',
cf_open_modify = '{$_POST['cf_open_modify']}',
cf_memo_send_point = '{$_POST['cf_memo_send_point']}',
cf_mobile_new_skin = '{$_POST['cf_mobile_new_skin']}',
@@ -274,12 +316,16 @@ $sql = " update {$g5['config_table']}
cf_captcha_mp3 = '{$_POST['cf_captcha_mp3']}',
cf_editor = '{$_POST['cf_editor']}',
cf_cert_use = '{$_POST['cf_cert_use']}',
cf_cert_find = '{$_POST['cf_cert_find']}',
cf_cert_ipin = '{$_POST['cf_cert_ipin']}',
cf_cert_hp = '{$_POST['cf_cert_hp']}',
cf_cert_simple = '{$_POST['cf_cert_simple']}',
cf_cert_use_seed = '".(int)$_POST['cf_cert_use_seed']."',
cf_cert_kg_cd = '{$_POST['cf_cert_kg_cd']}',
cf_cert_kg_mid = '" . trim($_POST['cf_cert_kg_mid']) . "',
cf_cert_kcb_cd = '{$_POST['cf_cert_kcb_cd']}',
cf_cert_kcp_cd = '{$_POST['cf_cert_kcp_cd']}',
cf_lg_mid = '{$_POST['cf_lg_mid']}',
cf_lg_mert_key = '{$_POST['cf_lg_mert_key']}',
cf_cert_kcp_enckey = '{$_POST['cf_cert_kcp_enckey']}',
cf_cert_limit = '{$_POST['cf_cert_limit']}',
cf_cert_req = '{$_POST['cf_cert_req']}',
cf_sms_use = '{$_POST['cf_sms_use']}',
@@ -332,12 +378,16 @@ sql_query($sql);
//sql_query(" OPTIMIZE TABLE `$g5[config_table]` ");
if( isset($_POST['cf_bbs_rewrite']) ){
if (isset($_POST['cf_bbs_rewrite'])) {
g5_delete_all_cache();
}
if (function_exists('get_admin_captcha_by')) {
get_admin_captcha_by('remove');
}
run_event('admin_config_form_update');
update_rewrite_rules();
goto_url('./config_form.php', false);
goto_url('./config_form.php', false);
+281 -298
View File
@@ -1,298 +1,281 @@
<?php
$sub_menu = '300600';
include_once('./_common.php');
include_once(G5_EDITOR_LIB);
auth_check_menu($auth, $sub_menu, "w");
$co_id = isset($_REQUEST['co_id']) ? preg_replace('/[^a-z0-9_]/i', '', $_REQUEST['co_id']) : '';
// 상단, 하단 파일경로 필드 추가
if(!sql_query(" select co_include_head from {$g5['content_table']} limit 1 ", false)) {
$sql = " ALTER TABLE `{$g5['content_table']}` ADD `co_include_head` VARCHAR( 255 ) NOT NULL ,
ADD `co_include_tail` VARCHAR( 255 ) NOT NULL ";
sql_query($sql, false);
}
// html purifier 사용여부 필드
if(!sql_query(" select co_tag_filter_use from {$g5['content_table']} limit 1 ", false)) {
sql_query(" ALTER TABLE `{$g5['content_table']}`
ADD `co_tag_filter_use` tinyint(4) NOT NULL DEFAULT '0' AFTER `co_content` ", true);
sql_query(" update {$g5['content_table']} set co_tag_filter_use = '1' ");
}
// 모바일 내용 추가
if(!sql_query(" select co_mobile_content from {$g5['content_table']} limit 1", false)) {
sql_query(" ALTER TABLE `{$g5['content_table']}`
ADD `co_mobile_content` longtext NOT NULL AFTER `co_content` ", true);
}
// 스킨 설정 추가
if(!sql_query(" select co_skin from {$g5['content_table']} limit 1 ", false)) {
sql_query(" ALTER TABLE `{$g5['content_table']}`
ADD `co_skin` varchar(255) NOT NULL DEFAULT '' AFTER `co_mobile_content`,
ADD `co_mobile_skin` varchar(255) NOT NULL DEFAULT '' AFTER `co_skin` ", true);
sql_query(" update {$g5['content_table']} set co_skin = 'basic', co_mobile_skin = 'basic' ");
}
$html_title = "내용";
$g5['title'] = $html_title.' 관리';
$readonly = '';
if ($w == "u")
{
$html_title .= " 수정";
$readonly = " readonly";
$sql = " select * from {$g5['content_table']} where co_id = '$co_id' ";
$co = sql_fetch($sql);
if (!$co['co_id'])
alert('등록된 자료가 없습니다.');
}
else
{
$html_title .= ' 입력';
$co = array(
'co_id' => '',
'co_subject' => '',
'co_content' => '',
'co_mobile_content' => '',
'co_include_head' => '',
'co_include_tail' => '',
'co_tag_filter_use' => 1,
'co_html' => 2,
'co_skin' => 'basic',
'co_mobile_skin' => 'basic'
);
}
include_once (G5_ADMIN_PATH.'/admin.head.php');
?>
<form name="frmcontentform" action="./contentformupdate.php" onsubmit="return frmcontentform_check(this);" method="post" enctype="MULTIPART/FORM-DATA" >
<input type="hidden" name="w" value="<?php echo $w; ?>">
<input type="hidden" name="co_html" value="1">
<input type="hidden" name="token" value="">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="co_id">ID</label></th>
<td>
<?php echo help('20자 이내의 영문자, 숫자, _ 만 가능합니다.'); ?>
<input type="text" value="<?php echo $co['co_id']; ?>" name="co_id" id ="co_id" required <?php echo $readonly; ?> class="required <?php echo $readonly; ?> frm_input" size="20" maxlength="20">
<?php if ($w == 'u') { ?><a href="<?php echo get_pretty_url('content', $co_id); ?>" class="btn_frmline">내용확인</a><?php } ?>
</td>
</tr>
<tr>
<th scope="row"><label for="co_subject">제목</label></th>
<td><input type="text" name="co_subject" value="<?php echo htmlspecialchars2($co['co_subject']); ?>" id="co_subject" required class="frm_input required" size="90"></td>
</tr>
<tr>
<th scope="row">내용</th>
<td><?php echo editor_html('co_content', get_text(html_purifier($co['co_content']), 0)); ?></td>
</tr>
<tr>
<th scope="row">모바일 내용</th>
<td><?php echo editor_html('co_mobile_content', get_text(html_purifier($co['co_mobile_content']), 0)); ?></td>
</tr>
<tr>
<th scope="row"><label for="co_skin">스킨 디렉토리<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo get_skin_select('content', 'co_skin', 'co_skin', $co['co_skin'], 'required'); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="co_mobile_skin">모바일스킨 디렉토리<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo get_mobile_skin_select('content', 'co_mobile_skin', 'co_mobile_skin', $co['co_mobile_skin'], 'required'); ?>
</td>
</tr>
<!--
<tr>
<th scope="row"><label for="co_tag_filter_use">태그 필터링 사용</label></th>
<td>
<?php echo help("내용에서 iframe 등의 태그를 사용하려면 사용안함으로 선택해 주십시오."); ?>
<select name="co_tag_filter_use" id="co_tag_filter_use">
<option value="1"<?php echo get_selected($co['co_tag_filter_use'], 1); ?>>사용함</option>
<option value="0"<?php echo get_selected($co['co_tag_filter_use'], 0); ?>>사용안함</option>
</select>
</td>
</tr>
-->
<tr>
<th scope="row"><label for="co_include_head">상단 파일 경로</label></th>
<td>
<?php echo help("설정값이 없으면 기본 상단 파일을 사용합니다."); ?>
<input type="text" name="co_include_head" value="<?php echo $co['co_include_head']; ?>" id="co_include_head" class="frm_input" size="60">
</td>
</tr>
<tr>
<th scope="row"><label for="co_include_tail">하단 파일 경로</label></th>
<td>
<?php echo help("설정값이 없으면 기본 하단 파일을 사용합니다."); ?>
<input type="text" name="co_include_tail" value="<?php echo $co['co_include_tail']; ?>" id="co_include_tail" class="frm_input" size="60">
</td>
</tr>
<tr id="admin_captcha_box" style="display:none;">
<th scope="row">자동등록방지</th>
<td>
<?php
echo help("파일 경로를 입력 또는 수정시 캡챠를 반드시 입력해야 합니다.");
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
$captcha_html = captcha_html();
$captcha_js = chk_captcha_js();
echo $captcha_html;
?>
<script>
jQuery("#captcha_key").removeAttr("required").removeClass("required");
</script>
</td>
</tr>
<tr>
<th scope="row"><label for="co_himg">상단이미지</label></th>
<td>
<input type="file" name="co_himg" id="co_himg">
<?php
$himg = G5_DATA_PATH.'/content/'.$co['co_id'].'_h';
$himg_str = '';
if (file_exists($himg)) {
$size = @getimagesize($himg);
if($size[0] && $size[0] > 750)
$width = 750;
else
$width = $size[0];
echo '<input type="checkbox" name="co_himg_del" value="1" id="co_himg_del"> <label for="co_himg_del">삭제</label>';
$himg_str = '<img src="'.G5_DATA_URL.'/content/'.$co['co_id'].'_h" width="'.$width.'" alt="">';
}
if ($himg_str) {
echo '<div class="banner_or_img">';
echo $himg_str;
echo '</div>';
}
?>
</td>
</tr>
<tr>
<th scope="row"><label for="co_timg">하단이미지</label></th>
<td>
<input type="file" name="co_timg" id="co_timg">
<?php
$timg = G5_DATA_PATH.'/content/'.$co['co_id'].'_t';
$timg_str = '';
if (file_exists($timg)) {
$size = @getimagesize($timg);
if($size[0] && $size[0] > 750)
$width = 750;
else
$width = $size[0];
echo '<input type="checkbox" name="co_timg_del" value="1" id="co_timg_del"> <label for="co_timg_del">삭제</label>';
$timg_str = '<img src="'.G5_DATA_URL.'/content/'.$co['co_id'].'_t" width="'.$width.'" alt="">';
}
if ($timg_str) {
echo '<div class="banner_or_img">';
echo $timg_str;
echo '</div>';
}
?>
</td>
</tr>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<a href="./contentlist.php" class="btn btn_02">목록</a>
<input type="submit" value="확인" class="btn btn_submit" accesskey="s">
</div>
</form>
<?php
// [KVE-2018-2089] 취약점 으로 인해 파일 경로 수정시에만 자동등록방지 코드 사용
?>
<script>
var captcha_chk = false;
function use_captcha_check(){
$.ajax({
type: "POST",
url: g5_admin_url+"/ajax.use_captcha.php",
data: { admin_use_captcha: "1" },
cache: false,
async: false,
dataType: "json",
success: function(data) {
}
});
}
function frm_check_file(){
var co_include_head = "<?php echo $co['co_include_head']; ?>";
var co_include_tail = "<?php echo $co['co_include_tail']; ?>";
var head = jQuery.trim(jQuery("#co_include_head").val());
var tail = jQuery.trim(jQuery("#co_include_tail").val());
if(co_include_head !== head || co_include_tail !== tail){
// 캡챠를 사용합니다.
jQuery("#admin_captcha_box").show();
captcha_chk = true;
use_captcha_check();
return false;
} else {
jQuery("#admin_captcha_box").hide();
}
return true;
}
jQuery(function($){
if( window.self !== window.top ){ // frame 또는 iframe을 사용할 경우 체크
$("#co_include_head, #co_include_tail").on("change paste keyup", function(e) {
frm_check_file();
});
use_captcha_check();
}
});
function frmcontentform_check(f)
{
errmsg = "";
errfld = "";
<?php echo get_editor_js('co_content'); ?>
<?php echo chk_editor_js('co_content'); ?>
<?php echo get_editor_js('co_mobile_content'); ?>
check_field(f.co_id, "ID를 입력하세요.");
check_field(f.co_subject, "제목을 입력하세요.");
check_field(f.co_content, "내용을 입력하세요.");
if (errmsg != "") {
alert(errmsg);
errfld.focus();
return false;
}
if( captcha_chk ) {
<?php echo $captcha_js; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
}
return true;
}
</script>
<?php
include_once (G5_ADMIN_PATH.'/admin.tail.php');
<?php
$sub_menu = '300600';
require_once './_common.php';
require_once G5_EDITOR_LIB;
auth_check_menu($auth, $sub_menu, "w");
$co_id = isset($_REQUEST['co_id']) ? preg_replace('/[^a-z0-9_]/i', '', $_REQUEST['co_id']) : '';
// 상단, 하단 파일경로 필드 추가
// html purifier 사용여부 필드
// 모바일 내용 추가
// 스킨 설정 추가
$html_title = "내용";
$g5['title'] = $html_title . ' 관리';
$readonly = '';
if ($w == "u") {
$html_title .= " 수정";
$readonly = " readonly";
$sql = " select * from {$g5['content_table']} where co_id = '$co_id' ";
$co = sql_fetch($sql);
if (!$co['co_id']) {
alert('등록된 자료가 없습니다.');
}
if (function_exists('check_case_exist_title')) check_case_exist_title($co, G5_CONTENT_DIR, false);
} else {
$html_title .= ' 입력';
$co = array(
'co_id' => '',
'co_subject' => '',
'co_content' => '',
'co_mobile_content' => '',
'co_include_head' => '',
'co_include_tail' => '',
'co_tag_filter_use' => 1,
'co_html' => 2,
'co_skin' => 'basic',
'co_mobile_skin' => 'basic'
);
}
require_once G5_ADMIN_PATH . '/admin.head.php';
?>
<form name="frmcontentform" action="./contentformupdate.php" onsubmit="return frmcontentform_check(this);" method="post" enctype="MULTIPART/FORM-DATA">
<input type="hidden" name="w" value="<?php echo $w; ?>">
<input type="hidden" name="co_html" value="1">
<input type="hidden" name="token" value="">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="co_id">ID</label></th>
<td>
<?php echo help('20자 이내의 영문자, 숫자, _ 만 가능합니다.'); ?>
<input type="text" value="<?php echo $co['co_id']; ?>" name="co_id" id="co_id" required <?php echo $readonly; ?> class="required <?php echo $readonly; ?> frm_input" size="20" maxlength="20">
<?php if ($w == 'u') { ?><a href="<?php echo get_pretty_url('content', $co_id); ?>" class="btn_frmline">내용확인</a><?php } ?>
</td>
</tr>
<tr>
<th scope="row"><label for="co_subject">제목</label></th>
<td><input type="text" name="co_subject" value="<?php echo htmlspecialchars2($co['co_subject']); ?>" id="co_subject" required class="frm_input required" size="90"></td>
</tr>
<tr>
<th scope="row">내용</th>
<td><?php echo editor_html('co_content', get_text(html_purifier($co['co_content']), 0)); ?></td>
</tr>
<tr>
<th scope="row">모바일 내용</th>
<td><?php echo editor_html('co_mobile_content', get_text(html_purifier($co['co_mobile_content']), 0)); ?></td>
</tr>
<tr>
<th scope="row"><label for="co_skin">스킨 디렉토리<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo get_skin_select('content', 'co_skin', 'co_skin', $co['co_skin'], 'required'); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="co_mobile_skin">모바일스킨 디렉토리<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo get_mobile_skin_select('content', 'co_mobile_skin', 'co_mobile_skin', $co['co_mobile_skin'], 'required'); ?>
</td>
</tr>
<!--
<tr>
<th scope="row"><label for="co_tag_filter_use">태그 필터링 사용</label></th>
<td>
<?php echo help("내용에서 iframe 등의 태그를 사용하려면 사용안함으로 선택해 주십시오."); ?>
<select name="co_tag_filter_use" id="co_tag_filter_use">
<option value="1"<?php echo get_selected($co['co_tag_filter_use'], 1); ?>>사용함</option>
<option value="0"<?php echo get_selected($co['co_tag_filter_use'], 0); ?>>사용안함</option>
</select>
</td>
</tr>
-->
<tr>
<th scope="row"><label for="co_include_head">상단 파일 경로</label></th>
<td>
<?php echo help("설정값이 없으면 기본 상단 파일을 사용합니다."); ?>
<input type="text" name="co_include_head" value="<?php echo get_sanitize_input($co['co_include_head']); ?>" id="co_include_head" class="frm_input" size="60">
</td>
</tr>
<tr>
<th scope="row"><label for="co_include_tail">하단 파일 경로</label></th>
<td>
<?php echo help("설정값이 없으면 기본 하단 파일을 사용합니다."); ?>
<input type="text" name="co_include_tail" value="<?php echo get_sanitize_input($co['co_include_tail']); ?>" id="co_include_tail" class="frm_input" size="60">
</td>
</tr>
<tr id="admin_captcha_box" style="display:none;">
<th scope="row">자동등록방지</th>
<td>
<?php
echo help("파일 경로를 입력 또는 수정시 캡챠를 반드시 입력해야 합니다.");
require_once G5_CAPTCHA_PATH . '/captcha.lib.php';
$captcha_html = captcha_html();
$captcha_js = chk_captcha_js();
echo $captcha_html;
?>
<script>
jQuery("#captcha_key").removeAttr("required").removeClass("required");
</script>
</td>
</tr>
<tr>
<th scope="row"><label for="co_himg">상단이미지</label></th>
<td>
<input type="file" name="co_himg" id="co_himg">
<?php
$himg = G5_DATA_PATH . '/content/' . $co['co_id'] . '_h';
$himg_str = '';
if (file_exists($himg)) {
$size = @getimagesize($himg);
if ($size[0] && $size[0] > 750) {
$width = 750;
} else {
$width = $size[0];
}
echo '<input type="checkbox" name="co_himg_del" value="1" id="co_himg_del"> <label for="co_himg_del">삭제</label>';
$himg_str = '<img src="' . G5_DATA_URL . '/content/' . $co['co_id'] . '_h" width="' . $width . '" alt="">';
}
if ($himg_str) {
echo '<div class="banner_or_img">';
echo $himg_str;
echo '</div>';
}
?>
</td>
</tr>
<tr>
<th scope="row"><label for="co_timg">하단이미지</label></th>
<td>
<input type="file" name="co_timg" id="co_timg">
<?php
$timg = G5_DATA_PATH . '/content/' . $co['co_id'] . '_t';
$timg_str = '';
if (file_exists($timg)) {
$size = @getimagesize($timg);
if ($size[0] && $size[0] > 750) {
$width = 750;
} else {
$width = $size[0];
}
echo '<input type="checkbox" name="co_timg_del" value="1" id="co_timg_del"> <label for="co_timg_del">삭제</label>';
$timg_str = '<img src="' . G5_DATA_URL . '/content/' . $co['co_id'] . '_t" width="' . $width . '" alt="">';
}
if ($timg_str) {
echo '<div class="banner_or_img">';
echo $timg_str;
echo '</div>';
}
?>
</td>
</tr>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<a href="./contentlist.php" class="btn btn_02">목록</a>
<input type="submit" value="확인" class="btn btn_submit" accesskey="s">
</div>
</form>
<?php
// [KVE-2018-2089] 취약점 으로 인해 파일 경로 수정시에만 자동등록방지 코드 사용
?>
<script>
var captcha_chk = false;
function use_captcha_check() {
$.ajax({
type: "POST",
url: g5_admin_url + "/ajax.use_captcha.php",
data: {
admin_use_captcha: "1"
},
cache: false,
async: false,
dataType: "json",
success: function(data) {}
});
}
function frm_check_file() {
var co_include_head = "<?php echo $co['co_include_head']; ?>";
var co_include_tail = "<?php echo $co['co_include_tail']; ?>";
var head = jQuery.trim(jQuery("#co_include_head").val());
var tail = jQuery.trim(jQuery("#co_include_tail").val());
if (co_include_head !== head || co_include_tail !== tail) {
// 캡챠를 사용합니다.
jQuery("#admin_captcha_box").show();
captcha_chk = true;
use_captcha_check();
return false;
} else {
jQuery("#admin_captcha_box").hide();
}
return true;
}
jQuery(function($) {
if (window.self !== window.top) { // frame 또는 iframe을 사용할 경우 체크
$("#co_include_head, #co_include_tail").on("change paste keyup", function(e) {
frm_check_file();
});
use_captcha_check();
}
});
function frmcontentform_check(f) {
errmsg = "";
errfld = "";
<?php echo get_editor_js('co_content'); ?>
<?php echo chk_editor_js('co_content'); ?>
<?php echo get_editor_js('co_mobile_content'); ?>
check_field(f.co_id, "ID를 입력하세요.");
check_field(f.co_subject, "제목을 입력하세요.");
check_field(f.co_content, "내용을 입력하세요.");
if (errmsg != "") {
alert(errmsg);
errfld.focus();
return false;
}
if (captcha_chk) {
<?php echo $captcha_js; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
}
return true;
}
</script>
<?php
require_once G5_ADMIN_PATH . '/admin.tail.php';
+191 -157
View File
@@ -1,157 +1,191 @@
<?php
$sub_menu = '300600';
include_once('./_common.php');
if ($w == "u" || $w == "d")
check_demo();
if ($w == 'd')
auth_check_menu($auth, $sub_menu, "d");
else
auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
$co_row = array('co_id'=>'', 'co_include_head'=>'', 'co_include_tail'=>'');
if ($w == "" || $w == "u")
{
if(isset($_REQUEST['co_id']) && preg_match("/[^a-z0-9_]/i", $_REQUEST['co_id'])) alert("ID 는 영문자, 숫자, _ 만 가능합니다.");
$sql = " select * from {$g5['content_table']} where co_id = '$co_id' ";
$co_row = sql_fetch($sql);
}
$co_id = isset($_REQUEST['co_id']) ? preg_replace('/[^a-z0-9_]/i', '', $_REQUEST['co_id']) : '';
$co_subject = isset($_POST['co_subject']) ? strip_tags(clean_xss_attributes($_POST['co_subject'])) : '';
$co_include_head = isset($_POST['co_include_head']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_head'], 0, 255)) : '';
$co_include_tail = isset($_POST['co_include_tail']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_tail'], 0, 255)) : '';
$co_tag_filter_use = isset($_POST['co_tag_filter_use']) ? (int) $_POST['co_tag_filter_use'] : 1;
$co_himg_del = (isset($_POST['co_himg_del']) && $_POST['co_himg_del']) ? 1 : 0;
$co_timg_del = (isset($_POST['co_timg_del']) && $_POST['co_timg_del']) ? 1 : 0;
$co_html = isset($_POST['co_html']) ? (int) $_POST['co_html'] : 0;
$co_content = isset($_POST['co_content']) ? $_POST['co_content'] : '';
$co_mobile_content = isset($_POST['co_mobile_content']) ? $_POST['co_mobile_content'] : '';
$co_skin = isset($_POST['co_skin']) ? clean_xss_tags($_POST['co_skin'], 1, 1) : '';
$co_mobile_skin = isset($_POST['co_mobile_skin']) ? clean_xss_tags($_POST['co_mobile_skin'], 1, 1) : '';
// 관리자가 자동등록방지를 사용해야 할 경우
if ((( isset($co_row['co_include_head']) && $co_row['co_include_head'] !== $co_include_head ) || ( isset($co_row['co_include_tail']) && $co_row['co_include_tail'] !== $co_include_tail )) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()){
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
}
@mkdir(G5_DATA_PATH."/content", G5_DIR_PERMISSION);
@chmod(G5_DATA_PATH."/content", G5_DIR_PERMISSION);
if ($co_himg_del) @unlink(G5_DATA_PATH."/content/{$co_id}_h");
if ($co_timg_del) @unlink(G5_DATA_PATH."/content/{$co_id}_t");
$error_msg = '';
if( $co_include_head ){
$file_ext = pathinfo($co_include_head, PATHINFO_EXTENSION);
if( ! $file_ext || ! in_array($file_ext, array('php', 'htm', 'html')) || ! preg_match('/^.*\.(php|htm|html)$/i', $co_include_head) ) {
alert('상단 파일 경로의 확장자는 php, htm, html 만 허용합니다.');
}
}
if( $co_include_tail ){
$file_ext = pathinfo($co_include_tail, PATHINFO_EXTENSION);
if( ! $file_ext || ! in_array($file_ext, array('php', 'htm', 'html')) || ! preg_match('/^.*\.(php|htm|html)$/i', $co_include_tail) ) {
alert('하단 파일 경로의 확장자는 php, htm, html 만 허용합니다.');
}
}
if( $co_include_head && ! is_include_path_check($co_include_head, 1) ){
$co_include_head = '';
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 상단 파일 경로에 포함시킬수 없습니다.';
}
if( $co_include_tail && ! is_include_path_check($co_include_tail, 1) ){
$co_include_tail = '';
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 하단 파일 경로에 포함시킬수 없습니다.';
}
if( function_exists('filter_input_include_path') ){
$co_include_head = filter_input_include_path($co_include_head);
$co_include_tail = filter_input_include_path($co_include_tail);
}
$co_seo_title = exist_seo_title_recursive('content', generate_seo_title($co_subject), $g5['content_table'], $co_id);
$sql_common = " co_include_head = '$co_include_head',
co_include_tail = '$co_include_tail',
co_html = '$co_html',
co_tag_filter_use = '$co_tag_filter_use',
co_subject = '$co_subject',
co_content = '$co_content',
co_mobile_content = '$co_mobile_content',
co_seo_title = '$co_seo_title',
co_skin = '$co_skin',
co_mobile_skin = '$co_mobile_skin' ";
if ($w == "")
{
$row = $co_row;
if (isset($row['co_id']) && $row['co_id'])
alert("이미 같은 ID로 등록된 내용이 있습니다.");
$sql = " insert {$g5['content_table']}
set co_id = '$co_id',
$sql_common ";
sql_query($sql);
}
else if ($w == "u")
{
$sql = " update {$g5['content_table']}
set $sql_common
where co_id = '$co_id' ";
sql_query($sql);
}
else if ($w == "d")
{
@unlink(G5_DATA_PATH."/content/{$co_id}_h");
@unlink(G5_DATA_PATH."/content/{$co_id}_t");
$sql = " delete from {$g5['content_table']} where co_id = '$co_id' ";
sql_query($sql);
}
if(function_exists('get_admin_captcha_by'))
get_admin_captcha_by('remove');
g5_delete_cache_by_prefix('content-'.$co_id.'-');
if ($w == "" || $w == "u")
{
if ($_FILES['co_himg']['name'])
{
$dest_path = G5_DATA_PATH."/content/".$co_id."_h";
@move_uploaded_file($_FILES['co_himg']['tmp_name'], $dest_path);
@chmod($dest_path, G5_FILE_PERMISSION);
}
if ($_FILES['co_timg']['name'])
{
$dest_path = G5_DATA_PATH."/content/".$co_id."_t";
@move_uploaded_file($_FILES['co_timg']['tmp_name'], $dest_path);
@chmod($dest_path, G5_FILE_PERMISSION);
}
if( $error_msg ){
alert($error_msg, "./contentform.php?w=u&amp;co_id=$co_id");
} else {
goto_url("./contentform.php?w=u&amp;co_id=$co_id");
}
}
else
{
goto_url("./contentlist.php");
}
<?php
$sub_menu = '300600';
require_once './_common.php';
if ($w == "u" || $w == "d") {
check_demo();
}
if ($w == 'd') {
auth_check_menu($auth, $sub_menu, "d");
} else {
auth_check_menu($auth, $sub_menu, "w");
}
check_admin_token();
$co_row = array('co_id' => '', 'co_include_head' => '', 'co_include_tail' => '');
if ($w == "" || $w == "u") {
if (isset($_REQUEST['co_id']) && preg_match("/[^a-z0-9_]/i", $_REQUEST['co_id'])) {
alert("ID 는 영문자, 숫자, _ 만 가능합니다.");
}
$sql = " select * from {$g5['content_table']} where co_id = '$co_id' ";
$co_row = sql_fetch($sql);
}
$co_id = isset($_REQUEST['co_id']) ? preg_replace('/[^a-z0-9_]/i', '', $_REQUEST['co_id']) : '';
$co_subject = isset($_POST['co_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['co_subject'])))) : '';
$co_include_head = isset($_POST['co_include_head']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_head'], 0, 255)) : '';
$co_include_tail = isset($_POST['co_include_tail']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_tail'], 0, 255)) : '';
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
if ($is_admin !== 'super') {
if ($w == 'u') {
$co_include_head = isset($co_row['co_include_head']) ? $co_row['co_include_head'] : '';
$co_include_tail = isset($co_row['co_include_tail']) ? $co_row['co_include_tail'] : '';
} else {
$co_include_head = '';
$co_include_tail = '';
}
}
// 저장·검증 전에 경로를 먼저 정규화하여, 검증 이후 경로가 달라지지 않도록 한다.
if (function_exists('filter_input_include_path')) {
$co_include_head = filter_input_include_path($co_include_head);
$co_include_tail = filter_input_include_path($co_include_tail);
}
$co_tag_filter_use = isset($_POST['co_tag_filter_use']) ? (int) $_POST['co_tag_filter_use'] : 1;
$co_himg_del = (isset($_POST['co_himg_del']) && $_POST['co_himg_del']) ? 1 : 0;
$co_timg_del = (isset($_POST['co_timg_del']) && $_POST['co_timg_del']) ? 1 : 0;
$co_html = isset($_POST['co_html']) ? (int) $_POST['co_html'] : 0;
$co_content = isset($_POST['co_content']) ? $_POST['co_content'] : '';
$co_mobile_content = isset($_POST['co_mobile_content']) ? $_POST['co_mobile_content'] : '';
$co_skin = isset($_POST['co_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['co_skin']), 1, 1)) : '';
$co_mobile_skin = isset($_POST['co_mobile_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['co_mobile_skin']), 1, 1)) : '';
// 관리자가 자동등록방지를 사용해야 할 경우
if (((isset($co_row['co_include_head']) && $co_row['co_include_head'] !== $co_include_head) || (isset($co_row['co_include_tail']) && $co_row['co_include_tail'] !== $co_include_tail)) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
include_once G5_CAPTCHA_PATH . '/captcha.lib.php';
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
}
@mkdir(G5_DATA_PATH . "/content", G5_DIR_PERMISSION);
@chmod(G5_DATA_PATH . "/content", G5_DIR_PERMISSION);
if ($co_himg_del) {
@unlink(G5_DATA_PATH . "/content/{$co_id}_h");
}
if ($co_timg_del) {
@unlink(G5_DATA_PATH . "/content/{$co_id}_t");
}
$error_msg = '';
if ($co_include_head) {
$file_ext = pathinfo($co_include_head, PATHINFO_EXTENSION);
if (!$file_ext || !in_array($file_ext, array('php', 'htm', 'html')) || !preg_match('/^.*\.(php|htm|html)$/i', $co_include_head)) {
alert('상단 파일 경로의 확장자는 php, htm, html 만 허용합니다.');
}
}
if ($co_include_tail) {
$file_ext = pathinfo($co_include_tail, PATHINFO_EXTENSION);
if (!$file_ext || !in_array($file_ext, array('php', 'htm', 'html')) || !preg_match('/^.*\.(php|htm|html)$/i', $co_include_tail)) {
alert('하단 파일 경로의 확장자는 php, htm, html 만 허용합니다.');
}
}
if ($co_include_head && function_exists('is_content_include_allowed') && !is_content_include_allowed($co_include_head)) {
alert('상단 파일 경로로 사용할 수 없는 위치입니다.');
}
if ($co_include_tail && function_exists('is_content_include_allowed') && !is_content_include_allowed($co_include_tail)) {
alert('하단 파일 경로로 사용할 수 없는 위치입니다.');
}
if ($co_include_head && !is_include_path_check($co_include_head, 1)) {
$co_include_head = '';
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 상단 파일 경로에 포함시킬수 없습니다.';
}
if ($co_include_tail && !is_include_path_check($co_include_tail, 1)) {
$co_include_tail = '';
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 하단 파일 경로에 포함시킬수 없습니다.';
}
$co_seo_title = exist_seo_title_recursive('content', generate_seo_title($co_subject), $g5['content_table'], $co_id);
$sql_common = " co_include_head = '$co_include_head',
co_include_tail = '$co_include_tail',
co_html = '$co_html',
co_tag_filter_use = '$co_tag_filter_use',
co_subject = '$co_subject',
co_content = '$co_content',
co_mobile_content = '$co_mobile_content',
co_seo_title = '$co_seo_title',
co_skin = '$co_skin',
co_mobile_skin = '$co_mobile_skin' ";
if ($w == "") {
$row = $co_row;
if (isset($row['co_id']) && $row['co_id']) {
alert("이미 같은 ID로 등록된 내용이 있습니다.");
}
$sql = " insert {$g5['content_table']}
set co_id = '$co_id',
$sql_common ";
sql_query($sql);
run_event('admin_content_created', $co_id);
} elseif ($w == "u") {
$sql = " update {$g5['content_table']}
set $sql_common
where co_id = '$co_id' ";
sql_query($sql);
run_event('admin_content_updated', $co_id);
} elseif ($w == "d") {
@unlink(G5_DATA_PATH . "/content/{$co_id}_h");
@unlink(G5_DATA_PATH . "/content/{$co_id}_t");
$sql = " delete from {$g5['content_table']} where co_id = '$co_id' ";
sql_query($sql);
run_event('admin_content_deleted', $co_id);
}
if (function_exists('get_admin_captcha_by')) {
get_admin_captcha_by('remove');
}
g5_delete_cache_by_prefix('content-' . $co_id . '-');
if ($w == "" || $w == "u") {
foreach (array('co_himg', 'co_timg') as $content_img_field) {
if (empty($_FILES[$content_img_field]['name']) || empty($_FILES[$content_img_field]['tmp_name']))
continue;
// 상단/하단 이미지 슬롯에는 이미지만 허용하고, 실행 가능한 태그가 담긴 파일은 거부한다.
$tmp_file = $_FILES[$content_img_field]['tmp_name'];
$is_valid_image = @getimagesize($tmp_file);
$head_bytes = @file_get_contents($tmp_file, false, null, 0, 8192);
if ($is_valid_image === false || ($head_bytes !== false && preg_match('/<\?php|<\?=|<\?|<script/i', $head_bytes))) {
alert('상단/하단 이미지에는 이미지 파일만 등록할 수 있습니다.');
}
}
if ($_FILES['co_himg']['name']) {
$dest_path = G5_DATA_PATH . "/content/" . $co_id . "_h";
@move_uploaded_file($_FILES['co_himg']['tmp_name'], $dest_path);
@chmod($dest_path, G5_FILE_PERMISSION);
}
if ($_FILES['co_timg']['name']) {
$dest_path = G5_DATA_PATH . "/content/" . $co_id . "_t";
@move_uploaded_file($_FILES['co_timg']['tmp_name'], $dest_path);
@chmod($dest_path, G5_FILE_PERMISSION);
}
if ($error_msg) {
alert($error_msg, "./contentform.php?w=u&amp;co_id=$co_id");
} else {
goto_url("./contentform.php?w=u&amp;co_id=$co_id");
}
} else {
goto_url("./contentlist.php");
}
+78 -97
View File
@@ -1,97 +1,78 @@
<?php
$sub_menu = '300600';
include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "r");
if( !isset($g5['content_table']) ){
die('<meta charset="utf-8">/data/dbconfig.php 파일에 <strong>$g5[\'content_table\'] = G5_TABLE_PREFIX.\'content\';</strong> 를 추가해 주세요.');
}
//내용(컨텐츠)정보 테이블이 있는지 검사한다.
if(!sql_query(" DESCRIBE {$g5['content_table']} ", false)) {
if(sql_query(" DESCRIBE {$g5['g5_shop_content_table']} ", false)) {
sql_query(" ALTER TABLE {$g5['g5_shop_content_table']} RENAME TO `{$g5['content_table']}` ;", false);
} else {
$query_cp = sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['content_table']}` (
`co_id` varchar(20) NOT NULL DEFAULT '',
`co_html` tinyint(4) NOT NULL DEFAULT '0',
`co_subject` varchar(255) NOT NULL DEFAULT '',
`co_content` longtext NOT NULL,
`co_hit` int(11) NOT NULL DEFAULT '0',
`co_include_head` varchar(255) NOT NULL,
`co_include_tail` varchar(255) NOT NULL,
PRIMARY KEY (`co_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8 ", true);
// 내용관리 생성
sql_query(" insert into `{$g5['content_table']}` set co_id = 'company', co_html = '1', co_subject = '회사소개', co_content= '<p align=center><b>회사소개에 대한 내용을 입력하십시오.</b></p>' ", false );
sql_query(" insert into `{$g5['content_table']}` set co_id = 'privacy', co_html = '1', co_subject = '개인정보 처리방침', co_content= '<p align=center><b>개인정보 처리방침에 대한 내용을 입력하십시오.</b></p>' ", false );
sql_query(" insert into `{$g5['content_table']}` set co_id = 'provision', co_html = '1', co_subject = '서비스 이용약관', co_content= '<p align=center><b>서비스 이용약관에 대한 내용을 입력하십시오.</b></p>' ", false );
}
}
$g5['title'] = '내용관리';
include_once (G5_ADMIN_PATH.'/admin.head.php');
$sql_common = " from {$g5['content_table']} ";
// 테이블의 전체 레코드수만 얻음
$sql = " select count(*) as cnt " . $sql_common;
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) { $page = 1; } // 페이지가 없으면 첫 페이지 (1 페이지)
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = "select * $sql_common order by co_id limit $from_record, {$config['cf_page_rows']} ";
$result = sql_query($sql);
?>
<div class="local_ov01 local_ov">
<?php if ($page > 1) {?><a href="<?php echo $_SERVER['SCRIPT_NAME']; ?>">처음으로</a><?php } ?>
<span class="btn_ov01"><span class="ov_txt">전체 내용</span><span class="ov_num"> <?php echo $total_count; ?>건</span></span>
</div>
<div class="btn_fixed_top">
<a href="./contentform.php" class="btn btn_01">내용 추가</a>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">ID</th>
<th scope="col">제목</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php for ($i=0; $row=sql_fetch_array($result); $i++) {
$bg = 'bg'.($i%2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_id"><?php echo $row['co_id']; ?></td>
<td class="td_left"><?php echo htmlspecialchars2($row['co_subject']); ?></td>
<td class="td_mng td_mng_l">
<a href="./contentform.php?w=u&amp;co_id=<?php echo $row['co_id']; ?>" class="btn btn_03"><span class="sound_only"><?php echo htmlspecialchars2($row['co_subject']); ?> </span>수정</a>
<a href="<?php echo get_pretty_url('content', $row['co_id']); ?>" class="btn btn_02"><span class="sound_only"><?php echo htmlspecialchars2($row['co_subject']); ?> </span> 보기</a>
<a href="./contentformupdate.php?w=d&amp;co_id=<?php echo $row['co_id']; ?>" onclick="return delete_confirm(this);" class="btn btn_02"><span class="sound_only"><?php echo htmlspecialchars2($row['co_subject']); ?> </span>삭제</a>
</td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="3" class="empty_table">자료가 한건도 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page="); ?>
<?php
include_once (G5_ADMIN_PATH.'/admin.tail.php');
<?php
$sub_menu = '300600';
require_once './_common.php';
auth_check_menu($auth, $sub_menu, "r");
if (!isset($g5['content_table'])) {
die('<meta charset="utf-8">/data/dbconfig.php 파일에 <strong>$g5[\'content_table\'] = G5_TABLE_PREFIX.\'content\';</strong> 를 추가해 주세요.');
}
//내용(컨텐츠)정보 테이블이 있는지 검사한다.
$g5['title'] = '내용관리';
require_once G5_ADMIN_PATH . '/admin.head.php';
$sql_common = " from {$g5['content_table']} ";
// 테이블의 전체 레코드수만 얻음
$sql = " select count(*) as cnt " . $sql_common;
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) {
$page = 1;
} // 페이지가 없으면 첫 페이지 (1 페이지)
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = "select * $sql_common order by co_id limit $from_record, {$config['cf_page_rows']} ";
$result = sql_query($sql);
?>
<div class="local_ov01 local_ov">
<?php if ($page > 1) { ?><a href="<?php echo $_SERVER['SCRIPT_NAME']; ?>">처음으로</a><?php } ?>
<span class="btn_ov01"><span class="ov_txt">전체 내용</span><span class="ov_num"> <?php echo $total_count; ?>건</span></span>
</div>
<div class="btn_fixed_top">
<a href="./contentform.php" class="btn btn_01">내용 추가</a>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">ID</th>
<th scope="col">제목</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php for ($i = 0; $row = sql_fetch_array($result); $i++) {
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_id"><?php echo $row['co_id']; ?></td>
<td class="td_left"><?php echo htmlspecialchars2($row['co_subject']); ?></td>
<td class="td_mng td_mng_l">
<a href="./contentform.php?w=u&amp;co_id=<?php echo $row['co_id']; ?>" class="btn btn_03"><span class="sound_only"><?php echo htmlspecialchars2($row['co_subject']); ?> </span>수정</a>
<a href="<?php echo get_pretty_url('content', $row['co_id']); ?>" class="btn btn_02"><span class="sound_only"><?php echo htmlspecialchars2($row['co_subject']); ?> </span> 보기</a>
<a href="./contentformupdate.php?w=d&amp;co_id=<?php echo $row['co_id']; ?>" onclick="return delete_confirm(this);" class="btn btn_02"><span class="sound_only"><?php echo htmlspecialchars2($row['co_subject']); ?> </span>삭제</a>
</td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="3" class="empty_table">자료가 한건도 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page="); ?>
<?php
require_once G5_ADMIN_PATH . '/admin.tail.php';
+110 -49
View File
@@ -28,6 +28,39 @@ box-sizing: border-box;
h2{font-size: 1.083em;font-weight: bold;margin:10px 0}
#wrapper {min-height:480px}
/* admin 공통 */
/* 공통 - display none/block */
.is-hidden { display: none !important; }
.is-visible { display: block !important; }
/* 공통 - 뷰포트 (pc / mobile) 별 display none/block */
.pc-only { display: none; }
@media (min-width: 769px) { .pc-only { display: block !important; }}
.mobile-only { display: block; }
@media (min-width: 769px) { .mobile-only { display: none !important; }}
/* 공통 - 레이어 팝업 */
.popup-overlay { position: fixed; top: 0; left: 0; width: 100%; height: 100%; background: rgba(0,0,0,0.3); backdrop-filter: blur(6px); -webkit-backdrop-filter: blur(6px); z-index: 9999; display: flex; justify-content: center; align-items: center; }
.popup-content { background: #fff; border-radius: 10px; box-shadow: 0 8px 24px rgba(0,0,0,0.15); width: 800px; overflow: hidden; }
.popup-header, .popup-footer { padding: 18px 20px; display: flex; align-items: center; }
.popup-header { justify-content: space-between; border-bottom: 1px solid #e0e0e0; }
.popup-footer { gap: 20px; border-top: 1px solid #e0e0e0;}
.popup-close-btn { background: none; border: none; color: #888; font-size: 20px; cursor: pointer; padding: 4px; display: flex; align-items: center; justify-content: center; transition: color 0.2s ease; }
.popup-close-btn:hover { color: #333; }
.popup-title { font-size: 18px; font-weight: 600; }
.popup-body { padding: 20px; max-height: 400px; overflow-y: auto; color: #333; }
.popup-footer button { background: #3d70ff; color: white; border: 1px solid #3d70ff; padding: 8px 16px; border-radius: 6px; font-weight: 600; cursor: pointer; transition: background 0.2s ease, border-color 0.2s ease; }
.popup-footer button:hover { background: #2b3d9f; border-color: #2b3d9f; }
/* 공통 - tab */
.tab-container { display: flex; flex-direction: column; width: 100%; }
.tab-header { position: relative; bottom: -1px; display: flex; }
.tab-btn { padding: 10px 14px; background: none; border: none; border-bottom: 2px solid transparent; cursor: pointer; color: inherit; font: inherit; }
.tab-btn.active { border-bottom-color: #000; font-weight: bold; }
.tab-body { width: 100%; border-top: 1px solid #ccc; }
.tab-content { padding: 16px 0; }
/* 레이아웃 */
#hd h1 {position:absolute;font-size:0;line-height:0;overflow:hidden}
#hd_top{position:fixed;top:0;left:0;width:100%;height:50px;background:#3f51b5;z-index:1000}
@@ -95,9 +128,11 @@ box-shadow: 2px 0 2px rgba(150,150,150,0.1);}
#container.container-small #container_title{padding-left:70px}
.container_wr{padding:20px}
/* 화면낭독기 사용자용 */
/* 화면낭독기 사용자용 (스크린 리더 대응) */
/* 일반적인 .blind/.sr-only 사용시에 .sound_only 사용 권장 */
#hd_login_msg {position:absolute;top:0;left:0;width:1px;height:1px;overflow:hidden}
.msg_sound_only, .sound_only {display:inline-block !important;position:absolute;top:0;left:0;margin:0 !important;padding:0 !important;width:1px !important;height:1px !important;font-size:0;line-height:0;border:0 !important;overflow:hidden !important}
.sound_only, .msg_sound_only {overflow:hidden;position:absolute;width:1px;height:1px;margin:-1px;padding:0;clip:rect(0,0,0,0)}
/* 본문 바로가기 */
#to_content a {z-index:100000;position:absolute;top:0;left:0;font-size:0;line-height:0;overflow:hidden}
#to_content a:focus, #to_content a:active {width:100%;height:70px;background:#fff;font-size:2em;font-weight:bold;text-align:center;text-decoration:none;line-height:3.1em}
@@ -144,7 +179,7 @@ box-shadow: 2px 0 2px rgba(150,150,150,0.1);}
.btn_submit{background:#ff4081;color:#fff}
a.btn_submit{background:#ff4081;color:#fff}
.btn_confirm .btn_submit {padding:0 15px;border:0;height:30px;color:#fff}
.btn_frmline {display:inline-block;padding:0 7px;height:24px;border:0;background:#444;color:#fff !important;letter-spacing:-0.1em;text-decoration:none;vertical-align:middle;line-height:2em} /* 우편번호검색버튼 등 */
.btn_frmline:focus, .btn_frmline:hover, .btn_frmline:active {text-decoration:none}
@@ -178,14 +213,14 @@ a.btn_submit{background:#ff4081;color:#fff}
.btn_add01 {text-align:right}
.btn_add01 a, .btn_add01 button {padding:10px;border:1px solid #ccc;background:#f0f0f0;text-decoration:none;cursor:pointer}
.btn_add01 a {display:inline-block;vertical-align:middle}btn_confirm
.btn_add01 a {display:inline-block;vertical-align:middle}
.btn_add01 button {margin:0}
.td_mng a.btn,.td_mng a{display:inline-block;height:26px;line-height:26px;border:0;border-radius:3px;padding:0 8px;margin:1px;font-weight:normal}
.td_mng button,.td_mng button.btn{height:26px;border:0;border-radius:3px;padding:0 8px;margin:1px;font-weight:normal}
.btn{height:30px;border:0;border-radius:5px;padding:0 10px;font-weight:bold;font-size:1.09em;vertical-align:middle}
a.btn{display:inline-block;height:30px;line-height:30px;border:0;border-radius:5px;padding:0 10px;font-weight:bold;font-size:1.09em;vertical-align:middle}
.btn_submit{background:#ff4081;color:#fff}
@@ -208,7 +243,7 @@ a.btn_ov02:hover,a.ov_listall:hover{background:#3f51b5}
/*form*/
.sound_only {display:inline-block !important;position:absolute;top:0;left:0;margin:0 !important;padding:0 !important;width:1px !important;height:1px !important;font-size:0;line-height:0;border:0 !important;overflow:hidden !important}
.frm_input{height:35px;line-height:32px;border:1px solid #d5d5d5;}
.frm_input{padding:0 5px;height:35px;line-height:32px;border:1px solid #d5d5d5;}
.frm_input_full{width:100%}
.required{background:url('../img/wrest.gif') top right no-repeat #fff !important}
select{height:35px;line-height:32px;border:1px solid #d5d5d5;}
@@ -218,7 +253,7 @@ legend {position:absolute;width:0;height:0;font-size:0;line-height:0;text-indent
/* 외부서비스 사이트코드 */
.sitecode {display:inline-block;font:bold 15px 'Verdana';vertical-align:middle}
.sitecode.title {width:80px}
.readonly {}
@@ -247,18 +282,14 @@ legend {position:absolute;width:0;height:0;font-size:0;line-height:0;text-indent
.anchor a {display:inline-block;padding:5px 10px;border:1px solid #c8ced1;background:#d6dde1;text-decoration:none}
.anchor .selected{background:#3f51b5}
#sort_mb {width:800px}
#sort_sodr {width:600px}
/* 하단 레이아웃 */
#ft{background:#f3f3f3;padding:0 25px;color:#777;text-align:center}
#ft p{line-height:50px;}
.scroll_top{position:fixed;bottom:10px;right:10px;width:50px;height:50px;border:0;text-align:center;background:#ddd;background:rgba(0,0,0,0.1)}
.scroll_top{position:fixed;bottom:10px;right:10px;width:50px;height:50px;border:0;text-align:center;background:#ddd;background:rgba(0,0,0,0.1);z-index:50;}
.scroll_top span.top_img{display:inline-block;width: 0; height: 0; border-left: 5px solid transparent;border-right: 5px solid transparent;
border-bottom: 5px solid black;}
.scroll_top span.top_txt{display:block}
@@ -281,9 +312,50 @@ border-bottom: 5px solid black;}
.local_sch03 button{height:30px;padding:0 5px;border:0;background:#9eacc6;color:#fff;}
.local_sch03 .btn_submit{height:30px;padding:0 5px;border:0;color:#fff;}
.local_sch03 .frm_input{height:30px;border:1px solid #dcdcdc;padding:0 5px;}
/* 페이지 내 실행 */
.local_cmd {min-width:960px}
/* 회원 관리 데이터 필터링 */
.member_list_data { display: flex; flex-direction: column; padding: 20px; margin: 20px 0 40px; background: #f9f9f9; border: 1px solid #f2f2f2; color: #333; }
.sch_table { display: flex; flex-direction: column; gap: 10px; font-size: 11.5px; color: #333; }
.member_list_data .sch_row { display: flex; align-items: center; gap: 12px; min-height: 30px; }
.label { min-width: 120px; font-weight: 500; white-space: nowrap; display: flex; align-items: center; }
.label label {display: flex; gap: 10px;}
.field { flex: 1; display: flex; flex-wrap: wrap; align-items: center; gap: 8px; }
.field input[type="text"], .field input[type="number"], .field input[type="date"], .field select { height: 30px; min-width: 100px; padding: 0 10px; font-size: 11.5px; border: 1px solid #ddd; border-radius: 8px; background: #fff; transition: border-color 0.2s ease, box-shadow 0.2s ease; }
.field input[type="text"]:focus, .field input[type="number"]:focus, .field input[type="date"]:focus, .field select:focus { border-color: #6f809a; box-shadow: 0 0 0 2px rgba(63,81,181,0.1); outline: none; }
.field input::placeholder { color: #aaa; }
.field input[type="checkbox"], .field input[type="radio"] { width: 14px; height: 14px; accent-color: #536177; }
.radio_group { display: flex; gap: 15px; align-items: center; padding: 0 10px;}
.radio_group label {display: flex; align-items: center; gap: 5px;}
.ad_range_wrap {flex: 1; padding-left: 20px;}
.ad_range_box {display: flex;}
.ad_range_box .label {width: 109px;}
.sch_notice { font-size: 11px; color: #999; }
.sch_btn { display: flex; gap: 20px; justify-content: center; margin-top: 40px; }
.sch_btn { display: flex; gap: 10px; }
.btn_reset { display: flex; align-items: center; gap: 6px; padding: 0 20px; height: 40px; background: #9eacc6; color: #fff; font-weight: 600; border: none; border-radius: 8px; cursor: pointer; transition: background 0.2s ease, transform 0.15s ease; }
.btn_reset:hover { background: #5f6e89; }
.sch_btn button:not(.btn_reset) { padding: 0 20px; height: 40px; border: 1px solid #ccd1d8; background-color: #fff; color: #444; font-weight: 600; border-radius: 8px; cursor: pointer; user-select: none; transition: border-color 0.2s ease, box-shadow 0.2s ease; box-shadow: 0 1px 2px rgba(0,0,0,0.03); }
.sch_btn button:not(.btn_reset):hover { border-color: #6f809a; box-shadow: 0 2px 4px rgba(111, 128, 154, 0.15); }
.sch_btn button:not(.btn_reset):active { box-shadow: inset 0 1px 2px rgba(0,0,0,0.1); }
/* 회원 관리 다운로드 진행 팝업 */
.excel-download-progress p { color: #374151; }
.excel-download-progress .progress-desc { padding: 40px 0 32px; text-align: center; }
.excel-download-progress .progress-summary { margin-bottom: 6px; font-size: 16px; font-weight: 500; color: #111827; }
.excel-download-progress .progress-message { font-size: 20px; font-weight: 600; color: #3b82f6; }
.excel-download-progress .progress-error { color:red; }
.progress-spinner { display: flex; flex-direction: column; align-items: center; gap: 45px; padding: 24px 0; transition: all 0.2s ease; }
.spinner { width: 48px; height: 48px; border: 5px solid #3b82f6; border-top: 5px solid #fff; border-radius: 50%; animation: spin 0.8s linear infinite; }
@keyframes spin { to { transform: rotate(360deg); } }
.loading-message { text-align: center; font-size: 14px; color: #374151; }
.excel-download-progress .progress-download-box { margin-top: 24px; background: #f9fafb; padding: 20px; border-radius: 8px; box-shadow: 0 1px 2px rgba(0,0,0,0.03); }
.excel-download-progress .progress-download-box a { display: block; width: 100%; height: auto; text-align: center; margin-top: 8px; font-weight: 600; font-size: 14px; padding: 10px 20px; background: #fff; border: 1px solid #ccd1d8; border-radius: 8px; color: #444; cursor: pointer; transition: border-color 0.2s ease, box-shadow 0.2s ease; box-shadow: 0 1px 2px rgba(0,0,0,0.03); }
.excel-download-progress .progress-download-box a:hover { border-color: #6f809a; box-shadow: 0 2px 4px rgba(111, 128, 154, 0.15); }
.excel-download-progress .progress-download-box a:active { box-shadow: inset 0 1px 2px rgba(0,0,0,0.1); }
/* 페이지 내 실행 */
.local_cmd {min-width:960px}
.local_cmd01 {margin:0 0 10px;padding:0 }
.local_cmd01 .cmd_tit {font-weight:bold}
.local_cmd01 .btn_submit {padding:3px 5px;border:1px solid #ff3061;color:#fff;font-size:0.95em;vertical-align:middle}
@@ -298,7 +370,7 @@ border-bottom: 5px solid black;}
.local_desc01 {margin:10px 0 10px ;padding:10px 20px;border:1px solid #f2f2f2;background:#f9f9f9}
.local_desc01 strong {color:#ff3061}
.local_desc01 a {text-decoration:underline}
.local_desc01 a {text-decoration:underline;text-underline-offset:2px;}
.local_desc02 {margin:10px 0 ;min-width:960px} /* 주로 온라인 서식 관련 안내 내용에 사용 */
.local_desc02 p {padding:0;line-height:1.8em}
@@ -310,7 +382,7 @@ border-bottom: 5px solid black;}
.local_ov01 .ov_a{display:inline-block;line-height:30px;height:30px;font-size:0.92em;background:#ff4081;color:#fff;vertical-align:top;border-radius:5px;padding:0 7px}
.local_ov01 .ov_a:hover{background:#ff1464}
/* 테이블 */
table {clear:both;width:100%;border-collapse:collapse;border-spacing:0;}
table caption {height:0;font-size:0;line-height:0;overflow:hidden}
@@ -401,6 +473,7 @@ tfoot th {}
.mb_leave_msg {color:#b6b6b6}
.mb_intercept_msg {color:#ff0000}
#point_mng {margin-top:50px}
.ad_agree_log {max-height: 150px !important;}
/* 게시판추가/수정 */
#anc_bo_extra .td_grpset label {width:auto}
@@ -447,6 +520,7 @@ tfoot th {}
.td_delino {width:130px}
.td_device {width:70px;text-align:center}
.td_etc {width:80px;text-align:center}
.td_use {width:80px;text-align:center}
.td_extra label {display:inline-block;width:100px}
.td_extra input {margin-right:5px;width:130px}
.td_grid {width:60px;text-align:center}
@@ -503,6 +577,7 @@ td.td_grpset {width:160px;border-left:1px solid #e9ecee;text-align:center}
.td_time{text-align:center;width:130px}
.td_center{text-align:center;}
.td_type{width:120px}
.td_consent{min-width:70px;max-width:200px}
.td_mng_s{width:60px}
.td_mng_m{width:100px}
@@ -621,8 +696,8 @@ a.scf_pgreg {display:inline-block;margin:5px 0 0;padding:5px 10px;background:#22
a.kcp_btn {display:inline-block;margin:5px 0 0;padding:5px 10px;background:#226C8B;color:#fff;font-weight:normal;text-decoration:none}
a.lg_btn{display:inline-block;margin:5px 0 0;padding:5px 10px;background:#ED008C;color:#fff;font-weight:normal;text-decoration:none}
a.kg_btn{display:inline-block;margin:5px 0 0;padding:5px 10px;background:#4A2C7C;color:#fff;font-weight:normal;text-decoration:none}
a.kakao_btn{display:inline-block;margin:5px 0 0;padding:5px 10px;background:#FDDC2F;color:#3B1E1E;font-weight:normal;text-decoration:none}
a.naver_btn {display:inline-block;margin:5px 0 0;padding:5px 10px;background:#00C73C;color:#fff;font-weight:normal;text-decoration:none}
a.nicepay_btn{display:inline-block;margin:5px 0 0;padding:5px 10px;background:#0057bf;color:#fff;font-weight:normal;text-decoration:none}
.scf_cardtest {margin:5px 0 0}
.scf_cardtest_btn {margin-left:5px;vertical-align:middle}
@@ -654,17 +729,18 @@ a.naver_btn {display:inline-block;margin:5px 0 0;padding:5px 10px;background:#00
ul.de_pg_tab{margin:0;padding:0;zoom:1}
ul.de_pg_tab:after{display:block;visibility:hidden;clear:both;content:"";}
ul.de_pg_tab li{position:relative;display:inline-block;float:left;text-align:center;margin:0;padding:0;width:120px}
ul.de_pg_tab li a{margin:0 2px;display:block;overflow:hidden;text-overflow:ellipsis;white-space:nowrap;line-height:2.5;background-color:#f7f7f7;color:#74777b;font-weight:bold;font-size:1.2em;text-decoration:none}
ul.de_pg_tab li{position:relative;display:inline-block;float:left;text-align:center;margin:0;padding:0;min-width:130px}
ul.de_pg_tab li a{margin:0 2px;display:block;overflow:hidden;text-overflow:ellipsis;white-space:nowrap;line-height:2.5;background-color:#f7f7f7;color:#74777b;font-weight:bold;font-size:1.2em;text-decoration:none; padding:0px 10px;}
ul.de_pg_tab li a:hover{text-decoration:none}
ul.de_pg_tab li.tab-current a{background:#2CC185;color:#fff}
.pg_info_fld{position:relative}
.kcp_info_fld th{background-color:#F6FCFF}
.lg_info_fld th{background-color:#FFF4FA}
.lg_info_fld_v2 th{background-color:#ffe8f5}
.inicis_info_fld th{background-color:#F6F1FF}
.kakao_info_fld th{background-color:#FFFCED}
.naver_info_fld th{background-color:#F3FFF3}
.nicepay_info_fld th{background-color:#d1e6ff}
/* 주문내역 */
#sodr_list td {text-align:center}
@@ -750,7 +826,7 @@ strong.sodr_nonpay {display:block;padding:5px 0;text-align:right}
/* 분류관리 목록 */
#sct .sct_name {width:130px}
#sct th{padding:5px}
#sct .sct_name div {position:relative}
#sct .sct_name1 {padding-left:25px}
#sct .sct_name2 {padding-left:50px}
@@ -876,20 +952,6 @@ strong.sodr_nonpay {display:block;padding:5px 0;text-align:right}
.sbn_img {text-align:center}
.sbn_image {display:none;margin:0 0 10px;text-align:left}
/* SMS문자전송 */
#sms_send {padding-bottom:100px;zoom:1}
#sms_send:after {display:block;visibility:hidden;clear:both;content:""}
#sms_frm {float:left;width:650px}
#sms_frm table {margin:0 0 30px}
#sms_frm textarea {height:70px}
#sms_sm {position:relative;float:left;width:229px;height:418px;background:url('../shop_admin/img/mobilebg.jpg') no-repeat}
#sms_sm_text {position:absolute;top:75px;left:27px;width:180px;color:#fff;font-size:2em;word-break:break-all}
#sms_sm p {position:absolute;bottom:-70px;left:0;font-size:0.95em;letter-spacing:-0.1em}
#sms_send .local_desc01 {min-width:320px}
/* 가격비교사이트 */
#anc_pricecompare_info li {margin:5px 0 5px -1px}
@@ -905,10 +967,8 @@ strong.sodr_nonpay {display:block;padding:5px 0;text-align:right}
.new_win_ul {margin:-20px 0 20px 0;padding:0 0 0 20px;border-bottom:1px solid #515151;background:#484848;list-style:none;zoom:1}
.new_win_ul:after {display:block;visibility:hidden;clear:both;content:""}
.new_win_ul li {float:left;margin-left:-1px}
.new_win_ul a {display:block;padding:10px 10px 8px;border-right:1px solid #595959;border-left:1px solid #595959;color:#fff;font-family:dotum;font-weight:bold;text-decoration:none}
.new_win_desc {margin:0 }
.new_win .anchor {margin:0 0 5px}
@@ -918,12 +978,13 @@ strong.sodr_nonpay {display:block;padding:5px 0;text-align:right}
.new_win .win_btn a {display:inline-block;padding:0 10px;height:30px;background:#4b545e;color:#fff;vertical-align:middle;line-height:2.4em}
.new_win .win_btn a:focus, .new_win .win_btn a:hover {text-decoration:none}
.new_win .local_sch, .new_win .local_cmd, .new_win .local_desc01, .new_win .local_desc02, .new_win .local_ov {margin:10px}
.new_win_con{margin: 10px; background:#fff;padding:20px}
.new_win_con .table_form table th{width:120px}
.new_win .btn_confirm {text-align:center;}
/* 자바스크립트 alert 대안 */
#validation_check {margin:100px auto;width:500px}
#validation_check h1 {margin-bottom:20px;font-size:1.3em}
@@ -1001,7 +1062,7 @@ box-shadow: 2px 2px 3px 0px rgba(0,0,0,0.2);}
.service_wrap{ width:965px;margin:0 0 10px;overflow:hidden}
.sevice_1{border:1px solid #ebe8e8;width:310px;float:left;border-radius:5px;text-align:center;margin-right:6px;}
.sevice_1 .svc_img{padding:30px 0 0;}
.sevice_1 h3{font-size:16px;margin:185px 0 10px;color:#525252}
.sevice_1 h3{font-size:16px;margin:190px 0 10px;min-height:45px;color:#525252}
.sevice_1 p{padding:20px;background:#f8f8f8;font-size:12px;text-align:left;color:#898989;line-height:18px}
.sevice_1 ul {width:100%;padding:0; margin:0;border-top:1px solid #ebe8e8;}
.sevice_1 ul li{list-style:none;float:left;border-right:1px solid #ebe8e8;}
@@ -1011,10 +1072,10 @@ box-shadow: 2px 2px 3px 0px rgba(0,0,0,0.2);}
.sevice_1 h4{width:100%;padding:0; margin:0;border-top:1px solid #ebe8e8;}
.sevice_1 h4 a{display:inline-block;height:75px;padding:10px 0 0;width:100%}
.svc_card{background:url('../img/service_img1.jpg') no-repeat top center;margin-right:13px;}
.svc_card ul li{width:33%;}
.svc_card{background:url('../img/service_img1.jpg') no-repeat top center;margin-right:13px;width:520px;}
.svc_card ul li{width:25%;box-sizing:border-box;}
.svc_phone {background:url('../img/service_img2.jpg') no-repeat top center;margin-right:13px;}
.svc_phone ul li{width:33%;}
.svc_phone ul li{width:50%;}
.svc_ipin {background:url('../img/service_img3.jpg') no-repeat top center;}
.service_2{padding-top:15px;clear:both}
@@ -1053,7 +1114,7 @@ box-shadow: 2px 2px 3px 0px rgba(0,0,0,0.2);}
#theme_list{padding:0;margin:0;list-style:none; width: 1000px;position:relative}
#theme_list:after{display:block;visibility:hidden;clear:both;content:""}
#theme_list li{margin:10px 10px 10px 0;float:left}
#theme_list li:after{display:block;visibility:hidden;clear:both;content:""}
#theme_list li .tmli_if{border: 1px solid #d1dee2;width:302px;}
#theme_list li .tmli_if>img{width:300px;height:225px;}
@@ -1076,7 +1137,7 @@ box-shadow: 1px 2px 5px rgba(150,150,150,0.5);z-index:1000}
#theme_detail:after{display:block;visibility:hidden;clear:both;content:""}
#theme_detail h2{font-size:1.25em;background:#fff;padding:0 15px;line-height:40px;border-bottom:1px solid #d8d8d8;margin:0}
.theme_dt_img{float:left;padding:20px}
.theme_dt_img img{border:1px solid #aaa;}
.theme_dt_img img{border:1px solid #aaa;max-width:600px;max-height:460px}
.theme_dt_if{float:left;width:235px;padding:20px 0}
.theme_dt_if table{width:100%;border-collapse:collapse;margin:15px 0 0 ;font-size:0.92em}
.theme_dt_if table th{padding:5px;background:#fff;border-bottom:1px solid #f3f3f3;vertical-align:top;color:#3f51b5}
@@ -1111,9 +1172,9 @@ box-shadow: 1px 2px 5px rgba(150,150,150,0.5);z-index:1000}
#processing{margin: 0 auto;padding: 70px 0;border: 1px solid #eee;background: #f9f9f9;text-align:center;}
#processing p{font-size:1.2em}
.check_processing {width:300px;height:300px;margin:0 auto;background:url(../img/check.png) no-repeat 50% 50% }
#processing button{background:#ff3061;border:none;color:#fff;padding: 15px;width:200px;margin-top:15px;border-radius:5px;font-weight:bold;font-size:1.167em}
#processing button{background:#ff3061;border:none;color:#fff;padding: 15px;width:200px;margin-top:15px;border-radius:5px;font-weight:bold;font-size:1.167em}
/*미완료 주문*/
@@ -1134,7 +1195,7 @@ box-shadow: 1px 2px 5px rgba(150,150,150,0.5);z-index:1000}
#itemuselist .use_href{font-weight:bold;text-decoration:none;display:block;}
#itemuselist .use_href .tit_op{background:url(./../img/op_btn1.gif) no-repeat 50% 50%;display:inline-block;text-indent:-999px;overflow:hidden;width:7px;height:4px;margin-left:5px}
#itemuselist .use_div{background:#d8dfe9;padding:10px;margin:5px 0 0;display:none;}
#itemuselist .td_select{width:100px}
#itemuselist .td_select{width:100px}
@media only screen and (max-device-width : 768px) and (orientation : landscape){
+199 -206
View File
@@ -1,220 +1,213 @@
<?php
$sub_menu = '100410';
include_once('./_common.php');
include_once(G5_LIB_PATH . '/migration.lib.php');
include_once(G5_LIB_PATH . '/shop_install.lib.php');
auth_check_menu($auth, $sub_menu, 'r');
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
$is_execute = isset($_SERVER['REQUEST_METHOD']) && $_SERVER['REQUEST_METHOD'] === 'POST';
$migration_result = array('success' => true, 'applied' => 0, 'skipped' => 0, 'errors' => array());
$shop_install_result = null;
$action = '';
if ($is_execute) {
check_demo();
check_admin_token();
$action = isset($_POST['action']) ? trim($_POST['action']) : 'migrate';
if ($action === 'install_shop') {
$shop_install_result = g5_shop_install_run();
} elseif ($action === 'record_existing') {
$migration_result = g5_migration_run('', true);
} else {
$migration_id = isset($_POST['migration_id']) ? trim($_POST['migration_id']) : '';
$migration_result = g5_migration_run($migration_id);
$migration_result = run_replace('admin_dbupgrade_result', $migration_result);
}
}
$migration_statuses = g5_migration_status();
$pending_count = 0;
$unrecorded_count = 0;
foreach ($migration_statuses as $migration_status) {
if (isset($migration_status['status']) && $migration_status['status'] === 'unrecorded') {
$unrecorded_count++;
} elseif (isset($migration_status['error']) || $migration_status['status'] !== 'success' || $migration_status['checksum_changed']) {
$pending_count++;
}
}
if ($shop_install_result !== null && $shop_install_result['success']) {
alert('쇼핑몰 설치가 완료되었습니다.', G5_ADMIN_URL . '/dbupgrade.php');
} elseif ($shop_install_result !== null) {
$db_upgrade_msg = '쇼핑몰 설치에 실패했습니다. 오류 내용을 확인해 주십시오.';
} elseif (!$is_execute) {
$db_upgrade_msg = $pending_count ? '확인·실행이 필요한 DB 마이그레이션이 있습니다. 아래 내용을 확인해 주십시오.' : ($unrecorded_count ? '현재 실행할 변경은 없지만 기존 상태 확인 이력이 등록되지 않았습니다.' : 'DB 마이그레이션이 모두 적용되어 있습니다.');
} elseif (!$migration_result['success']) {
$db_upgrade_msg = 'DB 마이그레이션에 실패했습니다. 오류 내용을 확인해 주십시오.';
} elseif ($action === 'record_existing') {
$db_upgrade_msg = '기존 상태 확인 이력 ' . (int) $migration_result['skipped'] . '건을 등록했습니다. 선행 항목에 실행이 필요하거나 실패 이력이 있으면 등록을 중단합니다.';
} elseif ($migration_result['applied'] || $migration_result['skipped']) {
$db_upgrade_msg = 'DB 마이그레이션이 완료되었습니다.';
} else {
$db_upgrade_msg = '적용할 DB 마이그레이션이 없습니다.';
}
$g5['title'] = 'DB 업그레이드';
include_once('./admin.head.php');
$is_check = false;
//소셜 로그인 관련 필드 및 구글 리챕챠 필드 추가
if(!isset($config['cf_social_login_use'])) {
sql_query("ALTER TABLE `{$g5['config_table']}`
ADD `cf_social_login_use` tinyint(4) NOT NULL DEFAULT '0' AFTER `cf_googl_shorturl_apikey`,
ADD `cf_google_clientid` varchar(100) NOT NULL DEFAULT '' AFTER `cf_twitter_secret`,
ADD `cf_google_secret` varchar(100) NOT NULL DEFAULT '' AFTER `cf_google_clientid`,
ADD `cf_naver_clientid` varchar(100) NOT NULL DEFAULT '' AFTER `cf_google_secret`,
ADD `cf_naver_secret` varchar(100) NOT NULL DEFAULT '' AFTER `cf_naver_clientid`,
ADD `cf_kakao_rest_key` varchar(100) NOT NULL DEFAULT '' AFTER `cf_naver_secret`,
ADD `cf_social_servicelist` varchar(255) NOT NULL DEFAULT '' AFTER `cf_social_login_use`,
ADD `cf_payco_clientid` varchar(100) NOT NULL DEFAULT '' AFTER `cf_social_servicelist`,
ADD `cf_payco_secret` varchar(100) NOT NULL DEFAULT '' AFTER `cf_payco_clientid`,
ADD `cf_captcha` varchar(100) NOT NULL DEFAULT '' AFTER `cf_kakao_js_apikey`,
ADD `cf_recaptcha_site_key` varchar(100) NOT NULL DEFAULT '' AFTER `cf_captcha`,
ADD `cf_recaptcha_secret_key` varchar(100) NOT NULL DEFAULT '' AFTER `cf_recaptcha_site_key`
", true);
$is_check = true;
}
//소셜 로그인 관련 필드 카카오 클라이언트 시크릿 추가
if(!isset($config['cf_kakao_client_secret'])) {
sql_query("ALTER TABLE `{$g5['config_table']}`
ADD `cf_kakao_client_secret` varchar(100) NOT NULL DEFAULT '' AFTER `cf_kakao_rest_key`
", true);
$is_check = true;
}
// 회원 이미지 관련 필드 추가
if(!isset($config['cf_member_img_size'])) {
sql_query("ALTER TABLE `{$g5['config_table']}`
ADD `cf_member_img_size` int(11) NOT NULL DEFAULT '0' AFTER `cf_member_icon_height`,
ADD `cf_member_img_width` int(11) NOT NULL DEFAULT '0' AFTER `cf_member_img_size`,
ADD `cf_member_img_height` int(11) NOT NULL DEFAULT '0' AFTER `cf_member_img_width`
", true);
$sql = " update {$g5['config_table']} set cf_member_img_size = 50000, cf_member_img_width = 60, cf_member_img_height = 60 ";
sql_query($sql, false);
$is_check = true;
}
// 소셜 로그인 관리 테이블 없을 경우 생성
if( isset($g5['social_profile_table']) && !sql_query(" DESC {$g5['social_profile_table']} ", false)) {
sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['social_profile_table']}` (
`mp_no` int(11) NOT NULL AUTO_INCREMENT,
`mb_id` varchar(255) NOT NULL DEFAULT '',
`provider` varchar(50) NOT NULL DEFAULT '',
`object_sha` varchar(45) NOT NULL DEFAULT '',
`identifier` varchar(255) NOT NULL DEFAULT '',
`profileurl` varchar(255) NOT NULL DEFAULT '',
`photourl` varchar(255) NOT NULL DEFAULT '',
`displayname` varchar(150) NOT NULL DEFAULT '',
`description` varchar(255) NOT NULL DEFAULT '',
`mp_register_day` datetime NOT NULL DEFAULT '0000-00-00 00:00:00',
`mp_latest_day` datetime NOT NULL DEFAULT '0000-00-00 00:00:00',
UNIQUE KEY `mp_no` (`mp_no`),
KEY `mb_id` (`mb_id`),
KEY `provider` (`provider`)
) ", true);
$is_check = true;
}
// 게시판 짧은 주소
$sql = " select bo_table from {$g5['board_table']} ";
$result = sql_query($sql);
while ($row = sql_fetch_array($result)) {
$write_table = $g5['write_prefix'] . $row['bo_table']; // 게시판 테이블 전체이름
$sql = " SHOW COLUMNS FROM {$write_table} LIKE 'wr_seo_title' ";
$row = sql_fetch($sql);
if( !$row ){
sql_query("ALTER TABLE `{$write_table}`
ADD `wr_seo_title` varchar(200) NOT NULL DEFAULT '' AFTER `wr_content`,
ADD INDEX `wr_seo_title` (`wr_seo_title`);
", false);
$is_check = true;
}
}
// 내용 관리 짧은 주소
$sql = " SHOW COLUMNS FROM `{$g5['content_table']}` LIKE 'co_seo_title' ";
$row = sql_fetch($sql);
if( !$row ){
sql_query("ALTER TABLE `{$g5['content_table']}`
ADD `co_seo_title` varchar(200) NOT NULL DEFAULT '' AFTER `co_content`,
ADD INDEX `co_seo_title` (`co_seo_title`);
", false);
$is_check = true;
}
$sql = "select * from {$g5['content_table']} limit 100 ";
$result = sql_query($sql);
while ($row = sql_fetch_array($result)) {
if( ! $row['co_seo_title']){
$co_seo_title = exist_seo_title_recursive('content', generate_seo_title($row['co_subject']), $g5['content_table'], $row['co_id']);
$sql = " update {$g5['content_table']}
set co_seo_title = '$co_seo_title'
where co_id = '{$row['co_id']}' ";
sql_query($sql);
}
}
// 메모 테이블
$sql = " SHOW COLUMNS FROM `{$g5['memo_table']}` LIKE 'me_send_id' ";
$row = sql_fetch($sql);
if( !$row ){
sql_query("ALTER TABLE `{$g5['memo_table']}`
ADD `me_send_id` INT(11) NOT NULL DEFAULT '0',
ADD `me_type` ENUM('send','recv') NOT NULL DEFAULT 'recv',
ADD `me_send_ip` VARCHAR(100) NOT NULL DEFAULT '',
CHANGE COLUMN `me_id` `me_id` INT(11) NOT NULL AUTO_INCREMENT;
", false);
$is_check = true;
}
// 읽지 않은 메모 수 칼럼
if(!isset($member['mb_memo_cnt'])) {
sql_query(" ALTER TABLE `{$g5['member_table']}`
ADD `mb_memo_cnt` int(11) NOT NULL DEFAULT '0' AFTER `mb_memo_call`", true);
$is_check = true;
}
// 스크랩 읽은 수 추가
if(!isset($member['mb_scrap_cnt'])) {
sql_query(" ALTER TABLE `{$g5['member_table']}`
ADD `mb_scrap_cnt` int(11) NOT NULL DEFAULT '0' AFTER `mb_memo_cnt`", true);
$is_check = true;
}
// 짧은 URL 주소를 사용 여부 필드 추가
if (!isset($config['cf_bbs_rewrite'])) {
sql_query(" ALTER TABLE `{$g5['config_table']}`
ADD `cf_bbs_rewrite` tinyint(4) NOT NULL DEFAULT '0' AFTER `cf_link_target` ", true);
$is_check = true;
}
// 파일테이블에 추가 칼럼
$sql = " SHOW COLUMNS FROM `{$g5['board_file_table']}` LIKE 'bf_fileurl' ";
$row = sql_fetch($sql);
if( !$row ) {
sql_query(" ALTER TABLE `{$g5['board_file_table']}`
ADD COLUMN `bf_fileurl` VARCHAR(255) NOT NULL DEFAULT '' AFTER `bf_content`,
ADD COLUMN `bf_thumburl` VARCHAR(255) NOT NULL DEFAULT '' AFTER `bf_fileurl`,
ADD COLUMN `bf_storage` VARCHAR(50) NOT NULL DEFAULT '' AFTER `bf_thumburl`", true);
$is_check = true;
}
// 임시저장 테이블이 없을 경우 생성
if(!sql_query(" DESC {$g5['g5_shop_post_log_table']} ", false)) {
sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['g5_shop_post_log_table']}` (
`log_id` int(11) NOT NULL AUTO_INCREMENT,
`oid` bigint(20) unsigned NOT NULL,
`mb_id` varchar(255) NOT NULL DEFAULT '',
`post_data` text NOT NULL,
`ol_code` varchar(255) NOT NULL DEFAULT '',
`ol_msg` text NOT NULL,
`ol_datetime` datetime NOT NULL DEFAULT '0000-00-00 00:00:00',
`ol_ip` varchar(25) NOT NULL DEFAULT '',
PRIMARY KEY (`log_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8; ", true);
$is_check = true;
}
$result = sql_query("describe `{$g5['g5_shop_post_log_table']}`");
while ($row = sql_fetch_array($result)){
if( $row['Field'] === 'ol_msg' && $row['Type'] === 'varchar(255)' ){
sql_query("ALTER TABLE `{$g5['g5_shop_post_log_table']}` MODIFY ol_msg TEXT NOT NULL;", false);
sql_query("ALTER TABLE `{$g5['g5_shop_post_log_table']}` DROP PRIMARY KEY;", false);
sql_query("ALTER TABLE `{$g5['g5_shop_post_log_table']}` ADD `log_id` int(11) NOT NULL AUTO_INCREMENT, ADD PRIMARY KEY (`log_id`);", false);
$is_check = true;
break;
}
}
$is_check = run_replace('admin_dbupgrade', $is_check);
$db_upgrade_msg = $is_check ? 'DB 업그레이드가 완료되었습니다.' : '더 이상 업그레이드 할 내용이 없습니다.<br>현재 DB 업그레이드가 완료된 상태입니다.';
$dbupgrade_token = get_admin_token();
?>
<div class="local_desc01 local_desc">
<p>
<?php echo $db_upgrade_msg; ?>
</p>
<p><?php echo $db_upgrade_msg; ?></p>
<?php if ($unrecorded_count) { ?>
<p>실행 불필요 <?php echo (int) $unrecorded_count; ?>건: 현재 실행 조건상 건너뛰는 항목입니다. 과거 실행 성공을 의미하지 않으며, 선행 작업 후에는 결과가 달라질 수 있습니다. 기존 상태 등록은 처음부터 연속해서 실행 불필요한 항목만 기록합니다.</p>
<?php } ?>
<p>대기 항목에는 데이터 보정 등 조회만으로 완료를 판단할 수 없는 작업도 포함됩니다. 조회 시 DB 변경이나 이력 등록은 수행하지 않습니다.</p>
</div>
<?php if ($shop_install_result !== null && !$shop_install_result['success']) { ?>
<div class="local_desc01 local_desc" style="color:#d00">
<p><?php echo htmlspecialchars($shop_install_result['error'], ENT_QUOTES, 'UTF-8'); ?></p>
</div>
<?php } elseif ($migration_result['errors']) { ?>
<div class="local_desc01 local_desc" style="color:#d00">
<?php foreach ($migration_result['errors'] as $migration_error) { ?>
<p><?php echo htmlspecialchars($migration_error, ENT_QUOTES, 'UTF-8'); ?></p>
<?php } ?>
</div>
<?php } ?>
<div class="dbupgrade_all_actions">
<?php if ($unrecorded_count) { ?>
<form class="dbupgrade_existing_action" method="post" action="<?php echo G5_ADMIN_URL; ?>/dbupgrade.php">
<input type="hidden" name="token" value="<?php echo $dbupgrade_token; ?>">
<input type="hidden" name="action" value="record_existing">
<button type="submit" class="btn_submit">기존 상태 확인 이력 등록</button>
</form>
<?php } ?>
<?php if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) { ?>
<form method="post" action="<?php echo G5_ADMIN_URL; ?>/dbupgrade.php" onsubmit="return confirm('쇼핑몰을 설치하시겠습니까? 설치 전 데이터베이스와 data/dbconfig.php 백업을 권장합니다.');">
<input type="hidden" name="token" value="<?php echo $dbupgrade_token; ?>">
<input type="hidden" name="action" value="install_shop">
<button type="submit" class="btn_submit">쇼핑몰 설치</button>
</form>
<?php } ?>
<form method="post" action="<?php echo G5_ADMIN_URL; ?>/dbupgrade.php" onsubmit="return confirm('선택한 DB 마이그레이션을 실행하시겠습니까? 실행 전 데이터베이스 백업을 권장합니다.');">
<input type="hidden" name="token" value="<?php echo $dbupgrade_token; ?>">
<input type="hidden" name="action" value="migrate">
<button type="submit" name="migration_id" value="" class="btn_submit">전체 마이그레이션 실행</button>
</form>
</div>
<form method="post" action="<?php echo G5_ADMIN_URL; ?>/dbupgrade.php" onsubmit="return confirm('선택한 DB 마이그레이션을 실행하시겠습니까? 실행 전 데이터베이스 백업을 권장합니다.');">
<input type="hidden" name="token" value="<?php echo $dbupgrade_token; ?>">
<input type="hidden" name="action" value="migrate">
<div class="tbl_head01 tbl_wrap">
<table id="dbupgrade_migration_table">
<caption>버전형 DB 마이그레이션 목록</caption>
<thead>
<tr>
<th scope="col" aria-sort="none"><button type="button" class="dbupgrade_sort" data-column="0">마이그레이션 <span aria-hidden="true"></span></button></th>
<th scope="col" class="dbupgrade_description" aria-sort="none"><button type="button" class="dbupgrade_sort" data-column="1">설명 <span aria-hidden="true"></span></button></th>
<th scope="col" aria-sort="none"><button type="button" class="dbupgrade_sort" data-column="2">상태 <span aria-hidden="true"></span></button></th>
<th scope="col" aria-sort="none"><button type="button" class="dbupgrade_sort" data-column="3">적용 시각 <span aria-hidden="true"></span></button></th>
<th scope="col" aria-sort="none"><button type="button" class="dbupgrade_sort" data-column="4">실행 <span aria-hidden="true"></span></button></th>
</tr>
</thead>
<tbody>
<?php $previous_migrations_ready = true; ?>
<?php foreach ($migration_statuses as $migration_status) { ?>
<?php
$current_migration_status = isset($migration_status['status']) ? $migration_status['status'] : 'error';
$migration_succeeded = $current_migration_status === 'success' && !$migration_status['checksum_changed'];
$migration_can_run = in_array($current_migration_status, array('pending', 'failed'), true) && $previous_migrations_ready;
$migration_button_title = $current_migration_status === 'unrecorded' ? '기존 상태 확인 이력을 등록해 주십시오.' : ($current_migration_status === 'success' ? '이미 성공한 마이그레이션입니다.' : ($previous_migrations_ready ? '' : '선행 마이그레이션을 먼저 실행해야 합니다.'));
?>
<tr>
<?php if (isset($migration_status['error'])) { ?>
<td colspan="5"><?php echo htmlspecialchars($migration_status['error'], ENT_QUOTES, 'UTF-8'); ?></td>
<?php } else { ?>
<td><?php echo htmlspecialchars($migration_status['id'], ENT_QUOTES, 'UTF-8'); ?></td>
<td class="dbupgrade_description"><?php echo htmlspecialchars($migration_status['description'], ENT_QUOTES, 'UTF-8'); ?></td>
<td><?php echo g5_migration_status_label($migration_status['status'], $migration_status['checksum_changed']); ?></td>
<td><?php echo htmlspecialchars($migration_status['applied_at'], ENT_QUOTES, 'UTF-8'); ?></td>
<td>
<button type="submit" name="migration_id" value="<?php echo htmlspecialchars($migration_status['id'], ENT_QUOTES, 'UTF-8'); ?>" class="btn_frmline"<?php echo $migration_can_run ? '' : ' disabled'; ?><?php echo $migration_button_title !== '' ? ' title="' . htmlspecialchars($migration_button_title, ENT_QUOTES, 'UTF-8') . '"' : ''; ?>>실행</button>
</td>
<?php } ?>
</tr>
<?php $previous_migrations_ready = $previous_migrations_ready && $migration_succeeded; ?>
<?php } ?>
</tbody>
</table>
</div>
</form>
<style>
.dbupgrade_all_actions {display:flex;width:100%;margin:0 0 20px;justify-content:flex-end;gap:5px}
.dbupgrade_all_actions form {margin:0}
.dbupgrade_all_actions .dbupgrade_existing_action {margin-right:auto}
.dbupgrade_all_actions .btn_submit {display:inline-block;float:none;position:static;width:auto;height:30px;margin:0;padding:0 15px;border:0}
.dbupgrade_sort {width:100%; border:0; background:transparent; color:inherit; font:inherit; cursor:pointer}
#dbupgrade_migration_table td.dbupgrade_description {text-align:left}
#dbupgrade_migration_table th.dbupgrade_description, #dbupgrade_migration_table th.dbupgrade_description .dbupgrade_sort {text-align:center}
.btn_frmline:disabled {background:#b7b7b7;color:#fff;cursor:not-allowed}
</style>
<script>
(function () {
var table = document.getElementById('dbupgrade_migration_table');
if (!table || !table.tBodies.length) {
return;
}
var buttons = table.querySelectorAll('.dbupgrade_sort');
var tbody = table.tBodies[0];
function getCellText(row, column) {
return row.cells[column] ? row.cells[column].textContent.replace(/^\s+|\s+$/g, '') : '';
}
function sortRows(button, initialAscending) {
var column = parseInt(button.getAttribute('data-column'), 10);
var header = button.parentNode;
var ascending = typeof initialAscending === 'boolean' ? initialAscending : header.getAttribute('aria-sort') !== 'ascending';
var rows = Array.prototype.slice.call(tbody.rows);
rows.sort(function (left, right) {
var leftText = getCellText(left, column);
var rightText = getCellText(right, column);
var compared = leftText.localeCompare(rightText, undefined, {numeric: true, sensitivity: 'base'});
return ascending ? compared : -compared;
});
for (var i = 0; i < buttons.length; i++) {
buttons[i].parentNode.setAttribute('aria-sort', 'none');
buttons[i].getElementsByTagName('span')[0].textContent = '';
}
header.setAttribute('aria-sort', ascending ? 'ascending' : 'descending');
button.getElementsByTagName('span')[0].textContent = ascending ? '▲' : '▼';
for (var j = 0; j < rows.length; j++) {
tbody.appendChild(rows[j]);
}
}
for (var i = 0; i < buttons.length; i++) {
buttons[i].onclick = function () {
sortRows(this);
};
}
if (buttons.length) {
sortRows(buttons[0], false);
}
}());
</script>
<?php
include_once ('./admin.tail.php');
include_once('./admin.tail.php');
+4
View File
@@ -30,6 +30,7 @@ if ($w == "")
sql_query($sql);
$fa_id = sql_insert_id();
run_event('admin_faq_item_created', $fa_id, $fm_id);
}
else if ($w == "u")
{
@@ -37,11 +38,14 @@ else if ($w == "u")
set $sql_common
where fa_id = '$fa_id' ";
sql_query($sql);
run_event('admin_faq_item_updated', $fa_id, $fm_id);
}
else if ($w == "d")
{
$sql = " delete from {$g5['faq_table']} where fa_id = '$fa_id' ";
sql_query($sql);
run_event('admin_faq_item_deleted', $fa_id, $fm_id);
}
if ($w == 'd')
+97 -99
View File
@@ -1,99 +1,97 @@
<?php
$sub_menu = '300700';
include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "r");
$g5['title'] = 'FAQ 상세관리';
if (isset($_REQUEST['fm_subject'])){
$fm_subject = clean_xss_tags($_REQUEST['fm_subject'], 1, 1, 255);
$g5['title'] .= ' : '.$fm_subject;
}
$fm_id = (int) $fm_id;
include_once (G5_ADMIN_PATH.'/admin.head.php');
$sql = " select * from {$g5['faq_master_table']} where fm_id = '$fm_id' ";
$fm = sql_fetch($sql);
$sql_common = " from {$g5['faq_table']} where fm_id = '$fm_id' ";
// 테이블의 전체 레코드수만 얻음
$sql = " select count(*) as cnt " . $sql_common;
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql = "select * $sql_common order by fa_order , fa_id ";
$result = sql_query($sql);
?>
<div class="local_ov01 local_ov">
<span class="btn_ov01"><span class="ov_txt"> 등록된 FAQ 상세내용</span><span class="ov_num"> <?php echo $total_count; ?>건</span></span>
</div>
<div class="local_desc01 local_desc">
<ol>
<li>FAQ는 무제한으로 등록할 수 있습니다</li>
<li><strong>FAQ 상세내용 추가</strong>를 눌러 자주하는 질문과 답변을 입력합니다.</li>
</ol>
</div>
<div class="btn_fixed_top">
<a href="./faqmasterlist.php" class="btn btn_02">FAQ 관리</a>
<a href="./faqform.php?fm_id=<?php echo $fm['fm_id']; ?>" class="btn btn_01">FAQ 상세내용 추가</a>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">번호</th>
<th scope="col">제목</th>
<th scope="col">순서</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++)
{
$row1 = sql_fetch(" select COUNT(*) as cnt from {$g5['faq_table']} where fm_id = '{$row['fm_id']}' ");
$cnt = $row1['cnt'];
$s_mod = icon("수정", "");
$s_del = icon("삭제", "");
$num = $i + 1;
$bg = 'bg'.($i%2);
$fa_subject = conv_content($row['fa_subject'], 1);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_num"><?php echo $num; ?></td>
<td class="td_left"><?php echo $fa_subject; ?></td>
<td class="td_num"><?php echo $row['fa_order']; ?></td>
<td class="td_mng td_mng_m">
<a href="./faqform.php?w=u&amp;fm_id=<?php echo $row['fm_id']; ?>&amp;fa_id=<?php echo $row['fa_id']; ?>" class="btn btn_03"><span class="sound_only"><?php echo $fa_subject; ?> </span>수정</a>
<a href="./faqformupdate.php?w=d&amp;fm_id=<?php echo $row['fm_id']; ?>&amp;fa_id=<?php echo $row['fa_id']; ?>" onclick="return delete_confirm(this);" class="btn btn_02"><span class="sound_only"><?php echo $fa_subject; ?> </span>삭제</a>
</td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="4" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<?php
include_once (G5_ADMIN_PATH.'/admin.tail.php');
<?php
$sub_menu = '300700';
require_once './_common.php';
auth_check_menu($auth, $sub_menu, "r");
$g5['title'] = 'FAQ 상세관리';
if (isset($_REQUEST['fm_subject'])) {
$fm_subject = clean_xss_tags($_REQUEST['fm_subject'], 1, 1, 255);
$g5['title'] .= ' : ' . $fm_subject;
}
$fm_id = isset($fm_id) ? (int) $fm_id : 0;
require_once G5_ADMIN_PATH . '/admin.head.php';
$sql = " select * from {$g5['faq_master_table']} where fm_id = '$fm_id' ";
$fm = sql_fetch($sql);
$sql_common = " from {$g5['faq_table']} where fm_id = '$fm_id' ";
// 테이블의 전체 레코드수만 얻음
$sql = " select count(*) as cnt " . $sql_common;
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql = "select * $sql_common order by fa_order , fa_id ";
$result = sql_query($sql);
?>
<div class="local_ov01 local_ov">
<span class="btn_ov01"><span class="ov_txt"> 등록된 FAQ 상세내용</span><span class="ov_num"> <?php echo $total_count; ?>건</span></span>
</div>
<div class="local_desc01 local_desc">
<ol>
<li>FAQ는 무제한으로 등록할 수 있습니다</li>
<li><strong>FAQ 상세내용 추가</strong>를 눌러 자주하는 질문과 답변을 입력합니다.</li>
</ol>
</div>
<div class="btn_fixed_top">
<a href="./faqmasterlist.php" class="btn btn_02">FAQ 관리</a>
<a href="./faqform.php?fm_id=<?php echo $fm['fm_id']; ?>" class="btn btn_01">FAQ 상세내용 추가</a>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">번호</th>
<th scope="col">제목</th>
<th scope="col">순서</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$row1 = sql_fetch(" select COUNT(*) as cnt from {$g5['faq_table']} where fm_id = '{$row['fm_id']}' ");
$cnt = $row1['cnt'];
$s_mod = icon("수정", "");
$s_del = icon("삭제", "");
$num = $i + 1;
$bg = 'bg' . ($i % 2);
$fa_subject = conv_content($row['fa_subject'], 1);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_num"><?php echo $num; ?></td>
<td class="td_left"><?php echo $fa_subject; ?></td>
<td class="td_num"><?php echo $row['fa_order']; ?></td>
<td class="td_mng td_mng_m">
<a href="./faqform.php?w=u&amp;fm_id=<?php echo $row['fm_id']; ?>&amp;fa_id=<?php echo $row['fa_id']; ?>" class="btn btn_03"><span class="sound_only"><?php echo $fa_subject; ?> </span>수정</a>
<a href="./faqformupdate.php?w=d&amp;fm_id=<?php echo $row['fm_id']; ?>&amp;fa_id=<?php echo $row['fa_id']; ?>" onclick="return delete_confirm(this);" class="btn btn_02"><span class="sound_only"><?php echo $fa_subject; ?> </span>삭제</a>
</td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="4" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<?php
require_once G5_ADMIN_PATH . '/admin.tail.php';
+167 -167
View File
@@ -1,167 +1,167 @@
<?php
$sub_menu = '300700';
include_once('./_common.php');
include_once(G5_EDITOR_LIB);
auth_check_menu($auth, $sub_menu, "w");
$html_title = 'FAQ';
$fm_id = isset($_GET['fm_id']) ? preg_replace('/[^0-9]/', '', $_GET['fm_id']) : 0;
if ($w == "u")
{
$html_title .= ' 수정';
$readonly = ' readonly';
$sql = " select * from {$g5['faq_master_table']} where fm_id = '$fm_id' ";
$fm = sql_fetch($sql);
if (!$fm['fm_id']) alert('등록된 자료가 없습니다.');
}
else
{
$html_title .= ' 입력';
$fm = array('fm_order'=>'', 'fm_subject'=>'', 'fm_id'=>0, 'fm_head_html'=> '', 'fm_tail_html'=> '', 'fm_mobile_head_html' => '', 'fm_mobile_tail_html' => '');
}
$g5['title'] = $html_title.' 관리';
// 모바일 상하단 내용 필드추가
if(!sql_query(" select fm_mobile_head_html from {$g5['faq_master_table']} limit 1 ", false)) {
sql_query(" ALTER TABLE `{$g5['faq_master_table']}`
ADD `fm_mobile_head_html` text NOT NULL AFTER `fm_tail_html`,
ADD `fm_mobile_tail_html` text NOT NULL AFTER `fm_mobile_head_html` ", true);
}
include_once (G5_ADMIN_PATH.'/admin.head.php');
?>
<form name="frmfaqmasterform" action="./faqmasterformupdate.php" onsubmit="return frmfaqmasterform_check(this);" method="post" enctype="MULTIPART/FORM-DATA">
<input type="hidden" name="w" value="<?php echo $w; ?>">
<input type="hidden" name="fm_id" value="<?php echo $fm_id; ?>">
<input type="hidden" name="token" value="">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="fm_order">출력순서</label></th>
<td>
<?php echo help('숫자가 작을수록 FAQ 분류에서 먼저 출력됩니다.'); ?>
<input type="text" name="fm_order" value="<?php echo $fm['fm_order']; ?>" id="fm_order" class="frm_input" maxlength="10" size="10">
</td>
</tr>
<tr>
<th scope="row"><label for="fm_subject">제목</label></th>
<td>
<input type="text" value="<?php echo get_text($fm['fm_subject']); ?>" name="fm_subject" id="fm_subject" required class="frm_input required" size="70">
<?php if ($w == 'u') { ?>
<a href="<?php echo G5_BBS_URL; ?>/faq.php?fm_id=<?php echo $fm_id; ?>" class="btn_frmline">보기</a>
<a href="./faqlist.php?fm_id=<?php echo $fm_id; ?>" class="btn_frmline">상세보기</a>
<?php } ?>
</td>
</tr>
<tr>
<th scope="row"><label for="fm_himg">상단이미지</label></th>
<td>
<input type="file" name="fm_himg" id="fm_himg">
<?php
$himg = G5_DATA_PATH.'/faq/'.$fm['fm_id'].'_h';
$himg_str = '';
if (file_exists($himg)) {
$size = @getimagesize($himg);
if($size[0] && $size[0] > 750)
$width = 750;
else
$width = $size[0];
echo '<input type="checkbox" name="fm_himg_del" value="1" id="fm_himg_del"> <label for="fm_himg_del">삭제</label>';
$himg_str = '<img src="'.G5_DATA_URL.'/faq/'.$fm['fm_id'].'_h" width="'.$width.'" alt="">';
}
if ($himg_str) {
echo '<div class="banner_or_img">';
echo $himg_str;
echo '</div>';
}
?>
</td>
</tr>
<tr>
<th scope="row"><label for="fm_timg">하단이미지</label></th>
<td>
<input type="file" name="fm_timg" id="fm_timg">
<?php
$timg = G5_DATA_PATH.'/faq/'.$fm['fm_id'].'_t';
$timg_str = '';
if (file_exists($timg)) {
$size = @getimagesize($timg);
if($size[0] && $size[0] > 750)
$width = 750;
else
$width = $size[0];
echo '<input type="checkbox" name="fm_timg_del" value="1" id="fm_timg_del"><label for="fm_timg_del">삭제</label>';
$timg_str = '<img src="'.G5_DATA_URL.'/faq/'.$fm['fm_id'].'_t" width="'.$width.'" alt="">';
}
if ($timg_str) {
echo '<div class="banner_or_img">';
echo $timg_str;
echo '</div>';
}
?>
</td>
</tr>
<tr>
<th scope="row">상단 내용</th>
<td>
<?php echo editor_html('fm_head_html', get_text(html_purifier($fm['fm_head_html']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row">하단 내용</th>
<td>
<?php echo editor_html('fm_tail_html', get_text(html_purifier($fm['fm_tail_html']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row">모바일상단 내용</th>
<td>
<?php echo editor_html('fm_mobile_head_html', get_text(html_purifier($fm['fm_mobile_head_html']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row">모바일하단 내용</th>
<td>
<?php echo editor_html('fm_mobile_tail_html', get_text(html_purifier($fm['fm_mobile_tail_html']), 0)); ?>
</td>
</tr>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<a href="./faqmasterlist.php" class="btn btn_02">목록</a>
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
</div>
</form>
<script>
function frmfaqmasterform_check(f)
{
<?php echo get_editor_js('fm_head_html'); ?>
<?php echo get_editor_js('fm_tail_html'); ?>
<?php echo get_editor_js('fm_mobile_head_html'); ?>
<?php echo get_editor_js('fm_mobile_tail_html'); ?>
}
// document.frmfaqmasterform.fm_subject.focus();
</script>
<?php
include_once (G5_ADMIN_PATH.'/admin.tail.php');
<?php
$sub_menu = '300700';
require_once './_common.php';
require_once G5_EDITOR_LIB;
auth_check_menu($auth, $sub_menu, "w");
$html_title = 'FAQ';
$fm_id = isset($_GET['fm_id']) ? strval(preg_replace('/[^0-9]/', '', $_GET['fm_id'])) : 0;
if ($w == "u") {
$html_title .= ' 수정';
$readonly = ' readonly';
$sql = " select * from {$g5['faq_master_table']} where fm_id = '$fm_id' ";
$fm = sql_fetch($sql);
if (!$fm['fm_id']) {
alert('등록된 자료가 없습니다.');
}
} else {
$html_title .= ' 입력';
$fm = array('fm_order' => '', 'fm_subject' => '', 'fm_id' => 0, 'fm_head_html' => '', 'fm_tail_html' => '', 'fm_mobile_head_html' => '', 'fm_mobile_tail_html' => '');
}
$g5['title'] = $html_title . ' 관리';
// 모바일 상하단 내용 필드추가
require_once G5_ADMIN_PATH . '/admin.head.php';
?>
<form name="frmfaqmasterform" action="./faqmasterformupdate.php" onsubmit="return frmfaqmasterform_check(this);" method="post" enctype="MULTIPART/FORM-DATA">
<input type="hidden" name="w" value="<?php echo $w; ?>">
<input type="hidden" name="fm_id" value="<?php echo $fm_id; ?>">
<input type="hidden" name="token" value="">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="fm_order">출력순서</label></th>
<td>
<?php echo help('숫자가 작을수록 FAQ 분류에서 먼저 출력됩니다.'); ?>
<input type="text" name="fm_order" value="<?php echo $fm['fm_order']; ?>" id="fm_order" class="frm_input" maxlength="10" size="10">
</td>
</tr>
<tr>
<th scope="row"><label for="fm_subject">제목</label></th>
<td>
<input type="text" value="<?php echo get_text($fm['fm_subject']); ?>" name="fm_subject" id="fm_subject" required class="frm_input required" size="70">
<?php if ($w == 'u') { ?>
<a href="<?php echo G5_BBS_URL; ?>/faq.php?fm_id=<?php echo $fm_id; ?>" class="btn_frmline">보기</a>
<a href="./faqlist.php?fm_id=<?php echo $fm_id; ?>" class="btn_frmline">상세보기</a>
<?php } ?>
</td>
</tr>
<tr>
<th scope="row"><label for="fm_himg">상단이미지</label></th>
<td>
<input type="file" name="fm_himg" id="fm_himg">
<?php
$himg = G5_DATA_PATH . '/faq/' . $fm['fm_id'] . '_h';
$himg_str = '';
$width = 0;
if (file_exists($himg)) {
$size = @getimagesize($himg);
if ($size) {
if ($size[0] && $size[0] > 750) {
$width = 750;
} else {
$width = $size[0];
}
}
echo '<input type="checkbox" name="fm_himg_del" value="1" id="fm_himg_del"> <label for="fm_himg_del">삭제</label>';
$himg_str = '<img src="' . G5_DATA_URL . '/faq/' . $fm['fm_id'] . '_h" width="' . $width . '" alt="">';
}
if ($himg_str) {
echo '<div class="banner_or_img">';
echo $himg_str;
echo '</div>';
}
?>
</td>
</tr>
<tr>
<th scope="row"><label for="fm_timg">하단이미지</label></th>
<td>
<input type="file" name="fm_timg" id="fm_timg">
<?php
$timg = G5_DATA_PATH . '/faq/' . $fm['fm_id'] . '_t';
$timg_str = '';
$width = 0;
if (file_exists($timg)) {
$size = @getimagesize($timg);
if ($size) {
if ($size[0] && $size[0] > 750) {
$width = 750;
} else {
$width = $size[0];
}
}
echo '<input type="checkbox" name="fm_timg_del" value="1" id="fm_timg_del"><label for="fm_timg_del">삭제</label>';
$timg_str = '<img src="' . G5_DATA_URL . '/faq/' . $fm['fm_id'] . '_t" width="' . $width . '" alt="">';
}
if ($timg_str) {
echo '<div class="banner_or_img">';
echo $timg_str;
echo '</div>';
}
?>
</td>
</tr>
<tr>
<th scope="row">상단 내용</th>
<td>
<?php echo editor_html('fm_head_html', get_text(html_purifier($fm['fm_head_html']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row">하단 내용</th>
<td>
<?php echo editor_html('fm_tail_html', get_text(html_purifier($fm['fm_tail_html']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row">모바일상단 내용</th>
<td>
<?php echo editor_html('fm_mobile_head_html', get_text(html_purifier($fm['fm_mobile_head_html']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row">모바일하단 내용</th>
<td>
<?php echo editor_html('fm_mobile_tail_html', get_text(html_purifier($fm['fm_mobile_tail_html']), 0)); ?>
</td>
</tr>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<a href="./faqmasterlist.php" class="btn btn_02">목록</a>
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
</div>
</form>
<script>
function frmfaqmasterform_check(f) {
<?php echo get_editor_js('fm_head_html'); ?>
<?php echo get_editor_js('fm_tail_html'); ?>
<?php echo get_editor_js('fm_mobile_head_html'); ?>
<?php echo get_editor_js('fm_mobile_tail_html'); ?>
}
// document.frmfaqmasterform.fm_subject.focus();
</script>
<?php
require_once G5_ADMIN_PATH . '/admin.tail.php';
+86 -83
View File
@@ -1,83 +1,86 @@
<?php
$sub_menu = '300700';
include_once('./_common.php');
if ($w == "u" || $w == "d")
check_demo();
if ($w == 'd')
auth_check_menu($auth, $sub_menu, "d");
else
auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
@mkdir(G5_DATA_PATH."/faq", G5_DIR_PERMISSION);
@chmod(G5_DATA_PATH."/faq", G5_DIR_PERMISSION);
$fm_id = isset($_REQUEST['fm_id']) ? (int) $_REQUEST['fm_id'] : 0;
$fm_himg_del = isset($_POST['fm_himg_del']) ? (int) $_POST['fm_himg_del'] : 0;
$fm_timg_del = isset($_POST['fm_timg_del']) ? (int) $_POST['fm_timg_del'] : 0;
$fm_subject = isset($_POST['fm_subject']) ? strip_tags(clean_xss_attributes($_POST['fm_subject'])) : '';
$fm_head_html = isset($_POST['fm_head_html']) ? $_POST['fm_head_html'] : '';
$fm_tail_html = isset($_POST['fm_tail_html']) ? $_POST['fm_tail_html'] : '';
$fm_mobile_head_html = isset($_POST['fm_mobile_head_html']) ? $_POST['fm_mobile_head_html'] : '';
$fm_mobile_tail_html = isset($_POST['fm_mobile_tail_html']) ? $_POST['fm_mobile_tail_html'] : '';
$fm_order = isset($_POST['fm_order']) ? (int) $_POST['fm_order'] : 0;
if ($fm_himg_del) @unlink(G5_DATA_PATH."/faq/{$fm_id}_h");
if ($fm_timg_del) @unlink(G5_DATA_PATH."/faq/{$fm_id}_t");
$sql_common = " set fm_subject = '$fm_subject',
fm_head_html = '$fm_head_html',
fm_tail_html = '$fm_tail_html',
fm_mobile_head_html = '$fm_mobile_head_html',
fm_mobile_tail_html = '$fm_mobile_tail_html',
fm_order = '$fm_order' ";
if ($w == "")
{
$sql = " alter table {$g5['faq_master_table']} auto_increment=1 ";
sql_query($sql);
$sql = " insert {$g5['faq_master_table']} $sql_common ";
sql_query($sql);
$fm_id = sql_insert_id();
}
else if ($w == "u")
{
$sql = " update {$g5['faq_master_table']} $sql_common where fm_id = '$fm_id' ";
sql_query($sql);
}
else if ($w == "d")
{
@unlink(G5_DATA_PATH."/faq/{$fm_id}_h");
@unlink(G5_DATA_PATH."/faq/{$fm_id}_t");
// FAQ삭제
$sql = " delete from {$g5['faq_master_table']} where fm_id = '$fm_id' ";
sql_query($sql);
// FAQ상세삭제
$sql = " delete from {$g5['faq_table']} where fm_id = '$fm_id' ";
sql_query($sql);
}
if ($w == "" || $w == "u")
{
if ($_FILES['fm_himg']['name']){
$dest_path = G5_DATA_PATH."/faq/".$fm_id."_h";
@move_uploaded_file($_FILES['fm_himg']['tmp_name'], $dest_path);
@chmod($dest_path, G5_FILE_PERMISSION);
}
if ($_FILES['fm_timg']['name']){
$dest_path = G5_DATA_PATH."/faq/".$fm_id."_t";
@move_uploaded_file($_FILES['fm_timg']['tmp_name'], $dest_path);
@chmod($dest_path, G5_FILE_PERMISSION);
}
goto_url("./faqmasterform.php?w=u&amp;fm_id=$fm_id");
}
else
goto_url("./faqmasterlist.php");
<?php
$sub_menu = '300700';
require_once './_common.php';
if ($w == "u" || $w == "d") {
check_demo();
}
if ($w == 'd') {
auth_check_menu($auth, $sub_menu, "d");
} else {
auth_check_menu($auth, $sub_menu, "w");
}
check_admin_token();
@mkdir(G5_DATA_PATH . "/faq", G5_DIR_PERMISSION);
@chmod(G5_DATA_PATH . "/faq", G5_DIR_PERMISSION);
$fm_id = isset($_REQUEST['fm_id']) ? (int) $_REQUEST['fm_id'] : 0;
$fm_himg_del = isset($_POST['fm_himg_del']) ? (int) $_POST['fm_himg_del'] : 0;
$fm_timg_del = isset($_POST['fm_timg_del']) ? (int) $_POST['fm_timg_del'] : 0;
$fm_subject = isset($_POST['fm_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['fm_subject'])))) : '';
$fm_head_html = isset($_POST['fm_head_html']) ? $_POST['fm_head_html'] : '';
$fm_tail_html = isset($_POST['fm_tail_html']) ? $_POST['fm_tail_html'] : '';
$fm_mobile_head_html = isset($_POST['fm_mobile_head_html']) ? $_POST['fm_mobile_head_html'] : '';
$fm_mobile_tail_html = isset($_POST['fm_mobile_tail_html']) ? $_POST['fm_mobile_tail_html'] : '';
$fm_order = isset($_POST['fm_order']) ? (int) $_POST['fm_order'] : 0;
if ($fm_himg_del) {
@unlink(G5_DATA_PATH . "/faq/{$fm_id}_h");
}
if ($fm_timg_del) {
@unlink(G5_DATA_PATH . "/faq/{$fm_id}_t");
}
$sql_common = " set fm_subject = '$fm_subject',
fm_head_html = '$fm_head_html',
fm_tail_html = '$fm_tail_html',
fm_mobile_head_html = '$fm_mobile_head_html',
fm_mobile_tail_html = '$fm_mobile_tail_html',
fm_order = '$fm_order' ";
if ($w == "") {
$sql = " insert {$g5['faq_master_table']} $sql_common ";
sql_query($sql);
$fm_id = sql_insert_id();
run_event('admin_faq_master_created', $fm_id);
} elseif ($w == "u") {
$sql = " update {$g5['faq_master_table']} $sql_common where fm_id = '$fm_id' ";
sql_query($sql);
run_event('admin_faq_master_updated', $fm_id);
} elseif ($w == "d") {
@unlink(G5_DATA_PATH . "/faq/{$fm_id}_h");
@unlink(G5_DATA_PATH . "/faq/{$fm_id}_t");
// FAQ삭제
$sql = " delete from {$g5['faq_master_table']} where fm_id = '$fm_id' ";
sql_query($sql);
// FAQ상세삭제
$sql = " delete from {$g5['faq_table']} where fm_id = '$fm_id' ";
sql_query($sql);
run_event('admin_faq_master_deleted', $fm_id);
}
if ($w == "" || $w == "u") {
if ($_FILES['fm_himg']['name']) {
$dest_path = G5_DATA_PATH . "/faq/" . $fm_id . "_h";
@move_uploaded_file($_FILES['fm_himg']['tmp_name'], $dest_path);
@chmod($dest_path, G5_FILE_PERMISSION);
}
if ($_FILES['fm_timg']['name']) {
$dest_path = G5_DATA_PATH . "/faq/" . $fm_id . "_t";
@move_uploaded_file($_FILES['fm_timg']['tmp_name'], $dest_path);
@chmod($dest_path, G5_FILE_PERMISSION);
}
goto_url("./faqmasterform.php?w=u&amp;fm_id=$fm_id");
} else {
goto_url("./faqmasterlist.php");
}
+100 -127
View File
@@ -1,127 +1,100 @@
<?php
$sub_menu = '300700';
include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "r");
//dbconfig파일에 $g5['faq_table'] , $g5['faq_master_table'] 배열변수가 있는지 체크
if( !isset($g5['faq_table']) || !isset($g5['faq_master_table']) ){
die('<meta charset="utf-8">/data/dbconfig.php 파일에 <br ><strong>$g5[\'faq_table\'] = G5_TABLE_PREFIX.\'faq\';</strong><br ><strong>$g5[\'faq_master_table\'] = G5_TABLE_PREFIX.\'faq_master\';</strong><br > 를 추가해 주세요.');
}
//자주하시는 질문 마스터 테이블이 있는지 검사한다.
if(!sql_query(" DESCRIBE {$g5['faq_master_table']} ", false)) {
if(sql_query(" DESCRIBE {$g5['g5_shop_faq_master_table']} ", false)) {
sql_query(" ALTER TABLE {$g5['g5_shop_faq_master_table']} RENAME TO `{$g5['faq_master_table']}` ;", false);
} else {
$query_cp = sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['faq_master_table']}` (
`fm_id` int(11) NOT NULL AUTO_INCREMENT,
`fm_subject` varchar(255) NOT NULL DEFAULT '',
`fm_head_html` text NOT NULL,
`fm_tail_html` text NOT NULL,
`fm_order` int(11) NOT NULL DEFAULT '0',
PRIMARY KEY (`fm_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8 ", true);
}
// FAQ Master
sql_query(" insert into `{$g5['faq_master_table']}` set fm_id = '1', fm_subject = '자주하시는 질문' ", false);
}
//자주하시는 질문 테이블이 있는지 검사한다.
if(!sql_query(" DESCRIBE {$g5['faq_table']} ", false)) {
if(sql_query(" DESCRIBE {$g5['g5_shop_faq_table']} ", false)) {
sql_query(" ALTER TABLE {$g5['g5_shop_faq_table']} RENAME TO `{$g5['faq_table']}` ;", false);
} else {
$query_cp = sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['faq_table']}` (
`fa_id` int(11) NOT NULL AUTO_INCREMENT,
`fm_id` int(11) NOT NULL DEFAULT '0',
`fa_subject` text NOT NULL,
`fa_content` text NOT NULL,
`fa_order` int(11) NOT NULL DEFAULT '0',
PRIMARY KEY (`fa_id`),
KEY `fm_id` (`fm_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8 ", true);
}
}
$g5['title'] = 'FAQ관리';
include_once (G5_ADMIN_PATH.'/admin.head.php');
$sql_common = " from {$g5['faq_master_table']} ";
// 테이블의 전체 레코드수만 얻음
$sql = " select count(*) as cnt " . $sql_common;
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) { $page = 1; } // 페이지가 없으면 첫 페이지 (1 페이지)
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = "select * $sql_common order by fm_order, fm_id limit $from_record, {$config['cf_page_rows']} ";
$result = sql_query($sql);
?>
<div class="local_ov01 local_ov">
<?php if ($page > 1) {?><a href="<?php echo $_SERVER['SCRIPT_NAME']; ?>">처음으로</a><?php } ?>
<span class="btn_ov01"><span class="ov_txt"> 전체 FAQ </span><span class="ov_num"> <?php echo $total_count; ?>건</span></span>
</div>
<div class="local_desc01 local_desc">
<ol>
<li>FAQ는 무제한으로 등록할 수 있습니다</li>
<li><strong>FAQ추가</strong>를 눌러 FAQ Master를 생성합니다. (하나의 FAQ 타이틀 생성 : 자주하시는 질문, 이용안내..등 )</li>
<li>생성한 FAQ Master 의 <strong>제목</strong>을 눌러 세부 내용을 관리할 수 있습니다.</li>
</ol>
</div>
<div class="btn_fixed_top">
<a href="./faqmasterform.php" class="btn_01 btn">FAQ추가</a>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">ID</th>
<th scope="col">제목</th>
<th scope="col">FAQ수</th>
<th scope="col">순서</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php for ($i=0; $row=sql_fetch_array($result); $i++) {
$sql1 = " select COUNT(*) as cnt from {$g5['faq_table']} where fm_id = '{$row['fm_id']}' ";
$row1 = sql_fetch($sql1);
$cnt = $row1['cnt'];
$bg = 'bg'.($i%2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_num"><?php echo $row['fm_id']; ?></td>
<td class="td_left"><a href="./faqlist.php?fm_id=<?php echo $row['fm_id']; ?>&amp;fm_subject=<?php echo $row['fm_subject']; ?>"><?php echo stripslashes($row['fm_subject']); ?></a></td>
<td class="td_num"><?php echo $cnt; ?></td>
<td class="td_num"><?php echo $row['fm_order']?></td>
<td class="td_mng td_mng_l">
<a href="./faqmasterform.php?w=u&amp;fm_id=<?php echo $row['fm_id']; ?>" class="btn btn_03"><span class="sound_only"><?php echo stripslashes($row['fm_subject']); ?> </span>수정</a>
<a href="<?php echo G5_BBS_URL; ?>/faq.php?fm_id=<?php echo $row['fm_id']; ?>" class="btn btn_02"><span class="sound_only"><?php echo stripslashes($row['fm_subject']); ?> </span>보기</a>
<a href="./faqmasterformupdate.php?w=d&amp;fm_id=<?php echo $row['fm_id']; ?>" onclick="return delete_confirm(this);" class="btn btn_02"><span class="sound_only"><?php echo stripslashes($row['fm_subject']); ?> </span>삭제</a>
</td>
</tr>
<?php
}
if ($i == 0){
echo '<tr><td colspan="5" class="empty_table"><span>자료가 한건도 없습니다.</span></td></tr>';
}
?>
</tbody>
</table>
</div>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page="); ?>
<?php
include_once (G5_ADMIN_PATH.'/admin.tail.php');
<?php
$sub_menu = '300700';
require_once './_common.php';
auth_check_menu($auth, $sub_menu, "r");
//dbconfig파일에 $g5['faq_table'] , $g5['faq_master_table'] 배열변수가 있는지 체크
if (!isset($g5['faq_table']) || !isset($g5['faq_master_table'])) {
die('<meta charset="utf-8">/data/dbconfig.php 파일에 <br ><strong>$g5[\'faq_table\'] = G5_TABLE_PREFIX.\'faq\';</strong><br ><strong>$g5[\'faq_master_table\'] = G5_TABLE_PREFIX.\'faq_master\';</strong><br > 를 추가해 주세요.');
}
//자주하시는 질문 마스터 테이블이 있는지 검사한다.
//자주하시는 질문 테이블이 있는지 검사한다.
$g5['title'] = 'FAQ관리';
require_once G5_ADMIN_PATH . '/admin.head.php';
$sql_common = " from {$g5['faq_master_table']} ";
// 테이블의 전체 레코드수만 얻음
$sql = " select count(*) as cnt " . $sql_common;
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) {
$page = 1;
} // 페이지가 없으면 첫 페이지 (1 페이지)
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = "select * $sql_common order by fm_order, fm_id limit $from_record, {$config['cf_page_rows']} ";
$result = sql_query($sql);
?>
<div class="local_ov01 local_ov">
<?php if ($page > 1) { ?>
<a href="<?php echo $_SERVER['SCRIPT_NAME']; ?>">처음으로</a>
<?php } ?>
<span class="btn_ov01"><span class="ov_txt"> 전체 FAQ </span><span class="ov_num"> <?php echo $total_count; ?>건</span></span>
</div>
<div class="local_desc01 local_desc">
<ol>
<li>FAQ는 무제한으로 등록할 수 있습니다</li>
<li><strong>FAQ추가</strong>를 눌러 FAQ Master를 생성합니다. (하나의 FAQ 타이틀 생성 : 자주하시는 질문, 이용안내..등 )</li>
<li>생성한 FAQ Master 의 <strong>제목</strong>을 눌러 세부 내용을 관리할 수 있습니다.</li>
</ol>
</div>
<div class="btn_fixed_top">
<a href="./faqmasterform.php" class="btn_01 btn">FAQ추가</a>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">ID</th>
<th scope="col">제목</th>
<th scope="col">FAQ수</th>
<th scope="col">순서</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php for ($i = 0; $row = sql_fetch_array($result); $i++) {
$sql1 = " select COUNT(*) as cnt from {$g5['faq_table']} where fm_id = '{$row['fm_id']}' ";
$row1 = sql_fetch($sql1);
$cnt = $row1['cnt'];
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_num"><?php echo $row['fm_id']; ?></td>
<td class="td_left"><a href="./faqlist.php?fm_id=<?php echo $row['fm_id']; ?>&amp;fm_subject=<?php echo $row['fm_subject']; ?>"><?php echo stripslashes($row['fm_subject']); ?></a></td>
<td class="td_num"><?php echo $cnt; ?></td>
<td class="td_num"><?php echo $row['fm_order'] ?></td>
<td class="td_mng td_mng_l">
<a href="./faqmasterform.php?w=u&amp;fm_id=<?php echo $row['fm_id']; ?>" class="btn btn_03"><span class="sound_only"><?php echo stripslashes($row['fm_subject']); ?> </span>수정</a>
<a href="<?php echo G5_BBS_URL; ?>/faq.php?fm_id=<?php echo $row['fm_id']; ?>" class="btn btn_02"><span class="sound_only"><?php echo stripslashes($row['fm_subject']); ?> </span>보기</a>
<a href="./faqmasterformupdate.php?w=d&amp;fm_id=<?php echo $row['fm_id']; ?>" onclick="return delete_confirm(this);" class="btn btn_02"><span class="sound_only"><?php echo stripslashes($row['fm_subject']); ?> </span>삭제</a>
</td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="5" class="empty_table"><span>자료가 한건도 없습니다.</span></td></tr>';
}
?>
</tbody>
</table>
</div>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page="); ?>
<?php
require_once G5_ADMIN_PATH . '/admin.tail.php';
Binary file not shown.

After

Width:  |  Height:  |  Size: 4.7 KiB

+318 -283
View File
@@ -1,312 +1,347 @@
<?php
$sub_menu = '100000';
include_once('./_common.php');
require_once './_common.php';
@include_once('./safe_check.php');
if(function_exists('social_log_file_delete')){
social_log_file_delete(86400); //소셜로그인 디버그 파일 24시간 지난것은 삭제
@require_once './safe_check.php';
if (function_exists('social_log_file_delete')) {
//소셜로그인 디버그 파일 24시간 지난것은 삭제
social_log_file_delete(86400);
}
$g5['title'] = '관리자메인';
include_once ('./admin.head.php');
require_once './admin.head.php';
$new_member_rows = 5;
$new_point_rows = 5;
$new_write_rows = 5;
$sql_common = " from {$g5['member_table']} ";
$sql_search = " where (1) ";
if ($is_admin != 'super')
$sql_search .= " and mb_level <= '{$member['mb_level']}' ";
if (!$sst) {
$sst = "mb_datetime";
$sod = "desc";
$addtional_content_before = run_replace('adm_index_addtional_content_before', '', $is_admin, $auth, $member);
if ($addtional_content_before) {
echo $addtional_content_before;
}
$sql_order = " order by {$sst} {$sod} ";
if (!auth_check_menu($auth, '200100', 'r', true)) {
$sql_common = " from {$g5['member_table']} ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql_search = " where (1) ";
// 탈퇴회원수
$sql = " select count(*) as cnt {$sql_common} {$sql_search} and mb_leave_date <> '' {$sql_order} ";
$row = sql_fetch($sql);
$leave_count = $row['cnt'];
if ($is_admin != 'super') {
$sql_search .= " and mb_level <= '{$member['mb_level']}' ";
}
// 차단회원수
$sql = " select count(*) as cnt {$sql_common} {$sql_search} and mb_intercept_date <> '' {$sql_order} ";
$row = sql_fetch($sql);
$intercept_count = $row['cnt'];
if (!$sst) {
$sst = "mb_datetime";
$sod = "desc";
}
$sql = " select * {$sql_common} {$sql_search} {$sql_order} limit {$new_member_rows} ";
$result = sql_query($sql);
$allowed_sst = array('mb_datetime');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'mb_datetime';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$colspan = 12;
?>
$sql_order = " order by {$sst} {$sod} ";
<section>
<h2>신규가입회원 <?php echo $new_member_rows ?>건 목록</h2>
<div class="local_desc02 local_desc">
총회원수 <?php echo number_format($total_count) ?>명 중 차단 <?php echo number_format($intercept_count) ?>명, 탈퇴 : <?php echo number_format($leave_count) ?>명
</div>
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
<div class="tbl_head01 tbl_wrap">
<table>
<caption>신규가입회원</caption>
<thead>
<tr>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">권한</th>
<th scope="col">포인트</th>
<th scope="col">수신</th>
<th scope="col">공개</th>
<th scope="col">인증</th>
<th scope="col">차단</th>
<th scope="col">그룹</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++)
{
// 접근가능한 그룹수
$sql2 = " select count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
$group = "";
if ($row2['cnt'])
$group = '<a href="./boardgroupmember_form.php?mb_id='.$row['mb_id'].'">'.$row2['cnt'].'</a>';
// 탈퇴회원수
$sql = " select count(*) as cnt {$sql_common} {$sql_search} and mb_leave_date <> '' {$sql_order} ";
$row = sql_fetch($sql);
$leave_count = $row['cnt'];
if ($is_admin == 'group')
{
$s_mod = '';
$s_del = '';
}
else
{
$s_mod = '<a href="./member_form.php?$qstr&amp;w=u&amp;mb_id='.$row['mb_id'].'">수정</a>';
$s_del = '<a href="./member_delete.php?'.$qstr.'&amp;w=d&amp;mb_id='.$row['mb_id'].'&amp;url='.$_SERVER['SCRIPT_NAME'].'" onclick="return delete_confirm(this);">삭제</a>';
}
$s_grp = '<a href="./boardgroupmember_form.php?mb_id='.$row['mb_id'].'">그룹</a>';
// 차단회원수
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} and mb_intercept_date <> '' {$sql_order} ";
$row = sql_fetch($sql);
$intercept_count = $row['cnt'];
$leave_date = $row['mb_leave_date'] ? $row['mb_leave_date'] : date("Ymd", G5_SERVER_TIME);
$intercept_date = $row['mb_intercept_date'] ? $row['mb_intercept_date'] : date("Ymd", G5_SERVER_TIME);
$sql = " SELECT * {$sql_common} {$sql_search} {$sql_order} limit {$new_member_rows} ";
$result = sql_query($sql);
$mb_nick = get_sideview($row['mb_id'], get_text($row['mb_nick']), $row['mb_email'], $row['mb_homepage']);
$colspan = 12;
?>
$mb_id = $row['mb_id'];
?>
<tr>
<td class="td_mbid"><?php echo $mb_id ?></td>
<td class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td class="td_mbname sv_use"><div><?php echo $mb_nick ?></div></td>
<td class="td_num"><?php echo $row['mb_level'] ?></td>
<td><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo number_format($row['mb_point']) ?></a></td>
<td class="td_boolean"><?php echo $row['mb_mailling']?'예':'아니오'; ?></td>
<td class="td_boolean"><?php echo $row['mb_open']?'예':'아니오'; ?></td>
<td class="td_boolean"><?php echo preg_match('/[1-9]/', $row['mb_email_certify'])?'예':'아니오'; ?></td>
<td class="td_boolean"><?php echo $row['mb_intercept_date']?'예':'아니오'; ?></td>
<td class="td_category"><?php echo $group ?></td>
</tr>
<?php
}
if ($i == 0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
<section>
<h2>신규가입회원 <?php echo $new_member_rows ?>건 목록</h2>
<div class="local_desc02 local_desc">
총회원수 <?php echo number_format($total_count) ?>명 중 차단 <?php echo number_format($intercept_count) ?>명, 탈퇴 : <?php echo number_format($leave_count) ?>명
</div>
<div class="btn_list03 btn_list">
<a href="./member_list.php">회원 전체보기</a>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>신규가입회원</caption>
<thead>
<tr>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">권한</th>
<th scope="col">포인트</th>
<th scope="col">수신</th>
<th scope="col">공개</th>
<th scope="col">인증</th>
<th scope="col">차단</th>
<th scope="col">그룹</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
// 접근가능한 그룹수
$sql2 = " SELECT count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
$group = "";
if ($row2['cnt']) {
$group = '<a href="./boardgroupmember_form.php?mb_id=' . $row['mb_id'] . '">' . $row2['cnt'] . '</a>';
}
</section>
if ($is_admin == 'group') {
$s_mod = '';
$s_del = '';
} else {
$s_mod = '<a href="./member_form.php?$qstr&amp;w=u&amp;mb_id=' . $row['mb_id'] . '">수정</a>';
$s_del = '<a href="./member_delete.php?' . $qstr . '&amp;w=d&amp;mb_id=' . $row['mb_id'] . '&amp;url=' . $_SERVER['SCRIPT_NAME'] . '" onclick="return delete_confirm(this);">삭제</a>';
}
$s_grp = '<a href="./boardgroupmember_form.php?mb_id=' . $row['mb_id'] . '">그룹</a>';
<?php
$sql_common = " from {$g5['board_new_table']} a, {$g5['board_table']} b, {$g5['group_table']} c where a.bo_table = b.bo_table and b.gr_id = c.gr_id ";
$leave_date = $row['mb_leave_date'] ? $row['mb_leave_date'] : date("Ymd", G5_SERVER_TIME);
$intercept_date = $row['mb_intercept_date'] ? $row['mb_intercept_date'] : date("Ymd", G5_SERVER_TIME);
if ($gr_id)
$sql_common .= " and b.gr_id = '$gr_id' ";
if (isset($view) && $view) {
if ($view == 'w')
$sql_common .= " and a.wr_id = a.wr_parent ";
else if ($view == 'c')
$sql_common .= " and a.wr_id <> a.wr_parent ";
$mb_nick = get_sideview($row['mb_id'], get_text($row['mb_nick']), $row['mb_email'], $row['mb_homepage']);
$mb_id = $row['mb_id'];
?>
<tr>
<td class="td_mbid"><?php echo $mb_id ?></td>
<td class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td class="td_mbname sv_use">
<div><?php echo $mb_nick ?></div>
</td>
<td class="td_num"><?php echo $row['mb_level'] ?></td>
<td><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo number_format($row['mb_point']) ?></a></td>
<td class="td_boolean"><?php echo $row['mb_mailling'] ? '예' : '아니오'; ?></td>
<td class="td_boolean"><?php echo $row['mb_open'] ? '예' : '아니오'; ?></td>
<td class="td_boolean"><?php echo preg_match('/[1-9]/', $row['mb_email_certify']) ? '예' : '아니오'; ?></td>
<td class="td_boolean"><?php echo $row['mb_intercept_date'] ? '예' : '아니오'; ?></td>
<td class="td_category"><?php echo $group ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="./member_list.php">회원 전체보기</a>
</div>
</section>
<?php
} //endif 최신 회원
if (!auth_check_menu($auth, '300100', 'r', true)) {
$sql_common = " from {$g5['board_new_table']} a, {$g5['board_table']} b, {$g5['group_table']} c where a.bo_table = b.bo_table and b.gr_id = c.gr_id ";
if ($gr_id) {
$sql_common .= " and b.gr_id = '{$gr_id}' ";
}
if (isset($view) && $view) {
if ($view == 'w') {
$sql_common .= " and a.wr_id = a.wr_parent ";
} elseif ($view == 'c') {
$sql_common .= " and a.wr_id <> a.wr_parent ";
}
}
$sql_order = " order by a.bn_id desc ";
$sql = " SELECT count(*) as cnt {$sql_common} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$colspan = 5;
?>
<section>
<h2>최근게시물</h2>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>최근게시물</caption>
<thead>
<tr>
<th scope="col">그룹</th>
<th scope="col">게시판</th>
<th scope="col">제목</th>
<th scope="col">이름</th>
<th scope="col">일시</th>
</tr>
</thead>
<tbody>
<?php
$sql = " SELECT a.*, b.bo_subject, c.gr_subject, c.gr_id {$sql_common} {$sql_order} limit {$new_write_rows} ";
$result = sql_query($sql);
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$tmp_write_table = $g5['write_prefix'] . $row['bo_table'];
if ($row['wr_id'] == $row['wr_parent']) {
// 원글
$comment = "";
$comment_link = "";
$row2 = sql_fetch(" SELECT * from {$tmp_write_table} where wr_id = '{$row['wr_id']}' ");
$name = get_sideview($row2['mb_id'], get_text(cut_str($row2['wr_name'], $config['cf_cut_name'])), $row2['wr_email'], $row2['wr_homepage']);
// 당일인 경우 시간으로 표시함
$datetime = substr($row2['wr_datetime'], 0, 10);
$datetime2 = $row2['wr_datetime'];
if ($datetime == G5_TIME_YMD) {
$datetime2 = substr($datetime2, 11, 5);
} else {
$datetime2 = substr($datetime2, 5, 5);
}
} else {
// 코멘트
$comment = '댓글. ';
$comment_link = '#c_' . $row['wr_id'];
$row2 = sql_fetch(" SELECT * from {$tmp_write_table} where wr_id = '{$row['wr_parent']}' ");
$row3 = sql_fetch(" SELECT mb_id, wr_name, wr_email, wr_homepage, wr_datetime from {$tmp_write_table} where wr_id = '{$row['wr_id']}' ");
$name = get_sideview($row3['mb_id'], get_text(cut_str($row3['wr_name'], $config['cf_cut_name'])), $row3['wr_email'], $row3['wr_homepage']);
// 당일인 경우 시간으로 표시함
$datetime = substr($row3['wr_datetime'], 0, 10);
$datetime2 = $row3['wr_datetime'];
if ($datetime == G5_TIME_YMD) {
$datetime2 = substr($datetime2, 11, 5);
} else {
$datetime2 = substr($datetime2, 5, 5);
}
}
?>
<tr>
<td class="td_category"><a href="<?php echo G5_BBS_URL ?>/new.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo cut_str($row['gr_subject'], 10) ?></a></td>
<td class="td_category"><a href="<?php echo get_pretty_url($row['bo_table']) ?>"><?php echo cut_str($row['bo_subject'], 20) ?></a></td>
<td><a href="<?php echo get_pretty_url($row['bo_table'], $row2['wr_id']); ?><?php echo $comment_link ?>"><?php echo $comment ?><?php echo conv_subject($row2['wr_subject'], 100) ?></a></td>
<td class="td_mbname">
<div><?php echo $name ?></div>
</td>
<td class="td_datetime"><?php echo $datetime ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="<?php echo G5_BBS_URL ?>/new.php">최근게시물 더보기</a>
</div>
</section>
<?php
} //endif 최근게시물
if (!auth_check_menu($auth, '200200', 'r', true)) {
$sql_common = " from {$g5['point_table']} ";
$sql_search = " where (1) ";
$sql_order = " order by po_id desc ";
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql = " SELECT * {$sql_common} {$sql_search} {$sql_order} limit {$new_point_rows} ";
$result = sql_query($sql);
$colspan = 7;
?>
<section>
<h2>최근 포인트 발생내역</h2>
<div class="local_desc02 local_desc">
전체 <?php echo number_format($total_count) ?> 건 중 <?php echo $new_point_rows ?>건 목록
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>최근 포인트 발생내역</caption>
<thead>
<tr>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">일시</th>
<th scope="col">포인트 내용</th>
<th scope="col">포인트</th>
<th scope="col">포인트합</th>
</tr>
</thead>
<tbody>
<?php
$row2 = array('mb_id'=>'');
for ($i = 0; $row = sql_fetch_array($result); $i++) {
if (empty($row2) || $row2['mb_id'] != $row['mb_id']) {
$sql2 = " SELECT mb_id, mb_name, mb_nick, mb_email, mb_homepage, mb_point from {$g5['member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
}
$mb_nick = get_sideview(
$row['mb_id'],
isset($row2['mb_nick']) ? $row2['mb_nick'] : '',
isset($row2['mb_email']) ? $row2['mb_email'] : '',
isset($row2['mb_homepage']) ? $row2['mb_homepage'] : ''
);
$link1 = $link2 = "";
if (!preg_match("/^\@/", $row['po_rel_table']) && $row['po_rel_table']) {
$link1 = '<a href="' . get_pretty_url($row['po_rel_table'], $row['po_rel_id']) . '" target="_blank">';
$link2 = '</a>';
}
?>
<tr>
<td class="td_mbid"><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
<td class="td_mbname"><?php echo isset($row2['mb_name']) ? get_text($row2['mb_name']) : ''; ?></td>
<td class="td_name sv_use">
<div><?php echo $mb_nick ?></div>
</td>
<td class="td_datetime"><?php echo $row['po_datetime'] ?></td>
<td><?php echo $link1 . $row['po_content'] . $link2 ?></td>
<td class="td_numbig"><?php echo number_format($row['po_point']) ?></td>
<td class="td_numbig"><?php echo number_format($row['po_mb_point']) ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="./point_list.php">포인트내역 전체보기</a>
</div>
</section>
<?php
} //endif
$addtional_content_after = run_replace('adm_index_addtional_content_after', '', $is_admin, $auth, $member);
if ($addtional_content_after) {
echo $addtional_content_after;
}
$sql_order = " order by a.bn_id desc ";
$sql = " select count(*) as cnt {$sql_common} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$colspan = 5;
?>
<section>
<h2>최근게시물</h2>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>최근게시물</caption>
<thead>
<tr>
<th scope="col">그룹</th>
<th scope="col">게시판</th>
<th scope="col">제목</th>
<th scope="col">이름</th>
<th scope="col">일시</th>
</tr>
</thead>
<tbody>
<?php
$sql = " select a.*, b.bo_subject, c.gr_subject, c.gr_id {$sql_common} {$sql_order} limit {$new_write_rows} ";
$result = sql_query($sql);
for ($i=0; $row=sql_fetch_array($result); $i++)
{
$tmp_write_table = $g5['write_prefix'] . $row['bo_table'];
if ($row['wr_id'] == $row['wr_parent']) // 원글
{
$comment = "";
$comment_link = "";
$row2 = sql_fetch(" select * from $tmp_write_table where wr_id = '{$row['wr_id']}' ");
$name = get_sideview($row2['mb_id'], get_text(cut_str($row2['wr_name'], $config['cf_cut_name'])), $row2['wr_email'], $row2['wr_homepage']);
// 당일인 경우 시간으로 표시함
$datetime = substr($row2['wr_datetime'],0,10);
$datetime2 = $row2['wr_datetime'];
if ($datetime == G5_TIME_YMD)
$datetime2 = substr($datetime2,11,5);
else
$datetime2 = substr($datetime2,5,5);
}
else // 코멘트
{
$comment = '댓글. ';
$comment_link = '#c_'.$row['wr_id'];
$row2 = sql_fetch(" select * from {$tmp_write_table} where wr_id = '{$row['wr_parent']}' ");
$row3 = sql_fetch(" select mb_id, wr_name, wr_email, wr_homepage, wr_datetime from {$tmp_write_table} where wr_id = '{$row['wr_id']}' ");
$name = get_sideview($row3['mb_id'], get_text(cut_str($row3['wr_name'], $config['cf_cut_name'])), $row3['wr_email'], $row3['wr_homepage']);
// 당일인 경우 시간으로 표시함
$datetime = substr($row3['wr_datetime'],0,10);
$datetime2 = $row3['wr_datetime'];
if ($datetime == G5_TIME_YMD)
$datetime2 = substr($datetime2,11,5);
else
$datetime2 = substr($datetime2,5,5);
}
?>
<tr>
<td class="td_category"><a href="<?php echo G5_BBS_URL ?>/new.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo cut_str($row['gr_subject'],10) ?></a></td>
<td class="td_category"><a href="<?php echo get_pretty_url($row['bo_table']) ?>"><?php echo cut_str($row['bo_subject'],20) ?></a></td>
<td><a href="<?php echo get_pretty_url($row['bo_table'], $row2['wr_id']); ?><?php echo $comment_link ?>"><?php echo $comment ?><?php echo conv_subject($row2['wr_subject'], 100) ?></a></td>
<td class="td_mbname"><div><?php echo $name ?></div></td>
<td class="td_datetime"><?php echo $datetime ?></td>
</tr>
<?php
}
if ($i == 0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="<?php echo G5_BBS_URL ?>/new.php">최근게시물 더보기</a>
</div>
</section>
<?php
$sql_common = " from {$g5['point_table']} ";
$sql_search = " where (1) ";
$sql_order = " order by po_id desc ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql = " select * {$sql_common} {$sql_search} {$sql_order} limit {$new_point_rows} ";
$result = sql_query($sql);
$colspan = 7;
?>
<section>
<h2>최근 포인트 발생내역</h2>
<div class="local_desc02 local_desc">
전체 <?php echo number_format($total_count) ?> 건 중 <?php echo $new_point_rows ?>건 목록
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>최근 포인트 발생내역</caption>
<thead>
<tr>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">일시</th>
<th scope="col">포인트 내용</th>
<th scope="col">포인트</th>
<th scope="col">포인트합</th>
</tr>
</thead>
<tbody>
<?php
$row2['mb_id'] = '';
for ($i=0; $row=sql_fetch_array($result); $i++)
{
if ($row2['mb_id'] != $row['mb_id'])
{
$sql2 = " select mb_id, mb_name, mb_nick, mb_email, mb_homepage, mb_point from {$g5['member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
}
$mb_nick = get_sideview($row['mb_id'], $row2['mb_nick'], $row2['mb_email'], $row2['mb_homepage']);
$link1 = $link2 = "";
if (!preg_match("/^\@/", $row['po_rel_table']) && $row['po_rel_table'])
{
$link1 = '<a href="'.get_pretty_url($row['po_rel_table'], $row['po_rel_id']).'" target="_blank">';
$link2 = '</a>';
}
?>
<tr>
<td class="td_mbid"><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
<td class="td_mbname"><?php echo get_text($row2['mb_name']); ?></td>
<td class="td_name sv_use"><div><?php echo $mb_nick ?></div></td>
<td class="td_datetime"><?php echo $row['po_datetime'] ?></td>
<td><?php echo $link1.$row['po_content'].$link2 ?></td>
<td class="td_numbig"><?php echo number_format($row['po_point']) ?></td>
<td class="td_numbig"><?php echo number_format($row['po_mb_point']) ?></td>
</tr>
<?php
}
if ($i == 0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="./point_list.php">포인트내역 전체보기</a>
</div>
</section>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+6 -4
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = '200300';
include_once('./_common.php');
require_once './_common.php';
check_demo();
@@ -10,14 +10,16 @@ check_admin_token();
$post_count_chk = (isset($_POST['chk']) && is_array($_POST['chk'])) ? count($_POST['chk']) : 0;
if(! $post_count_chk)
if (!$post_count_chk) {
alert('삭제할 메일목록을 1개이상 선택해 주세요.');
}
for($i=0; $i<$post_count_chk; $i++) {
for ($i = 0; $i < $post_count_chk; $i++) {
$ma_id = isset($_POST['chk'][$i]) ? (int) $_POST['chk'][$i] : 0;
$sql = " delete from {$g5['mail_table']} where ma_id = '$ma_id' ";
sql_query($sql);
run_event('admin_mail_deleted', $ma_id);
}
goto_url('./mail_list.php');
goto_url('./mail_list.php');
+88 -86
View File
@@ -1,86 +1,88 @@
<?php
$sub_menu = "200300";
include_once('./_common.php');
include_once(G5_EDITOR_LIB);
auth_check_menu($auth, $sub_menu, 'r');
$html_title = '회원메일';
$ma_id = isset($_GET['ma_id']) ? (int) $_GET['ma_id'] : 0;
$ma = array('ma_id'=>0, 'ma_subject'=>'', 'ma_content'=>'');
if ($w == 'u') {
$html_title .= '수정';
$readonly = ' readonly';
$sql = " select * from {$g5['mail_table']} where ma_id = '{$ma_id}' ";
$ma = sql_fetch($sql);
if (!$ma['ma_id'])
alert('등록된 자료가 없습니다.');
} else {
$html_title .= '입력';
}
$g5['title'] = $html_title;
include_once('./admin.head.php');
?>
<div class="local_desc"><p>메일 내용에 {이름} , {닉네임} , {회원아이디} , {이메일} 처럼 내용에 삽입하면 해당 내용에 맞게 변환하여 메일을 발송합니다.</p></div>
<form name="fmailform" id="fmailform" action="./mail_update.php" onsubmit="return fmailform_check(this);" method="post">
<input type="hidden" name="w" value="<?php echo $w ?>" id="w">
<input type="hidden" name="ma_id" value="<?php echo $ma['ma_id'] ?>" id="ma_id">
<input type="hidden" name="token" value="" id="token">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="ma_subject">메일 제목<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="ma_subject" value="<?php echo get_sanitize_input($ma['ma_subject']); ?>" id="ma_subject" required class="required frm_input" size="100"></td>
</tr>
<tr>
<th scope="row"><label for="ma_content">메일 내용<strong class="sound_only">필수</strong></label></th>
<td><?php echo editor_html("ma_content", get_text(html_purifier($ma['ma_content']), 0)); ?></td>
</tr>
</tbody>
</table>
</div>
<div class="btn_fixed_top ">
<input type="submit" class="btn_submit btn" accesskey="s" value="확인">
</div>
</form>
<script>
function fmailform_check(f)
{
errmsg = "";
errfld = "";
check_field(f.ma_subject, "제목을 입력하세요.");
//check_field(f.ma_content, "내용을 입력하세요.");
if (errmsg != "") {
alert(errmsg);
errfld.focus();
return false;
}
<?php echo get_editor_js("ma_content"); ?>
<?php echo chk_editor_js("ma_content"); ?>
return true;
}
document.fmailform.ma_subject.focus();
</script>
<?php
include_once('./admin.tail.php');
<?php
$sub_menu = "200300";
require_once './_common.php';
require_once G5_EDITOR_LIB;
auth_check_menu($auth, $sub_menu, 'r');
$html_title = '회원메일';
$ma_id = isset($_GET['ma_id']) ? (int) $_GET['ma_id'] : 0;
$ma = array('ma_id' => 0, 'ma_subject' => '', 'ma_content' => '');
if ($w == 'u') {
$html_title .= '수정';
$readonly = ' readonly';
$sql = " select * from {$g5['mail_table']} where ma_id = '{$ma_id}' ";
$ma = sql_fetch($sql);
if (!$ma['ma_id']) {
alert('등록된 자료가 없습니다.');
}
} else {
$html_title .= '입력';
}
$g5['title'] = $html_title;
require_once './admin.head.php';
?>
<div class="local_desc">
<p>메일 내용에 {이름} , {닉네임} , {회원아이디} , {이메일} 처럼 내용에 삽입하면 해당 내용에 맞게 변환하여 메일을 발송합니다.</p>
</div>
<form name="fmailform" id="fmailform" action="./mail_update.php" onsubmit="return fmailform_check(this);" method="post">
<input type="hidden" name="w" value="<?php echo $w ?>" id="w">
<input type="hidden" name="ma_id" value="<?php echo $ma['ma_id'] ?>" id="ma_id">
<input type="hidden" name="token" value="" id="token">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="ma_subject">메일 제목<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="ma_subject" value="<?php echo get_sanitize_input($ma['ma_subject']); ?>" id="ma_subject" required class="required frm_input" size="100"></td>
</tr>
<tr>
<th scope="row"><label for="ma_content">메일 내용<strong class="sound_only">필수</strong></label></th>
<td><?php echo editor_html("ma_content", get_text(html_purifier($ma['ma_content']), 0)); ?></td>
</tr>
</tbody>
</table>
</div>
<div class="btn_fixed_top ">
<input type="submit" class="btn_submit btn" accesskey="s" value="확인">
</div>
</form>
<script>
function fmailform_check(f) {
errmsg = "";
errfld = "";
check_field(f.ma_subject, "제목을 입력하세요.");
//check_field(f.ma_content, "내용을 입력하세요.");
if (errmsg != "") {
alert(errmsg);
errfld.focus();
return false;
}
<?php echo get_editor_js("ma_content"); ?>
<?php echo chk_editor_js("ma_content"); ?>
return true;
}
document.fmailform.ma_subject.focus();
</script>
<?php
require_once './admin.tail.php';
+60 -59
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = '200300';
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
@@ -17,7 +17,7 @@ $sql = " select * {$sql_common} order by ma_id desc ";
$result = sql_query($sql);
$g5['title'] = '회원메일발송';
include_once('./admin.head.php');
require_once './admin.head.php';
$colspan = 7;
?>
@@ -32,73 +32,74 @@ $colspan = 7;
<form name="fmaillist" id="fmaillist" action="./mail_delete.php" method="post">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col"><input type="checkbox" name="chkall" value="1" id="chkall" title="현재 페이지 목록 전체선택" onclick="check_all(this.form)"></th>
<th scope="col">번호</th>
<th scope="col">제목</th>
<th scope="col">작성일시</th>
<th scope="col">테스트</th>
<th scope="col">보내기</th>
<th scope="col">미리보기</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++) {
$s_vie = '<a href="./mail_preview.php?ma_id='.$row['ma_id'].'" target="_blank" class="btn btn_03">미리보기</a>';
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col"><input type="checkbox" name="chkall" value="1" id="chkall" title="현재 페이지 목록 전체선택" onclick="check_all(this.form)"></th>
<th scope="col">번호</th>
<th scope="col">제목</th>
<th scope="col">작성일시</th>
<th scope="col">테스트</th>
<th scope="col">보내기</th>
<th scope="col">미리보기</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$s_vie = '<a href="./mail_preview.php?ma_id=' . $row['ma_id'] . '" target="_blank" class="btn btn_03">미리보기</a>';
$num = number_format($total_count - ($page - 1) * $config['cf_page_rows'] - $i);
$num = number_format($total_count - ($page - 1) * $config['cf_page_rows'] - $i);
$bg = 'bg'.($i%2);
?>
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['ma_subject']; ?> 메일</label>
<input type="checkbox" id="chk_<?php echo $i ?>" name="chk[]" value="<?php echo $row['ma_id'] ?>">
</td>
<td class="td_num_c"><?php echo $num ?></td>
<td class="td_left"><a href="./mail_form.php?w=u&amp;ma_id=<?php echo $row['ma_id'] ?>"><?php echo $row['ma_subject'] ?></a></td>
<td class="td_datetime"><?php echo $row['ma_time'] ?></td>
<td class="td_test"><a href="./mail_test.php?ma_id=<?php echo $row['ma_id'] ?>">테스트</a></td>
<td class="td_send"><a href="./mail_select_form.php?ma_id=<?php echo $row['ma_id'] ?>">보내기</a></td>
<td class="td_mng"><?php echo $s_vie ?></td>
</tr>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['ma_subject']; ?> 메일</label>
<input type="checkbox" id="chk_<?php echo $i ?>" name="chk[]" value="<?php echo $row['ma_id'] ?>">
</td>
<td class="td_num_c"><?php echo $num ?></td>
<td class="td_left"><a href="./mail_form.php?w=u&amp;ma_id=<?php echo $row['ma_id'] ?>"><?php echo $row['ma_subject'] ?></a></td>
<td class="td_datetime"><?php echo $row['ma_time'] ?></td>
<td class="td_test"><a href="./mail_test.php?ma_id=<?php echo $row['ma_id'] ?>">테스트</a></td>
<td class="td_send"><a href="./mail_select_form.php?ma_id=<?php echo $row['ma_id'] ?>">보내기</a></td>
<td class="td_mng"><?php echo $s_vie ?></td>
</tr>
<?php
}
if (!$i)
echo "<tr><td colspan=\"".$colspan."\" class=\"empty_table\">자료가 없습니다.</td></tr>";
?>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<input type="submit" value="선택삭제" class="btn btn_02">
<a href="./mail_form.php" id="mail_add" class="btn btn_01">메일내용추가</a>
</div>
<?php
}
if (!$i) {
echo "<tr><td colspan=\"" . $colspan . "\" class=\"empty_table\">자료가 없습니다.</td></tr>";
}
?>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<input type="submit" value="선택삭제" class="btn btn_02">
<a href="./mail_form.php" id="mail_add" class="btn btn_01">메일내용추가</a>
</div>
</form>
<script>
$(function() {
$('#fmaillist').submit(function() {
if(confirm("한번 삭제한 자료는 복구할 방법이 없습니다.\n\n정말 삭제하시겠습니까?")) {
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
$(function() {
$('#fmaillist').submit(function() {
if (confirm("한번 삭제한 자료는 복구할 방법이 없습니다.\n\n정말 삭제하시겠습니까?")) {
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
return false;
}
return true;
} else {
return false;
}
return true;
} else {
return false;
}
});
});
});
</script>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+12 -16
View File
@@ -1,7 +1,7 @@
<?php
$sub_menu = "200300";
include_once('./_common.php');
include_once(G5_LIB_PATH.'/mailer.lib.php');
require_once './_common.php';
require_once G5_LIB_PATH . '/mailer.lib.php';
auth_check_menu($auth, $sub_menu, 'r');
@@ -10,27 +10,23 @@ $ma_id = isset($_REQUEST['ma_id']) ? (int) $_REQUEST['ma_id'] : 0;
$se = sql_fetch("select ma_subject, ma_content from {$g5['mail_table']} where ma_id = '{$ma_id}' ");
$subject = $se['ma_subject'];
$content = conv_content($se['ma_content'], 1) . "<hr size=0><p><span style='font-size:9pt; font-family:굴림'>▶ 더 이상 정보 수신을 원치 않으시면 [<a href='".G5_BBS_URL."/email_stop.php?mb_id=***&amp;mb_md5=***' target='_blank'>수신거부</a>] 해 주십시오.</span></p>";
$content = conv_content($se['ma_content'], 1) . "<hr size=0><p><span style='font-size:9pt; font-family:굴림'>▶ 더 이상 정보 수신을 원치 않으시면 [<a href='" . G5_BBS_URL . "/email_stop.php?mb_id=***&amp;mb_md5=***' target='_blank'>수신거부</a>] 해 주십시오.</span></p>";
?>
<!doctype html>
<html lang="ko">
<head>
<meta charset="utf-8">
<title><?php echo G5_VERSION ?> 메일발송 테스트</title>
<meta charset="utf-8">
<title><?php echo G5_VERSION ?> 메일발송 테스트</title>
</head>
<body>
<h1><?php echo $subject; ?></h1>
<p>
<?php echo $content; ?>
</p>
<p>
<strong>주의!</strong> 이 화면에 보여지는 디자인은 실제 내용이 발송되었을 때 디자인과 다를 수 있습니다.
</p>
<h1><?php echo $subject; ?></h1>
<p><?php echo $content; ?></p>
<p>
<strong>주의!</strong> 이 화면에 보여지는 디자인은 실제 내용이 발송되었을 때 디자인과 다를 수 있습니다.
</p>
</body>
</html>
+139 -127
View File
@@ -1,127 +1,139 @@
<?php
$sub_menu = "200300";
include_once('./_common.php');
if (!$config['cf_email_use'])
alert('환경설정에서 \'메일발송 사용\'에 체크하셔야 메일을 발송할 수 있습니다.');
auth_check_menu($auth, $sub_menu, 'r');
$ma_id = isset($_GET['ma_id']) ? (int) $_GET['ma_id'] : 0;
$sql = " select * from {$g5['mail_table']} where ma_id = '$ma_id' ";
$ma = sql_fetch($sql);
if (!$ma['ma_id'])
alert('보내실 내용을 선택하여 주십시오.');
// 전체회원수
$sql = " select COUNT(*) as cnt from {$g5['member_table']} ";
$row = sql_fetch($sql);
$tot_cnt = $row['cnt'];
// 탈퇴대기회원수
$sql = " select COUNT(*) as cnt from {$g5['member_table']} where mb_leave_date <> '' ";
$row = sql_fetch($sql);
$finish_cnt = $row['cnt'];
$last_option = explode('||', $ma['ma_last_option']);
for ($i=0; $i<count($last_option); $i++) {
$option = explode('=', $last_option[$i]);
// 동적변수
$var = isset($option[0]) ? $option[0] : '';
if( isset($option[1]) ) $$var = $option[1];
}
if (!isset($mb_id1)) $mb_id1 = 1;
if (!isset($mb_level_from)) $mb_level_from = 1;
if (!isset($mb_level_to)) $mb_level_to = 10;
if (!isset($mb_mailling)) $mb_mailling = 1;
$mb_id1_from = isset($mb_id1_from) ? clean_xss_tags($mb_id1_from, 1, 1, 30) : '';
$mb_id1_to = isset($mb_id1_to) ? clean_xss_tags($mb_id1_to, 1, 1, 30) : '';
$mb_email = isset($mb_email) ? clean_xss_tags($mb_email, 1, 1, 100) : '';
$g5['title'] = '회원메일발송';
include_once('./admin.head.php');
?>
<div class="local_ov01 local_ov">
전체회원 <?php echo number_format($tot_cnt) ?>명 , 탈퇴대기회원 <?php echo number_format($finish_cnt) ?>명, 정상회원 <?php echo number_format($tot_cnt - $finish_cnt) ?>명 중 메일 발송 대상 선택
</div>
<form name="frmsendmailselectform" id="frmsendmailselectform" action="./mail_select_list.php" method="post" autocomplete="off">
<input type="hidden" name="ma_id" value="<?php echo $ma_id ?>">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 대상선택</caption>
<tbody>
<tr>
<th scope="row">회원 ID</th>
<td>
<input type="radio" name="mb_id1" value="1" id="mb_id1_all" <?php echo $mb_id1?"checked":""; ?>> <label for="mb_id1_all">전체</label>
<input type="radio" name="mb_id1" value="0" id="mb_id1_section" <?php echo !$mb_id1?"checked":""; ?>> <label for="mb_id1_section">구간</label>
<input type="text" name="mb_id1_from" value="<?php echo get_sanitize_input($mb_id1_from); ?>" id="mb_id1_from" title="시작구간" class="frm_input"> 에서
<input type="text" name="mb_id1_to" value="<?php echo get_sanitize_input($mb_id1_to); ?>" id="mb_id1_to" title="종료구간" class="frm_input"> 까지
</td>
</tr>
<tr>
<th scope="row"><label for="mb_email">E-mail</label></th>
<td>
<?php echo help("메일 주소에 단어 포함 (예 : @".preg_replace('#^(www[^\.]*\.){1}#', '', $_SERVER['HTTP_HOST']).")") ?>
<input type="text" name="mb_email" value="<?php echo get_sanitize_input($mb_email); ?>" id="mb_email" class="frm_input" size="50">
</td>
</tr>
<tr>
<th scope="row"><label for="mb_mailling">메일링</label></th>
<td>
<select name="mb_mailling" id="mb_mailling">
<option value="1">수신동의한 회원만
<option value="">전체
</select>
</td>
</tr>
<tr>
<th scope="row">권한</th>
<td>
<label for="mb_level_from" class="sound_only">최소권한</label>
<select name="mb_level_from" id="mb_level_from">
<?php for ($i=1; $i<=10; $i++) { ?>
<option value="<?php echo $i ?>"><?php echo $i ?></option>
<?php } ?>
</select> 에서
<label for="mb_level_to" class="sound_only">최대권한</label>
<select name="mb_level_to" id="mb_level_to">
<?php for ($i=1; $i<=10; $i++) { ?>
<option value="<?php echo $i ?>"<?php echo $i==10 ? " selected" : ""; ?>><?php echo $i ?></option>
<?php } ?>
</select> 까지
</td>
</tr>
<tr>
<th scope="row"><label for="gr_id">게시판그룹회원</label></th>
<td>
<select name="gr_id" id="gr_id">
<option value=''>전체</option>
<?php
$sql = " select gr_id, gr_subject from {$g5['group_table']} order by gr_subject ";
$result = sql_query($sql);
for ($i=0; $row=sql_fetch_array($result); $i++) {
echo '<option value="'.$row['gr_id'].'">'.$row['gr_subject'].'</option>';
}
?>
</select>
</td>
</tr>
</tbody>
</table>
</div>
<div class="btn_confirm01 btn_confirm">
<input type="submit" value="확인" class="btn_submit">
<a href="./mail_list.php">목록 </a>
</div>
</form>
<?php
include_once('./admin.tail.php');
<?php
$sub_menu = "200300";
require_once './_common.php';
if (!$config['cf_email_use']) {
alert('환경설정에서 \'메일발송 사용\'에 체크하셔야 메일을 발송할 수 있습니다.');
}
auth_check_menu($auth, $sub_menu, 'r');
$ma_id = isset($_GET['ma_id']) ? (int) $_GET['ma_id'] : 0;
$sql = " select * from {$g5['mail_table']} where ma_id = '$ma_id' ";
$ma = sql_fetch($sql);
if (!$ma['ma_id']) {
alert('보내실 내용을 선택하여 주십시오.');
}
// 전체회원수
$sql = " select COUNT(*) as cnt from {$g5['member_table']} ";
$row = sql_fetch($sql);
$tot_cnt = $row['cnt'];
// 탈퇴대기회원수
$sql = " select COUNT(*) as cnt from {$g5['member_table']} where mb_leave_date <> '' ";
$row = sql_fetch($sql);
$finish_cnt = $row['cnt'];
$last_option = explode('||', $ma['ma_last_option']);
for ($i = 0; $i < count($last_option); $i++) {
$option = explode('=', $last_option[$i]);
// 동적변수
$var = isset($option[0]) ? $option[0] : '';
if (isset($option[1])) {
$$var = $option[1];
}
}
if (!isset($mb_id1)) {
$mb_id1 = 1;
}
if (!isset($mb_level_from)) {
$mb_level_from = 1;
}
if (!isset($mb_level_to)) {
$mb_level_to = 10;
}
if (!isset($mb_mailling)) {
$mb_mailling = 1;
}
$mb_id1_from = isset($mb_id1_from) ? clean_xss_tags($mb_id1_from, 1, 1, 30) : '';
$mb_id1_to = isset($mb_id1_to) ? clean_xss_tags($mb_id1_to, 1, 1, 30) : '';
$mb_email = isset($mb_email) ? clean_xss_tags($mb_email, 1, 1, 100) : '';
$g5['title'] = '회원메일발송';
require_once './admin.head.php';
?>
<div class="local_ov01 local_ov">
전체회원 <?php echo number_format($tot_cnt) ?>명 , 탈퇴대기회원 <?php echo number_format($finish_cnt) ?>명, 정상회원 <?php echo number_format($tot_cnt - $finish_cnt) ?>명 중 메일 발송 대상 선택
</div>
<form name="frmsendmailselectform" id="frmsendmailselectform" action="./mail_select_list.php" method="post" autocomplete="off">
<input type="hidden" name="ma_id" value="<?php echo $ma_id ?>">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 대상선택</caption>
<tbody>
<tr>
<th scope="row">회원 ID</th>
<td>
<input type="radio" name="mb_id1" value="1" id="mb_id1_all" <?php echo $mb_id1 ? "checked" : ""; ?>> <label for="mb_id1_all">전체</label>
<input type="radio" name="mb_id1" value="0" id="mb_id1_section" <?php echo !$mb_id1 ? "checked" : ""; ?>> <label for="mb_id1_section">구간</label>
<input type="text" name="mb_id1_from" value="<?php echo get_sanitize_input($mb_id1_from); ?>" id="mb_id1_from" title="시작구간" class="frm_input"> 에서
<input type="text" name="mb_id1_to" value="<?php echo get_sanitize_input($mb_id1_to); ?>" id="mb_id1_to" title="종료구간" class="frm_input"> 까지
</td>
</tr>
<tr>
<th scope="row"><label for="mb_email">E-mail</label></th>
<td>
<?php echo help("메일 주소에 단어 포함 (예 : @" . htmlspecialchars(preg_replace('#^(www[^\.]*\.){1}#', '', $_SERVER['HTTP_HOST'])) . ")") ?>
<input type="text" name="mb_email" value="<?php echo get_sanitize_input($mb_email); ?>" id="mb_email" class="frm_input" size="50">
</td>
</tr>
<tr>
<th scope="row"><label for="mb_mailling">메일링</label></th>
<td>
<select name="mb_mailling" id="mb_mailling">
<option value="1">수신동의한 회원만
<option value="">전체
</select>
</td>
</tr>
<tr>
<th scope="row">권한</th>
<td>
<label for="mb_level_from" class="sound_only">최소권한</label>
<select name="mb_level_from" id="mb_level_from">
<?php for ($i = 1; $i <= 10; $i++) { ?>
<option value="<?php echo $i ?>"><?php echo $i ?></option>
<?php } ?>
</select> 에서
<label for="mb_level_to" class="sound_only">최대권한</label>
<select name="mb_level_to" id="mb_level_to">
<?php for ($i = 1; $i <= 10; $i++) { ?>
<option value="<?php echo $i ?>" <?php echo $i == 10 ? " selected" : ""; ?>><?php echo $i ?></option>
<?php } ?>
</select> 까지
</td>
</tr>
<tr>
<th scope="row"><label for="gr_id">게시판그룹회원</label></th>
<td>
<select name="gr_id" id="gr_id">
<option value=''>전체</option>
<?php
$sql = " select gr_id, gr_subject from {$g5['group_table']} order by gr_subject ";
$result = sql_query($sql);
for ($i = 0; $row = sql_fetch_array($result); $i++) {
echo '<option value="' . $row['gr_id'] . '">' . $row['gr_subject'] . '</option>';
}
?>
</select>
</td>
</tr>
</tbody>
</table>
</div>
<div class="btn_confirm01 btn_confirm">
<input type="submit" value="확인" class="btn_submit">
<a href="./mail_list.php">목록 </a>
</div>
</form>
<?php
require_once './admin.tail.php';
+67 -52
View File
@@ -1,25 +1,38 @@
<?php
$sub_menu = "200300";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
$ma_id = isset($_REQUEST['ma_id']) ? (int) $_REQUEST['ma_id'] : 0;
$ma_last_option = "";
$sql_common = " from {$g5['member_table']} ";
$sql_where = " where (1) ";
$mb_id1 = isset($_POST['mb_id1']) ? (int) $_POST['mb_id1'] : 1;
$mb_id1_from = isset($_POST['mb_id1_from']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_id1_from']), 1, 1, 30)) : '';
$mb_id1_to = isset($_POST['mb_id1_to']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_id1_to']), 1, 1, 30)) : '';
$mb_email = isset($_POST['mb_email']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_email']), 1, 1, 100)) : '';
$mb_mailling = isset($_POST['mb_mailling']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_mailling']), 1, 1, 100)) : '';
$mb_level_from = isset($_POST['mb_level_from'])? (int) $_POST['mb_level_from'] : 1;
$mb_level_to = isset($_POST['mb_level_to']) ? (int) $_POST['mb_level_to'] : 10;
// 회원ID ..에서 ..까지
if ($mb_id1 != 1)
if ($mb_id1 != 1) {
$sql_where .= " and mb_id between '{$mb_id1_from}' and '{$mb_id1_to}' ";
}
// E-mail에 특정 단어 포함
if ($mb_email != "")
if ($mb_email != "") {
$sql_where .= " and mb_email like '%{$mb_email}%' ";
}
// 메일링
if ($mb_mailling != "")
if ($mb_mailling != "") {
$sql_where .= " and mb_mailling = '{$mb_mailling}' ";
}
// 권한
$sql_where .= " and mb_level between '{$mb_level_from}' and '{$mb_level_to}' ";
@@ -30,13 +43,14 @@ if ($gr_id) {
$comma = "";
$sql2 = " select mb_id from {$g5['group_member_table']} where gr_id = '{$gr_id}' order by mb_id ";
$result2 = sql_query($sql2);
for ($k=0; $row2=sql_fetch_array($result2); $k++) {
for ($k = 0; $row2 = sql_fetch_array($result2); $k++) {
$group_member .= "{$comma}'{$row2['mb_id']}'";
$comma = ",";
}
if (!$group_member)
if (!$group_member) {
alert('선택하신 게시판 그룹회원이 한명도 없습니다.');
}
$sql_where .= " and mb_id in ($group_member) ";
}
@@ -47,8 +61,9 @@ $sql_where .= " and mb_leave_date = '' and mb_intercept_date = '' ";
$sql = " select COUNT(*) as cnt {$sql_common} {$sql_where} ";
$row = sql_fetch($sql);
$cnt = $row['cnt'];
if ($cnt == 0)
if ($cnt == 0) {
alert('선택하신 내용으로는 해당되는 회원자료가 없습니다.');
}
// 마지막 옵션을 저장합니다.
$ma_last_option .= "mb_id1={$mb_id1}";
@@ -63,58 +78,58 @@ $ma_last_option .= "||gr_id={$gr_id}";
sql_query(" update {$g5['mail_table']} set ma_last_option = '{$ma_last_option}' where ma_id = '{$ma_id}' ");
$g5['title'] = "메일발송 대상 회원";
include_once('./admin.head.php');
require_once './admin.head.php';
?>
<form name="fmailselectlist" id="fmailselectlist" method="post" action="./mail_select_update.php">
<input type="hidden" name="token" value="">
<input type="hidden" name="ma_id" value="<?php echo $ma_id ?>">
<input type="hidden" name="token" value="">
<input type="hidden" name="ma_id" value="<?php echo get_text($ma_id); ?>">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">번호</th>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">E-mail</th>
</tr>
</thead>
<tbody>
<?php
$sql = " select mb_id, mb_name, mb_nick, mb_email, mb_datetime $sql_common $sql_where order by mb_id ";
$result = sql_query($sql);
$i=0;
$ma_list = "";
$cr = "";
while ($row=sql_fetch_array($result)) {
$i++;
$ma_list .= $cr . $row['mb_email'] . "||" . $row['mb_id'] . "||" . get_text($row['mb_name']) . "||" . $row['mb_nick'] . "||" . $row['mb_datetime'];
$cr = "\n";
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">번호</th>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">E-mail</th>
</tr>
</thead>
<tbody>
<?php
$sql = " select mb_id, mb_name, mb_nick, mb_email, mb_datetime $sql_common $sql_where order by mb_id ";
$result = sql_query($sql);
$i = 0;
$ma_list = "";
$cr = "";
while ($row = sql_fetch_array($result)) {
$i++;
$ma_list .= $cr . $row['mb_email'] . "||" . $row['mb_id'] . "||" . get_text($row['mb_name']) . "||" . $row['mb_nick'] . "||" . $row['mb_datetime'];
$cr = "\n";
$bg = 'bg'.($i%2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_num"><?php echo $i ?></td>
<td class="td_mbid"><?php echo $row['mb_id'] ?></td>
<td class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td class="td_mbname"><?php echo $row['mb_nick'] ?></td>
<td><?php echo $row['mb_email'] ?></td>
</tr>
<?php } ?>
</tbody>
</table>
<textarea name="ma_list" style="display:none"><?php echo $ma_list?></textarea>
</div>
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_num"><?php echo $i ?></td>
<td class="td_mbid"><?php echo $row['mb_id'] ?></td>
<td class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td class="td_mbname"><?php echo $row['mb_nick'] ?></td>
<td><?php echo $row['mb_email'] ?></td>
</tr>
<?php } ?>
</tbody>
</table>
<textarea name="ma_list" style="display:none"><?php echo html_purifier($ma_list); ?></textarea>
</div>
<div class="btn_confirm01 btn_confirm">
<input type="submit" value="메일보내기" class="btn_submit">
<a href="./mail_select_form.php?ma_id=<?php echo $ma_id ?>">뒤로</a>
</div>
<div class="btn_confirm01 btn_confirm">
<input type="submit" value="메일보내기" class="btn_submit">
<a href="./mail_select_form.php?ma_id=<?php echo $ma_id ?>">뒤로</a>
</div>
</form>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
+21 -18
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = "200300";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'w');
@@ -8,10 +8,12 @@ $html_title = '회원메일 발송';
check_demo();
$security_mail_url = g5_require_security_mail_url();
check_admin_token();
include_once('./admin.head.php');
include_once(G5_LIB_PATH.'/mailer.lib.php');
require_once './admin.head.php';
require_once G5_LIB_PATH . '/mailer.lib.php';
$countgap = 10; // 몇건씩 보낼지 설정
$maxscreen = 500; // 몇건씩 화면에 보여줄건지?
@@ -25,7 +27,7 @@ echo "</span>";
<span id="cont"></span>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
flush();
ob_flush();
@@ -43,25 +45,23 @@ $ma = sql_fetch($sql);
$subject = $ma['ma_subject'];
$cnt = 0;
for ($i=0; $i<count($member_list); $i++)
{
for ($i = 0; $i < count($member_list); $i++) {
list($to_email, $mb_id, $name, $nick, $datetime) = explode("||", trim($member_list[$i]));
$sw = preg_match("/[0-9a-zA-Z_]+(\.[0-9a-zA-Z_]+)*@[0-9a-zA-Z_]+(\.[0-9a-zA-Z_]+)*/", $to_email);
// 올바른 메일 주소만
if ($sw == true)
{
if ($sw == true) {
$cnt++;
$mb_md5 = md5($mb_id.$to_email.$datetime);
$mb_md5 = md5($mb_id . $to_email . $datetime);
$content = $ma['ma_content'];
$content = preg_replace("/{이름}/", $name, $content);
$content = preg_replace("/{닉네임}/", $nick, $content);
$content = preg_replace("/{회원아이디}/", $mb_id, $content);
$content = preg_replace("/{이메일}/", $to_email, $content);
$content = preg_replace("/{이름}/", $name, (string)$content);
$content = preg_replace("/{닉네임}/", $nick, (string)$content);
$content = preg_replace("/{회원아이디}/", $mb_id, (string)$content);
$content = preg_replace("/{이메일}/", $to_email, (string)$content);
$content = $content . "<hr size=0><p><span style='font-size:9pt; font-family:굴림'>▶ 더 이상 정보 수신을 원치 않으시면 [<a href='".G5_BBS_URL."/email_stop.php?mb_id={$mb_id}&amp;mb_md5={$mb_md5}' target='_blank'>수신거부</a>] 해 주십시오.</span></p>";
$content = $content . "<hr size=0><p><span style='font-size:9pt; font-family:굴림'>▶ 더 이상 정보 수신을 원치 않으시면 [<a href='" . ($security_mail_url . '/' . G5_BBS_DIR) . "/email_stop.php?mb_id={$mb_id}&amp;mb_md5={$mb_md5}' target='_blank'>수신거부</a>] 해 주십시오.</span></p>";
mailer($config['cf_admin_email_name'], $config['cf_admin_email'], $to_email, $subject, $content, 1);
@@ -71,15 +71,18 @@ for ($i=0; $i<count($member_list); $i++)
ob_flush();
ob_end_flush();
usleep($sleepsec);
if ($cnt % $countgap == 0)
{
if ($cnt % $countgap == 0) {
echo "<script> document.all.cont.innerHTML += '<br>'; document.body.scrollTop += 1000; </script>\n";
}
// 화면을 지운다... 부하를 줄임
if ($cnt % $maxscreen == 0)
if ($cnt % $maxscreen == 0) {
echo "<script> document.all.cont.innerHTML = ''; document.body.scrollTop += 1000; </script>\n";
}
}
}
?>
<script> document.all.cont.innerHTML += "<br><br>총 <?php echo number_format($cnt) ?>건 발송<br><br><font color=crimson><b>[끝]</b></font>"; document.body.scrollTop += 1000; </script>
<script>
document.all.cont.innerHTML += "<br><br>총 <?php echo number_format($cnt) ?>건 발송<br><br><font color=crimson><b>[끝]</b></font>";
document.body.scrollTop += 1000;
</script>
+13 -10
View File
@@ -1,16 +1,19 @@
<?php
$sub_menu = "200300";
include_once('./_common.php');
require_once './_common.php';
if (!$config['cf_email_use'])
if (!$config['cf_email_use']) {
alert('환경설정에서 \'메일발송 사용\'에 체크하셔야 메일을 발송할 수 있습니다.');
}
include_once(G5_LIB_PATH.'/mailer.lib.php');
require_once G5_LIB_PATH . '/mailer.lib.php';
auth_check_menu($auth, $sub_menu, 'w');
check_demo();
$security_mail_url = g5_require_security_mail_url();
$g5['title'] = '회원메일 테스트';
$name = get_text($member['mb_name']);
@@ -25,15 +28,15 @@ $ma = sql_fetch($sql);
$subject = $ma['ma_subject'];
$content = $ma['ma_content'];
$content = preg_replace("/{이름}/", $name, $content);
$content = preg_replace("/{닉네임}/", $nick, $content);
$content = preg_replace("/{회원아이디}/", $mb_id, $content);
$content = preg_replace("/{이메일}/", $email, $content);
$content = preg_replace("/{이름}/", $name, (string)$content);
$content = preg_replace("/{닉네임}/", $nick, (string)$content);
$content = preg_replace("/{회원아이디}/", $mb_id, (string)$content);
$content = preg_replace("/{이메일}/", $email, (string)$content);
$mb_md5 = md5($member['mb_id'].$member['mb_email'].$member['mb_datetime']);
$mb_md5 = md5($member['mb_id'] . $member['mb_email'] . $member['mb_datetime']);
$content = $content . '<p>더 이상 정보 수신을 원치 않으시면 [<a href="'.G5_BBS_URL.'/email_stop.php?mb_id='.$mb_id.'&amp;mb_md5='.$mb_md5.'" target="_blank">수신거부</a>] 해 주십시오.</p>';
$content = $content . '<p>더 이상 정보 수신을 원치 않으시면 [<a href="' . ($security_mail_url . '/' . G5_BBS_DIR) . '/email_stop.php?mb_id=' . $mb_id . '&amp;mb_md5=' . $mb_md5 . '" target="_blank">수신거부</a>] 해 주십시오.</p>';
mailer($config['cf_title'], $member['mb_email'], $member['mb_email'], $subject, $content, 1);
alert($member['mb_nick'].'('.$member['mb_email'].')님께 테스트 메일을 발송하였습니다. 확인하여 주십시오.');
alert($member['mb_nick'] . '(' . $member['mb_email'] . ')님께 테스트 메일을 발송하였습니다. 확인하여 주십시오.');
+18 -15
View File
@@ -1,41 +1,44 @@
<?php
$sub_menu = "200300";
include_once('./_common.php');
require_once './_common.php';
if ($w == 'u' || $w == 'd')
if ($w == 'u' || $w == 'd') {
check_demo();
}
auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
$ma_id = isset($_POST['ma_id']) ? (int) $_POST['ma_id'] : 0;
$ma_subject = isset($_POST['ma_subject']) ? strip_tags(clean_xss_attributes($_POST['ma_subject'])) : '';
$ma_subject = isset($_POST['ma_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['ma_subject'])))) : '';
$ma_content = isset($_POST['ma_content']) ? $_POST['ma_content'] : '';
if ($w == '')
{
if ($w == '') {
$sql = " insert {$g5['mail_table']}
set ma_subject = '{$ma_subject}',
ma_content = '{$ma_content}',
ma_time = '".G5_TIME_YMDHIS."',
ma_time = '" . G5_TIME_YMDHIS . "',
ma_ip = '{$_SERVER['REMOTE_ADDR']}' ";
sql_query($sql);
}
else if ($w == 'u')
{
$ma_id = sql_insert_id();
run_event('admin_mail_created', $ma_id);
} elseif ($w == 'u') {
$sql = " update {$g5['mail_table']}
set ma_subject = '{$ma_subject}',
ma_content = '{$ma_content}',
ma_time = '".G5_TIME_YMDHIS."',
ma_time = '" . G5_TIME_YMDHIS . "',
ma_ip = '{$_SERVER['REMOTE_ADDR']}'
where ma_id = '{$ma_id}' ";
sql_query($sql);
}
else if ($w == 'd')
{
$sql = " delete from {$g5['mail_table']} where ma_id = '{$ma_id}' ";
run_event('admin_mail_updated', $ma_id);
} elseif ($w == 'd') {
$sql = " delete from {$g5['mail_table']} where ma_id = '{$ma_id}' ";
sql_query($sql);
run_event('admin_mail_deleted', $ma_id);
}
goto_url('./mail_list.php');
goto_url('./mail_list.php');
+30
View File
@@ -0,0 +1,30 @@
<?php
$sub_menu = '200100';
require_once './_common.php';
check_demo();
auth_check_menu($auth, $sub_menu, 'w');
auth_check_menu($auth, $sub_menu, 'd');
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
alert('올바른 방법으로 이용해 주십시오.');
}
check_admin_token();
admin_referer_check();
$mb_id = isset($_POST['mb_id']) && is_string($_POST['mb_id']) ? trim($_POST['mb_id']) : '';
$mb = get_member($mb_id);
if (empty($mb['mb_id'])) {
alert('존재하지 않는 회원자료입니다.');
}
if ($is_admin !== 'super' && ($mb['mb_level'] >= $member['mb_level'] || is_admin($mb['mb_id']) === 'super')) {
alert('자신보다 권한이 높거나 같은 회원의 본인확인 정보는 삭제할 수 없습니다.');
}
if (!admin_clear_member_certification($mb['mb_id'])) {
alert('본인확인 정보를 모두 삭제하지 못했습니다. DB 상태를 확인한 뒤 다시 시도해 주십시오.');
}
alert('본인확인 정보와 인증 내역을 삭제했습니다.', './member_form.php?w=u&mb_id='.urlencode($mb['mb_id']));
+11 -9
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = "200100";
include_once("./_common.php");
require_once "./_common.php";
check_demo();
@@ -8,21 +8,23 @@ auth_check_menu($auth, $sub_menu, "d");
$mb = isset($_POST['mb_id']) ? get_member($_POST['mb_id']) : array();
if (! (isset($mb['mb_id']) && $mb['mb_id']))
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
alert("회원자료가 존재하지 않습니다.");
else if ($member['mb_id'] == $mb['mb_id'])
} elseif ($member['mb_id'] == $mb['mb_id']) {
alert("로그인 중인 관리자는 삭제 할 수 없습니다.");
else if (is_admin($mb['mb_id']) == "super")
} elseif (is_admin($mb['mb_id']) == "super") {
alert("최고 관리자는 삭제할 수 없습니다.");
else if ($mb['mb_level'] >= $member['mb_level'])
} elseif ($mb['mb_level'] >= $member['mb_level']) {
alert("자신보다 권한이 높거나 같은 회원은 삭제할 수 없습니다.");
}
check_admin_token();
// 회원자료 삭제
member_delete($mb['mb_id']);
if ($url)
goto_url("{$url}?$qstr&amp;w=u&amp;mb_id=$mb_id");
else
goto_url("./member_list.php?$qstr");
if (isset($url)) {
goto_url("{$url}?$qstr&amp;w=u&amp;mb_id=" . $mb['mb_id']);
} else {
goto_url("./member_list.php?$qstr");
}
+538 -393
View File
File diff suppressed because it is too large Load Diff
+229 -105
View File
@@ -1,33 +1,49 @@
<?php
$sub_menu = "200100";
include_once("./_common.php");
include_once(G5_LIB_PATH."/register.lib.php");
include_once(G5_LIB_PATH.'/thumbnail.lib.php');
require_once "./_common.php";
require_once G5_LIB_PATH . "/register.lib.php";
require_once G5_LIB_PATH . '/thumbnail.lib.php';
if ($w == 'u')
if ($w == 'u') {
check_demo();
}
auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
$mb_id = isset($_POST['mb_id']) ? trim($_POST['mb_id']) : '';
$mb_id = isset($_POST['mb_id']) ? trim($_POST['mb_id']) : '';
$mb_password = isset($_POST['mb_password']) ? trim($_POST['mb_password']) : '';
$mb_certify_case = isset($_POST['mb_certify_case']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_certify_case']) : '';
$mb_certify = isset($_POST['mb_certify']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_certify']) : '';
$mb_zip = isset($_POST['mb_zip']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_zip']) : '';
$mb_certify = isset($_POST['mb_certify']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_certify']) : '';
$mb_zip = isset($_POST['mb_zip']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_zip']) : '';
// 광고성 정보 수신
$mb_marketing_agree = isset($_POST['mb_marketing_agree']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_marketing_agree']), 1, 1)) : '0';
$mb_thirdparty_agree = isset($_POST['mb_thirdparty_agree']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_thirdparty_agree']), 1, 1)) : '0';
// 관리자가 자동등록방지를 사용해야 할 경우 ( 회원의 비밀번호 변경시 캡챠를 체크한다 )
if ($mb_password) {
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
}
// 휴대폰번호 체크
$mb_hp = hyphen_hp_number($_POST['mb_hp']);
if($mb_hp) {
if ($mb_hp) {
$result = exist_mb_hp($mb_hp, $mb_id);
if ($result)
if ($result) {
alert($result);
}
}
// 인증정보처리
if($mb_certify_case && $mb_certify) {
$mb_certify = isset($_POST['mb_certify_case']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_certify_case']) : '';
$mb_adult = isset($_POST['mb_adult']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_adult']) : '';
if ($mb_certify_case && $mb_certify) {
$mb_certify = isset($_POST['mb_certify_case']) ? preg_replace('/[^0-9a-z_]/i', '', (string)$_POST['mb_certify_case']) : '';
$mb_adult = isset($_POST['mb_adult']) ? preg_replace('/[^0-9a-z_]/i', '', (string)$_POST['mb_adult']) : '';
} else {
$mb_certify = '';
$mb_adult = 0;
@@ -39,37 +55,41 @@ $mb_zip2 = substr($mb_zip, 3);
$mb_email = isset($_POST['mb_email']) ? get_email_address(trim($_POST['mb_email'])) : '';
$mb_nick = isset($_POST['mb_nick']) ? trim(strip_tags($_POST['mb_nick'])) : '';
if ($msg = valid_mb_nick($mb_nick)) alert($msg, "", true, true);
if ($msg = valid_mb_nick($mb_nick)) {
alert($msg, "", true, true);
}
$posts = array();
$check_keys = array(
'mb_name',
'mb_homepage',
'mb_tel',
'mb_addr1',
'mb_addr2',
'mb_addr3',
'mb_addr_jibeon',
'mb_signature',
'mb_leave_date',
'mb_intercept_date',
'mb_mailling',
'mb_sms',
'mb_open',
'mb_profile',
'mb_level'
'mb_name',
'mb_homepage',
'mb_tel',
'mb_addr1',
'mb_addr2',
'mb_addr3',
'mb_addr_jibeon',
'mb_signature',
'mb_leave_date',
'mb_intercept_date',
'mb_mailling',
'mb_sms',
'mb_open',
'mb_profile',
'mb_level'
);
for($i=1;$i<=10;$i++){
$check_keys[] = 'mb_'.$i;
for ($i = 1; $i <= 10; $i++) {
$check_keys[] = 'mb_' . $i;
}
foreach( $check_keys as $key ){
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
foreach ($check_keys as $key) {
if( in_array($key, array('mb_signature', 'mb_profile')) ){
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1, 0, 0)) : '';
} else {
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
}
}
$mb_memo = isset($_POST['mb_memo']) ? $_POST['mb_memo'] : '';
$sql_common = " mb_name = '{$posts['mb_name']}',
mb_nick = '{$mb_nick}',
mb_email = '{$mb_email}',
@@ -91,8 +111,11 @@ $sql_common = " mb_name = '{$posts['mb_name']}',
mb_mailling = '{$posts['mb_mailling']}',
mb_sms = '{$posts['mb_sms']}',
mb_open = '{$posts['mb_open']}',
mb_open_date = '".G5_TIME_YMDHIS."',
mb_profile = '{$posts['mb_profile']}',
mb_level = '{$posts['mb_level']}',
mb_marketing_agree = '{$mb_marketing_agree}',
mb_thirdparty_agree = '{$mb_thirdparty_agree}',
mb_1 = '{$posts['mb_1']}',
mb_2 = '{$posts['mb_2']}',
mb_3 = '{$posts['mb_3']}',
@@ -104,82 +127,174 @@ $sql_common = " mb_name = '{$posts['mb_name']}',
mb_9 = '{$posts['mb_9']}',
mb_10 = '{$posts['mb_10']}' ";
if ($w == '')
{
// 부여하려는 mb_level 상한 검증 (자기보다 높은 권한 부여 차단)
if ($is_admin !== 'super' && (int) $posts['mb_level'] >= (int) $member['mb_level']) {
alert('자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.');
}
if ($w == '') {
$mb = get_member($mb_id);
if (isset($mb['mb_id']) && $mb['mb_id'])
alert('이미 존재하는 회원아이디입니다.\\nID : '.$mb['mb_id'].'\\n이름 : '.$mb['mb_name'].'\\n닉네임 : '.$mb['mb_nick'].'\\n메일 : '.$mb['mb_email']);
if (isset($mb['mb_id']) && $mb['mb_id']) {
alert('이미 존재하는 회원아이디입니다.\\nID : ' . $mb['mb_id'] . '\\n이름 : ' . $mb['mb_name'] . '\\n닉네임 : ' . $mb['mb_nick'] . '\\n메일 : ' . $mb['mb_email']);
}
// 닉네임중복체크
$sql = " select mb_id, mb_name, mb_nick, mb_email from {$g5['member_table']} where mb_nick = '{$mb_nick}' ";
$row = sql_fetch($sql);
if (isset($row['mb_id']) && $row['mb_id'])
alert('이미 존재하는 닉네임입니다.\\nID : '.$row['mb_id'].'\\n이름 : '.$row['mb_name'].'\\n닉네임 : '.$row['mb_nick'].'\\n메일 : '.$row['mb_email']);
if (isset($row['mb_id']) && $row['mb_id']) {
alert('이미 존재하는 닉네임입니다.\\nID : ' . $row['mb_id'] . '\\n이름 : ' . $row['mb_name'] . '\\n닉네임 : ' . $row['mb_nick'] . '\\n메일 : ' . $row['mb_email']);
}
// 이메일중복체크
$sql = " select mb_id, mb_name, mb_nick, mb_email from {$g5['member_table']} where mb_email = '{$mb_email}' ";
$row = sql_fetch($sql);
if (isset($row['mb_id']) && $row['mb_id'])
alert('이미 존재하는 이메일입니다.\\nID : '.$row['mb_id'].'\\n이름 : '.$row['mb_name'].'\\n닉네임 : '.$row['mb_nick'].'\\n메일 : '.$row['mb_email']);
if (isset($row['mb_id']) && $row['mb_id']) {
alert('이미 존재하는 이메일입니다.\\nID : ' . $row['mb_id'] . '\\n이름 : ' . $row['mb_name'] . '\\n닉네임 : ' . $row['mb_nick'] . '\\n메일 : ' . $row['mb_email']);
}
sql_query(" insert into {$g5['member_table']} set mb_id = '{$mb_id}', mb_password = '".get_encrypt_string($mb_password)."', mb_datetime = '".G5_TIME_YMDHIS."', mb_ip = '{$_SERVER['REMOTE_ADDR']}', mb_email_certify = '".G5_TIME_YMDHIS."', {$sql_common} ");
}
else if ($w == 'u')
{
$agree_items = array();
// 마케팅 목적의 개인정보 수집 및 이용
if ($mb_marketing_agree == 1) {
$sql_common .= " , mb_marketing_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "마케팅 목적의 개인정보 수집 및 이용(동의)";
}
// 광고성 이메일 수신
if ($mb_mailling == 1) {
$sql_common .= " , mb_mailling_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 이메일 수신(동의)";
}
// 광고성 SMS/카카오톡 수신
if ($mb_sms == 1) {
$sql_common .= " , mb_sms_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 SMS/카카오톡 수신(동의)";
}
// 개인정보 제3자 제공
if ($mb_thirdparty_agree == 1) {
$sql_common .= " , mb_thirdparty_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "개인정보 제3자 제공(동의)";
}
// 동의 로그 추가
if (!empty($agree_items)) {
$agree_log = "[".G5_TIME_YMDHIS.", 관리자 회원추가] " . implode(' | ', $agree_items) . "\n";
$sql_common .= " , mb_agree_log = CONCAT('{$agree_log}', IFNULL(mb_agree_log, ''))";
}
sql_query(" insert into {$g5['member_table']} set mb_id = '{$mb_id}', mb_password = '" . get_encrypt_string($mb_password) . "', mb_datetime = '" . G5_TIME_YMDHIS . "', mb_ip = '{$_SERVER['REMOTE_ADDR']}', mb_email_certify = '" . G5_TIME_YMDHIS . "', {$sql_common} ");
} elseif ($w == 'u') {
$mb = get_member($mb_id);
if (! (isset($mb['mb_id']) && $mb['mb_id']))
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
alert('존재하지 않는 회원자료입니다.');
}
if ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level'])
if ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level']) {
alert('자신보다 권한이 높거나 같은 회원은 수정할 수 없습니다.');
}
if ($is_admin !== 'super' && is_admin($mb['mb_id']) === 'super' ) {
if ($is_admin !== 'super' && is_admin($mb['mb_id']) === 'super') {
alert('최고관리자의 비밀번호를 수정할수 없습니다.');
}
if ($mb_id === $member['mb_id'] && $_POST['mb_level'] != $mb['mb_level'])
alert($mb['mb_id'].' : 로그인 중인 관리자 레벨은 수정 할 수 없습니다.');
if ($mb_id === $member['mb_id'] && $_POST['mb_level'] != $mb['mb_level']) {
alert($mb['mb_id'] . ' : 로그인 중인 관리자 레벨은 수정할 수 없습니다.');
}
if ($posts['mb_leave_date'] || $posts['mb_intercept_date']){
if ($member['mb_id'] === $mb['mb_id'] || is_admin($mb['mb_id']) === 'super'){
alert('해당 관리자의 탈퇴 일자 또는 접근 차단 일자를 수정할 수 없습니다.');
}
}
// 닉네임중복체크
$sql = " select mb_id, mb_name, mb_nick, mb_email from {$g5['member_table']} where mb_nick = '{$mb_nick}' and mb_id <> '$mb_id' ";
$row = sql_fetch($sql);
if (isset($row['mb_id']) && $row['mb_id'])
alert('이미 존재하는 닉네임입니다.\\nID : '.$row['mb_id'].'\\n이름 : '.$row['mb_name'].'\\n닉네임 : '.$row['mb_nick'].'\\n메일 : '.$row['mb_email']);
if (isset($row['mb_id']) && $row['mb_id']) {
alert('이미 존재하는 닉네임입니다.\\nID : ' . $row['mb_id'] . '\\n이름 : ' . $row['mb_name'] . '\\n닉네임 : ' . $row['mb_nick'] . '\\n메일 : ' . $row['mb_email']);
}
// 이메일중복체크
$sql = " select mb_id, mb_name, mb_nick, mb_email from {$g5['member_table']} where mb_email = '{$mb_email}' and mb_id <> '$mb_id' ";
$row = sql_fetch($sql);
if (isset($row['mb_id']) && $row['mb_id'])
alert('이미 존재하는 이메일입니다.\\nID : '.$row['mb_id'].'\\n이름 : '.$row['mb_name'].'\\n닉네임 : '.$row['mb_nick'].'\\n메일 : '.$row['mb_email']);
if (isset($row['mb_id']) && $row['mb_id']) {
alert('이미 존재하는 이메일입니다.\\nID : ' . $row['mb_id'] . '\\n이름 : ' . $row['mb_name'] . '\\n닉네임 : ' . $row['mb_nick'] . '\\n메일 : ' . $row['mb_email']);
}
if ($mb_password)
$sql_password = " , mb_password = '".get_encrypt_string($mb_password)."' ";
else
if ($mb_password) {
$sql_password = " , mb_password = '" . get_encrypt_string($mb_password) . "' ";
} else {
$sql_password = "";
}
if (isset($passive_certify) && $passive_certify)
$sql_certify = " , mb_email_certify = '".G5_TIME_YMDHIS."' ";
else
if (isset($passive_certify) && $passive_certify) {
$sql_certify = " , mb_email_certify = '" . G5_TIME_YMDHIS . "' ";
} else {
$sql_certify = "";
}
// 현재 데이터 조회
$row = sql_fetch("select * from {$g5['member_table']} where mb_id = '{$mb_id}' ");
$agree_items = array();
// 마케팅 목적의 개인정보 수집 및 이용
$sql_marketing_date = "";
if ($row['mb_marketing_agree'] !== $mb_marketing_agree) {
$sql_marketing_date .= " , mb_marketing_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "마케팅 목적의 개인정보 수집 및 이용(" . ($mb_marketing_agree == 1 ? "동의" : "철회") . ")";
}
// 광고성 이메일 수신
$sql_mailling_date = "";
if ($row['mb_mailling'] !== $mb_mailling) {
$sql_mailling_date .= " , mb_mailling_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 이메일 수신(" . ($mb_mailling == 1 ? "동의" : "철회") . ")";
}
// 광고성 SMS/카카오톡 수신
$sql_sms_date = "";
if ($row['mb_sms'] !== $mb_sms) {
$sql_sms_date .= " , mb_sms_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 SMS/카카오톡 수신(" . ($mb_sms == 1 ? "동의" : "철회") . ")";
}
// 개인정보 제3자 제공
$sql_thirdparty_date = "";
if ($row['mb_thirdparty_agree'] !== $mb_thirdparty_agree) {
$sql_thirdparty_date .= " , mb_thirdparty_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "개인정보 제3자 제공(" . ($mb_thirdparty_agree == 1 ? "동의" : "철회") . ")";
}
// 동의 로그 추가
$sql_agree_log = "";
if (!empty($agree_items)) {
$agree_log = "[".G5_TIME_YMDHIS.", 관리자 회원수정] " . implode(' | ', $agree_items) . "\n";
$sql_agree_log .= " , mb_agree_log = CONCAT('{$agree_log}', IFNULL(mb_agree_log, ''))";
}
$sql = " update {$g5['member_table']}
set {$sql_common}
{$sql_password}
{$sql_certify}
{$sql_mailling_date}
{$sql_sms_date}
{$sql_marketing_date}
{$sql_thirdparty_date}
{$sql_agree_log}
where mb_id = '{$mb_id}' ";
sql_query($sql);
}
else
} else {
alert('제대로 된 값이 넘어오지 않았습니다.');
}
if( $w == '' || $w == 'u' ){
$mb_dir = substr($mb_id,0,2);
$mb_icon_img = get_mb_icon_name($mb_id).'.gif';
if ($w == '' || $w == 'u') {
$mb_dir = substr($mb_id, 0, 2);
$mb_icon_img = get_mb_icon_name($mb_id) . '.gif';
// 회원 아이콘 삭제
if (isset($del_mb_icon) && $del_mb_icon)
@unlink(G5_DATA_PATH.'/member/'.$mb_dir.'/'.$mb_icon_img);
if (isset($del_mb_icon) && $del_mb_icon) {
@unlink(G5_DATA_PATH . '/member/' . $mb_dir . '/' . $mb_icon_img);
}
$image_regex = "/(\.(gif|jpe?g|png))$/i";
@@ -190,77 +305,82 @@ if( $w == '' || $w == 'u' ){
}
if (preg_match($image_regex, $_FILES['mb_icon']['name'])) {
$mb_icon_dir = G5_DATA_PATH.'/member/'.$mb_dir;
$mb_icon_dir = G5_DATA_PATH . '/member/' . $mb_dir;
@mkdir($mb_icon_dir, G5_DIR_PERMISSION);
@chmod($mb_icon_dir, G5_DIR_PERMISSION);
$dest_path = $mb_icon_dir.'/'.$mb_icon_img;
$dest_path = $mb_icon_dir . '/' . $mb_icon_img;
move_uploaded_file($_FILES['mb_icon']['tmp_name'], $dest_path);
chmod($dest_path, G5_FILE_PERMISSION);
if (file_exists($dest_path)) {
$size = @getimagesize($dest_path);
if ($size[0] > $config['cf_member_icon_width'] || $size[1] > $config['cf_member_icon_height']) {
$thumb = null;
if($size[2] === 2 || $size[2] === 3) {
//jpg 또는 png 파일 적용
$thumb = thumbnail($mb_icon_img, $mb_icon_dir, $mb_icon_dir, $config['cf_member_icon_width'], $config['cf_member_icon_height'], true, true);
if($thumb) {
if ($size) {
if ($size[0] > $config['cf_member_icon_width'] || $size[1] > $config['cf_member_icon_height']) {
$thumb = null;
if ($size[2] === 2 || $size[2] === 3) {
//jpg 또는 png 파일 적용
$thumb = thumbnail($mb_icon_img, $mb_icon_dir, $mb_icon_dir, $config['cf_member_icon_width'], $config['cf_member_icon_height'], true, true);
if ($thumb) {
@unlink($dest_path);
rename($mb_icon_dir . '/' . $thumb, $dest_path);
}
}
if (!$thumb) {
// 아이콘의 폭 또는 높이가 설정값 보다 크다면 이미 업로드 된 아이콘 삭제
@unlink($dest_path);
rename($mb_icon_dir.'/'.$thumb, $dest_path);
}
}
if( !$thumb ){
// 아이콘의 폭 또는 높이가 설정값 보다 크다면 이미 업로드 된 아이콘 삭제
@unlink($dest_path);
}
}
}
}
}
$mb_img_dir = G5_DATA_PATH.'/member_image/';
if( !is_dir($mb_img_dir) ){
$mb_img_dir = G5_DATA_PATH . '/member_image/';
if (!is_dir($mb_img_dir)) {
@mkdir($mb_img_dir, G5_DIR_PERMISSION);
@chmod($mb_img_dir, G5_DIR_PERMISSION);
}
$mb_img_dir .= substr($mb_id,0,2);
$mb_img_dir .= substr($mb_id, 0, 2);
// 회원 이미지 삭제
if (isset($del_mb_img) && $del_mb_img)
@unlink($mb_img_dir.'/'.$mb_icon_img);
if (isset($del_mb_img) && $del_mb_img) {
@unlink($mb_img_dir . '/' . $mb_icon_img);
}
// 아이콘 업로드
if (isset($_FILES['mb_img']) && is_uploaded_file($_FILES['mb_img']['tmp_name'])) {
if (!preg_match($image_regex, $_FILES['mb_img']['name'])) {
alert($_FILES['mb_img']['name'] . '은(는) 이미지 파일이 아닙니다.');
}
if (preg_match($image_regex, $_FILES['mb_img']['name'])) {
@mkdir($mb_img_dir, G5_DIR_PERMISSION);
@chmod($mb_img_dir, G5_DIR_PERMISSION);
$dest_path = $mb_img_dir.'/'.$mb_icon_img;
$dest_path = $mb_img_dir . '/' . $mb_icon_img;
move_uploaded_file($_FILES['mb_img']['tmp_name'], $dest_path);
chmod($dest_path, G5_FILE_PERMISSION);
if (file_exists($dest_path)) {
$size = @getimagesize($dest_path);
if ($size[0] > $config['cf_member_img_width'] || $size[1] > $config['cf_member_img_height']) {
$thumb = null;
if($size[2] === 2 || $size[2] === 3) {
//jpg 또는 png 파일 적용
$thumb = thumbnail($mb_icon_img, $mb_img_dir, $mb_img_dir, $config['cf_member_img_width'], $config['cf_member_img_height'], true, true);
if($thumb) {
if ($size) {
if ($size[0] > $config['cf_member_img_width'] || $size[1] > $config['cf_member_img_height']) {
$thumb = null;
if ($size[2] === 2 || $size[2] === 3) {
//jpg 또는 png 파일 적용
$thumb = thumbnail($mb_icon_img, $mb_img_dir, $mb_img_dir, $config['cf_member_img_width'], $config['cf_member_img_height'], true, true);
if ($thumb) {
@unlink($dest_path);
rename($mb_img_dir . '/' . $thumb, $dest_path);
}
}
if (!$thumb) {
// 아이콘의 폭 또는 높이가 설정값 보다 크다면 이미 업로드 된 아이콘 삭제
@unlink($dest_path);
rename($mb_img_dir.'/'.$thumb, $dest_path);
}
}
if( !$thumb ){
// 아이콘의 폭 또는 높이가 설정값 보다 크다면 이미 업로드 된 아이콘 삭제
@unlink($dest_path);
}
}
}
@@ -268,6 +388,10 @@ if( $w == '' || $w == 'u' ){
}
}
if (function_exists('get_admin_captcha_by')) {
get_admin_captcha_by('remove');
}
run_event('admin_member_form_update', $w, $mb_id);
goto_url('./member_form.php?'.$qstr.'&amp;w=u&amp;mb_id='.$mb_id, false);
goto_url('./member_form.php?' . $qstr . '&amp;w=u&amp;mb_id=' . $mb_id, false);
+266 -238
View File
@@ -1,40 +1,50 @@
<?php
$sub_menu = "200100";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
$sql_common = " from {$g5['member_table']} ";
$allowed_sfl = array('mb_id', 'mb_nick', 'mb_name', 'mb_level', 'mb_email', 'mb_tel', 'mb_hp', 'mb_point', 'mb_datetime', 'mb_ip', 'mb_recommend');
if (!in_array($sfl, $allowed_sfl)) {
$sfl = 'mb_id';
}
$sql_search = " where (1) ";
if ($stx) {
$sql_search .= " and ( ";
switch ($sfl) {
case 'mb_point' :
case 'mb_point':
$sql_search .= " ({$sfl} >= '{$stx}') ";
break;
case 'mb_level' :
case 'mb_level':
$sql_search .= " ({$sfl} = '{$stx}') ";
break;
case 'mb_tel' :
case 'mb_hp' :
case 'mb_tel':
case 'mb_hp':
$sql_search .= " ({$sfl} like '%{$stx}') ";
break;
default :
default:
$sql_search .= " ({$sfl} like '{$stx}%') ";
break;
}
$sql_search .= " ) ";
}
if ($is_admin != 'super')
if ($is_admin != 'super') {
$sql_search .= " and mb_level <= '{$member['mb_level']}' ";
}
if (!$sst) {
$sst = "mb_datetime";
$sod = "desc";
}
$allowed_sst = array('mb_datetime', 'mb_id', 'mb_name', 'mb_nick', 'mb_level', 'mb_point', 'mb_today_login', 'mb_open', 'mb_mailling', 'mb_sms', 'mb_adult', 'mb_certify', 'mb_email_certify', 'mb_intercept_date', 'mb_leave_date');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'mb_datetime';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
@@ -43,7 +53,9 @@ $total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) $page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
if ($page < 1) {
$page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
}
$from_record = ($page - 1) * $rows; // 시작 열을 구함
// 탈퇴회원수
@@ -56,10 +68,10 @@ $sql = " select count(*) as cnt {$sql_common} {$sql_search} and mb_intercept_dat
$row = sql_fetch($sql);
$intercept_count = $row['cnt'];
$listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목록</a>';
$listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall">전체목록</a>';
$g5['title'] = '회원관리';
include_once('./admin.head.php');
require_once './admin.head.php';
$sql = " select * {$sql_common} {$sql_search} {$sql_order} limit {$from_record}, {$rows} ";
$result = sql_query($sql);
@@ -71,28 +83,28 @@ $colspan = 16;
<?php echo $listall ?>
<span class="btn_ov01"><span class="ov_txt">총회원수 </span><span class="ov_num"> <?php echo number_format($total_count) ?>명 </span></span>
<a href="?sst=mb_intercept_date&amp;sod=desc&amp;sfl=<?php echo $sfl ?>&amp;stx=<?php echo $stx ?>" class="btn_ov01" data-tooltip-text="차단된 순으로 정렬합니다.&#xa;전체 데이터를 출력합니다."> <span class="ov_txt">차단 </span><span class="ov_num"><?php echo number_format($intercept_count) ?>명</span></a>
<a href="?sst=mb_leave_date&amp;sod=desc&amp;sfl=<?php echo $sfl ?>&amp;stx=<?php echo $stx ?>" class="btn_ov01" data-tooltip-text="탈퇴된 순으로 정렬합니다.&#xa;전체 데이터를 출력합니다."> <span class="ov_txt">탈퇴 </span><span class="ov_num"><?php echo number_format($leave_count) ?>명</span></a>
<a href="?sst=mb_leave_date&amp;sod=desc&amp;sfl=<?php echo $sfl ?>&amp;stx=<?php echo $stx ?>" class="btn_ov01" data-tooltip-text="탈퇴된 순으로 정렬합니다.&#xa;전체 데이터를 출력합니다."> <span class="ov_txt">탈퇴 </span><span class="ov_num"><?php echo number_format($leave_count) ?>명</span></a>
</div>
<form id="fsearch" name="fsearch" class="local_sch01 local_sch" method="get">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="mb_id"<?php echo get_selected($sfl, "mb_id"); ?>>회원아이디</option>
<option value="mb_nick"<?php echo get_selected($sfl, "mb_nick"); ?>>닉네임</option>
<option value="mb_name"<?php echo get_selected($sfl, "mb_name"); ?>>이름</option>
<option value="mb_level"<?php echo get_selected($sfl, "mb_level"); ?>>권한</option>
<option value="mb_email"<?php echo get_selected($sfl, "mb_email"); ?>>E-MAIL</option>
<option value="mb_tel"<?php echo get_selected($sfl, "mb_tel"); ?>>전화번호</option>
<option value="mb_hp"<?php echo get_selected($sfl, "mb_hp"); ?>>휴대폰번호</option>
<option value="mb_point"<?php echo get_selected($sfl, "mb_point"); ?>>포인트</option>
<option value="mb_datetime"<?php echo get_selected($sfl, "mb_datetime"); ?>>가입일시</option>
<option value="mb_ip"<?php echo get_selected($sfl, "mb_ip"); ?>>IP</option>
<option value="mb_recommend"<?php echo get_selected($sfl, "mb_recommend"); ?>>추천인</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" class="btn_submit" value="검색">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="mb_id" <?php echo get_selected($sfl, "mb_id"); ?>>회원아이디</option>
<option value="mb_nick" <?php echo get_selected($sfl, "mb_nick"); ?>>닉네임</option>
<option value="mb_name" <?php echo get_selected($sfl, "mb_name"); ?>>이름</option>
<option value="mb_level" <?php echo get_selected($sfl, "mb_level"); ?>>권한</option>
<option value="mb_email" <?php echo get_selected($sfl, "mb_email"); ?>>E-MAIL</option>
<option value="mb_tel" <?php echo get_selected($sfl, "mb_tel"); ?>>전화번호</option>
<option value="mb_hp" <?php echo get_selected($sfl, "mb_hp"); ?>>휴대폰번호</option>
<option value="mb_point" <?php echo get_selected($sfl, "mb_point"); ?>>포인트</option>
<option value="mb_datetime" <?php echo get_selected($sfl, "mb_datetime"); ?>>가입일시</option>
<option value="mb_ip" <?php echo get_selected($sfl, "mb_ip"); ?>>IP</option>
<option value="mb_recommend" <?php echo get_selected($sfl, "mb_recommend"); ?>>추천인</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" class="btn_submit" value="검색">
</form>
@@ -104,230 +116,246 @@ $colspan = 16;
<form name="fmemberlist" id="fmemberlist" action="./member_list_update.php" onsubmit="return fmemberlist_submit(this);" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col" id="mb_list_chk" rowspan="2" >
<label for="chkall" class="sound_only">회원 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col" id="mb_list_id" colspan="2"><?php echo subject_sort_link('mb_id') ?>아이디</a></th>
<th scope="col" rowspan="2" id="mb_list_cert"><?php echo subject_sort_link('mb_certify', '', 'desc') ?>본인확인</a></th>
<th scope="col" id="mb_list_mailc"><?php echo subject_sort_link('mb_email_certify', '', 'desc') ?>메일인증</a></th>
<th scope="col" id="mb_list_open"><?php echo subject_sort_link('mb_open', '', 'desc') ?>정보공개</a></th>
<th scope="col" id="mb_list_mailr"><?php echo subject_sort_link('mb_mailling', '', 'desc') ?>메일수신</a></th>
<th scope="col" id="mb_list_auth">상태</th>
<th scope="col" id="mb_list_mobile">휴대폰</th>
<th scope="col" id="mb_list_lastcall"><?php echo subject_sort_link('mb_today_login', '', 'desc') ?>최종접속</a></th>
<th scope="col" id="mb_list_grp">접근그룹</th>
<th scope="col" rowspan="2" id="mb_list_mng">관리</th>
</tr>
<tr>
<th scope="col" id="mb_list_name"><?php echo subject_sort_link('mb_name') ?>이름</a></th>
<th scope="col" id="mb_list_nick"><?php echo subject_sort_link('mb_nick') ?>닉네임</a></th>
<th scope="col" id="mb_list_sms"><?php echo subject_sort_link('mb_sms', '', 'desc') ?>SMS수신</a></th>
<th scope="col" id="mb_list_adultc"><?php echo subject_sort_link('mb_adult', '', 'desc') ?>성인인증</a></th>
<th scope="col" id="mb_list_auth"><?php echo subject_sort_link('mb_intercept_date', '', 'desc') ?>접근차단</a></th>
<th scope="col" id="mb_list_deny"><?php echo subject_sort_link('mb_level', '', 'desc') ?>권한</a></th>
<th scope="col" id="mb_list_tel">전화번호</th>
<th scope="col" id="mb_list_join"><?php echo subject_sort_link('mb_datetime', '', 'desc') ?>가입일</a></th>
<th scope="col" id="mb_list_point"><?php echo subject_sort_link('mb_point', '', 'desc') ?> 포인트</a></th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++) {
// 접근가능한 그룹수
$sql2 = " select count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
$group = '';
if ($row2['cnt'])
$group = '<a href="./boardgroupmember_form.php?mb_id='.$row['mb_id'].'">'.$row2['cnt'].'</a>';
if ($is_admin == 'group') {
$s_mod = '';
} else {
$s_mod = '<a href="./member_form.php?'.$qstr.'&amp;w=u&amp;mb_id='.$row['mb_id'].'" class="btn btn_03">수정</a>';
}
$s_grp = '<a href="./boardgroupmember_form.php?mb_id='.$row['mb_id'].'" class="btn btn_02">그룹</a>';
$leave_date = $row['mb_leave_date'] ? $row['mb_leave_date'] : date('Ymd', G5_SERVER_TIME);
$intercept_date = $row['mb_intercept_date'] ? $row['mb_intercept_date'] : date('Ymd', G5_SERVER_TIME);
$mb_nick = get_sideview($row['mb_id'], get_text($row['mb_nick']), $row['mb_email'], $row['mb_homepage']);
$mb_id = $row['mb_id'];
$leave_msg = '';
$intercept_msg = '';
$intercept_title = '';
if ($row['mb_leave_date']) {
$mb_id = $mb_id;
$leave_msg = '<span class="mb_leave_msg">탈퇴함</span>';
}
else if ($row['mb_intercept_date']) {
$mb_id = $mb_id;
$intercept_msg = '<span class="mb_intercept_msg">차단됨</span>';
$intercept_title = '차단해제';
}
if ($intercept_title == '')
$intercept_title = '차단하기';
$address = $row['mb_zip1'] ? print_address($row['mb_addr1'], $row['mb_addr2'], $row['mb_addr3'], $row['mb_addr_jibeon']) : '';
$bg = 'bg'.($i%2);
switch($row['mb_certify']) {
case 'hp':
$mb_certify_case = '휴대폰';
$mb_certify_val = 'hp';
break;
case 'ipin':
$mb_certify_case = '아이핀';
$mb_certify_val = '';
break;
case 'admin':
$mb_certify_case = '관리자';
$mb_certify_val = 'admin';
break;
default:
$mb_certify_case = '&nbsp;';
$mb_certify_val = 'admin';
break;
}
?>
<tr class="<?php echo $bg; ?>">
<td headers="mb_list_chk" class="td_chk" rowspan="2">
<input type="hidden" name="mb_id[<?php echo $i ?>]" value="<?php echo $row['mb_id'] ?>" id="mb_id_<?php echo $i ?>">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo get_text($row['mb_name']); ?> <?php echo get_text($row['mb_nick']); ?>님</label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td headers="mb_list_id" colspan="2" class="td_name sv_use">
<?php echo $mb_id ?>
<?php
//소셜계정이 있다면
if(function_exists('social_login_link_account')){
if( $my_social_accounts = social_login_link_account($row['mb_id'], false, 'get_data') ){
echo '<div class="member_social_provider sns-wrap-over sns-wrap-32">';
foreach( (array) $my_social_accounts as $account){ //반복문
if( empty($account) || empty($account['provider']) ) continue;
$provider = strtolower($account['provider']);
$provider_name = social_get_provider_service_name($provider);
echo '<span class="sns-icon sns-'.$provider.'" title="'.$provider_name.'">';
echo '<span class="ico"></span>';
echo '<span class="txt">'.$provider_name.'</span>';
echo '</span>';
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col" id="mb_list_chk" rowspan="2">
<label for="chkall" class="sound_only">회원 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col" id="mb_list_id" colspan="2"><?php echo subject_sort_link('mb_id') ?>아이디</a></th>
<th scope="col" rowspan="2" id="mb_list_cert"><?php echo subject_sort_link('mb_certify', '', 'desc') ?>본인확인</a></th>
<th scope="col" id="mb_list_mailc"><?php echo subject_sort_link('mb_email_certify', '', 'desc') ?>메일인증</a></th>
<th scope="col" id="mb_list_open"><?php echo subject_sort_link('mb_open', '', 'desc') ?>정보공개</a></th>
<th scope="col" id="mb_list_mailr"><?php echo subject_sort_link('mb_mailling', '', 'desc') ?>광고성이메일</a></th>
<th scope="col" id="mb_list_auth">상태</th>
<th scope="col" id="mb_list_mobile">휴대폰</th>
<th scope="col" id="mb_list_lastcall"><?php echo subject_sort_link('mb_today_login', '', 'desc') ?>최종접속</a></th>
<th scope="col" id="mb_list_grp">접근그룹</th>
<th scope="col" rowspan="2" id="mb_list_mng">관리</th>
</tr>
<tr>
<th scope="col" id="mb_list_name"><?php echo subject_sort_link('mb_name') ?>이름</a></th>
<th scope="col" id="mb_list_nick"><?php echo subject_sort_link('mb_nick') ?>닉네임</a></th>
<th scope="col" id="mb_list_adultc"><?php echo subject_sort_link('mb_adult', '', 'desc') ?>성인인증</a></th>
<th scope="col" id="mb_list_auth"><?php echo subject_sort_link('mb_intercept_date', '', 'desc') ?>접근차단</a></th>
<th scope="col" id="mb_list_sms"><?php echo subject_sort_link('mb_sms', '', 'desc') ?>광고성SMS</a></th>
<th scope="col" id="mb_list_deny"><?php echo subject_sort_link('mb_level', '', 'desc') ?>권한</a></th>
<th scope="col" id="mb_list_tel">전화번호</th>
<th scope="col" id="mb_list_join"><?php echo subject_sort_link('mb_datetime', '', 'desc') ?>가입일</a></th>
<th scope="col" id="mb_list_point"><?php echo subject_sort_link('mb_point', '', 'desc') ?> 포인트</a></th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
// 접근가능한 그룹수
$sql2 = " select count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
$group = '';
if ($row2['cnt']) {
$group = '<a href="./boardgroupmember_form.php?mb_id=' . $row['mb_id'] . '">' . $row2['cnt'] . '</a>';
}
echo '</div>';
if ($is_admin == 'group') {
$s_mod = '';
} else {
$s_mod = '<a href="./member_form.php?' . $qstr . '&amp;w=u&amp;mb_id=' . $row['mb_id'] . '" class="btn btn_03">수정</a>';
}
$s_grp = '<a href="./boardgroupmember_form.php?mb_id=' . $row['mb_id'] . '" class="btn btn_02">그룹</a>';
$leave_date = $row['mb_leave_date'] ? $row['mb_leave_date'] : date('Ymd', G5_SERVER_TIME);
$intercept_date = $row['mb_intercept_date'] ? $row['mb_intercept_date'] : date('Ymd', G5_SERVER_TIME);
$mb_nick = get_sideview($row['mb_id'], get_text($row['mb_nick']), $row['mb_email'], $row['mb_homepage']);
$mb_id = $row['mb_id'];
$leave_msg = '';
$intercept_msg = '';
$intercept_title = '';
if ($row['mb_leave_date']) {
$mb_id = $mb_id;
$leave_msg = '<span class="mb_leave_msg">탈퇴함</span>';
} elseif ($row['mb_intercept_date']) {
$mb_id = $mb_id;
$intercept_msg = '<span class="mb_intercept_msg">차단됨</span>';
$intercept_title = '차단해제';
}
if ($intercept_title == '') {
$intercept_title = '차단하기';
}
$address = $row['mb_zip1'] ? print_address($row['mb_addr1'], $row['mb_addr2'], $row['mb_addr3'], $row['mb_addr_jibeon']) : '';
$bg = 'bg' . ($i % 2);
switch ($row['mb_certify']) {
case 'hp':
$mb_certify_case = '휴대폰';
$mb_certify_val = 'hp';
break;
case 'ipin':
$mb_certify_case = '아이핀';
$mb_certify_val = '';
break;
case 'simple':
$mb_certify_case = '간편인증';
$mb_certify_val = '';
break;
case 'admin':
$mb_certify_case = '관리자';
$mb_certify_val = 'admin';
break;
default:
$mb_certify_case = '&nbsp;';
$mb_certify_val = 'admin';
break;
}
?>
<tr class="<?php echo $bg; ?>">
<td headers="mb_list_chk" class="td_chk" rowspan="2">
<input type="hidden" name="mb_id[<?php echo $i ?>]" value="<?php echo $row['mb_id'] ?>" id="mb_id_<?php echo $i ?>">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo get_text($row['mb_name']); ?> <?php echo get_text($row['mb_nick']); ?>님</label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td headers="mb_list_id" colspan="2" class="td_name sv_use">
<?php echo $mb_id ?>
<?php
//소셜계정이 있다면
if (function_exists('social_login_link_account')) {
if ($my_social_accounts = social_login_link_account($row['mb_id'], false, 'get_data')) {
echo '<div class="member_social_provider sns-wrap-over sns-wrap-32">';
foreach ((array) $my_social_accounts as $account) { //반복문
if (empty($account) || empty($account['provider'])) {
continue;
}
$provider = strtolower($account['provider']);
$provider_name = social_get_provider_service_name($provider);
echo '<span class="sns-icon sns-' . $provider . '" title="' . $provider_name . '">';
echo '<span class="ico"></span>';
echo '<span class="txt">' . $provider_name . '</span>';
echo '</span>';
}
echo '</div>';
}
}
?>
</td>
<td headers="mb_list_cert" rowspan="2" class="td_mbcert">
<input type="radio" name="mb_certify[<?php echo $i; ?>]" value="simple" id="mb_certify_sa_<?php echo $i; ?>" <?php echo $row['mb_certify'] == 'simple' ? 'checked' : ''; ?>>
<label for="mb_certify_sa_<?php echo $i; ?>">간편인증</label><br>
<input type="radio" name="mb_certify[<?php echo $i; ?>]" value="hp" id="mb_certify_hp_<?php echo $i; ?>" <?php echo $row['mb_certify'] == 'hp' ? 'checked' : ''; ?>>
<label for="mb_certify_hp_<?php echo $i; ?>">휴대폰</label><br>
<input type="radio" name="mb_certify[<?php echo $i; ?>]" value="ipin" id="mb_certify_ipin_<?php echo $i; ?>" <?php echo $row['mb_certify'] == 'ipin' ? 'checked' : ''; ?>>
<label for="mb_certify_ipin_<?php echo $i; ?>">아이핀</label>
</td>
<td headers="mb_list_mailc" class="td_consent"><?php echo preg_match('/[1-9]/', $row['mb_email_certify']) ? '<span class="txt_true">Yes</span>' : '<span class="txt_false">No</span>'; ?></td>
<td headers="mb_list_open" class="td_consent">
<label for="mb_open_<?php echo $i; ?>" class="sound_only">정보공개</label>
<input type="checkbox" name="mb_open[<?php echo $i; ?>]" <?php echo $row['mb_open'] ? 'checked' : ''; ?> value="1" id="mb_open_<?php echo $i; ?>">
</td>
<td headers="mb_list_mailr" class="td_consent">
<label for="mb_mailling_<?php echo $i; ?>" class="sound_only">광고성이메일수신</label>
<input type="checkbox" name="mb_mailling[<?php echo $i; ?>]" <?php echo $row['mb_mailling'] ? 'checked' : ''; ?> value="1" id="mb_mailling_<?php echo $i; ?>">
<input type="hidden" name="mb_mailling_default[<?php echo $i; ?>]" value="<?php echo isset($row['mb_mailling']) ? $row['mb_mailling'] : '0'; ?> " id="mb_mailling_default_<?php echo $i; ?>">
</td>
<td headers="mb_list_auth" class="td_mbstat">
<?php
if ($leave_msg || $intercept_msg) {
echo $leave_msg . ' ' . $intercept_msg;
} else if ($config['cf_use_email_certify'] && !preg_match('/[1-9]/', $row['mb_email_certify'])) {
echo '<span class="txt_false">메일 미인증</span>';
} else {
echo "정상";
}
?>
</td>
<td headers="mb_list_mobile" class="td_tel"><?php echo get_text($row['mb_hp']); ?></td>
<td headers="mb_list_lastcall" class="td_date"><?php echo substr($row['mb_today_login'], 2, 8); ?></td>
<td headers="mb_list_grp" class="td_numsmall"><?php echo $group ?></td>
<td headers="mb_list_mng" rowspan="2" class="td_mng td_mng_s"><?php echo $s_mod ?><?php echo $s_grp ?></td>
</tr>
<tr class="<?php echo $bg; ?>">
<td headers="mb_list_name" class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td headers="mb_list_nick" class="td_name sv_use">
<div><?php echo $mb_nick ?></div>
</td>
<td headers="mb_list_adultc">
<label for="mb_adult_<?php echo $i; ?>" class="sound_only">성인인증</label>
<input type="checkbox" name="mb_adult[<?php echo $i; ?>]" <?php echo $row['mb_adult'] ? 'checked' : ''; ?> value="1" id="mb_adult_<?php echo $i; ?>">
</td>
<td headers="mb_list_deny">
<?php if (empty($row['mb_leave_date'])) { ?>
<input type="checkbox" name="mb_intercept_date[<?php echo $i; ?>]" <?php echo $row['mb_intercept_date'] ? 'checked' : ''; ?> value="<?php echo $intercept_date ?>" id="mb_intercept_date_<?php echo $i ?>" title="<?php echo $intercept_title ?>">
<label for="mb_intercept_date_<?php echo $i; ?>" class="sound_only">접근차단</label>
<?php } ?>
</td>
<td headers="mb_list_sms">
<label for="mb_sms_<?php echo $i; ?>" class="sound_only">광고성SMS/카카오톡수신</label>
<input type="checkbox" name="mb_sms[<?php echo $i; ?>]" <?php echo $row['mb_sms'] ? 'checked' : ''; ?> value="1" id="mb_sms_<?php echo $i; ?>">
<input type="hidden" name="mb_sms_default[<?php echo $i; ?>]" value="<?php echo isset($row['mb_sms']) ? $row['mb_sms'] : '0'; ?> " id="mb_sms_default_<?php echo $i; ?>">
</td>
<td headers="mb_list_auth" class="td_mbstat">
<?php echo get_member_level_select("mb_level[$i]", 1, $member['mb_level'], $row['mb_level']) ?>
</td>
<td headers="mb_list_tel" class="td_tel"><?php echo get_text($row['mb_tel']); ?></td>
<td headers="mb_list_join" class="td_date"><?php echo substr($row['mb_datetime'], 2, 8); ?></td>
<td headers="mb_list_point" class="td_num"><a href="point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo number_format($row['mb_point']) ?></a></td>
</tr>
<?php
}
}
?>
</td>
<td headers="mb_list_cert" rowspan="2" class="td_mbcert">
<input type="radio" name="mb_certify[<?php echo $i; ?>]" value="ipin" id="mb_certify_ipin_<?php echo $i; ?>" <?php echo $row['mb_certify']=='ipin'?'checked':''; ?>>
<label for="mb_certify_ipin_<?php echo $i; ?>">아이핀</label><br>
<input type="radio" name="mb_certify[<?php echo $i; ?>]" value="hp" id="mb_certify_hp_<?php echo $i; ?>" <?php echo $row['mb_certify']=='hp'?'checked':''; ?>>
<label for="mb_certify_hp_<?php echo $i; ?>">휴대폰</label>
</td>
<td headers="mb_list_mailc"><?php echo preg_match('/[1-9]/', $row['mb_email_certify'])?'<span class="txt_true">Yes</span>':'<span class="txt_false">No</span>'; ?></td>
<td headers="mb_list_open">
<label for="mb_open_<?php echo $i; ?>" class="sound_only">정보공개</label>
<input type="checkbox" name="mb_open[<?php echo $i; ?>]" <?php echo $row['mb_open']?'checked':''; ?> value="1" id="mb_open_<?php echo $i; ?>">
</td>
<td headers="mb_list_mailr">
<label for="mb_mailling_<?php echo $i; ?>" class="sound_only">메일수신</label>
<input type="checkbox" name="mb_mailling[<?php echo $i; ?>]" <?php echo $row['mb_mailling']?'checked':''; ?> value="1" id="mb_mailling_<?php echo $i; ?>">
</td>
<td headers="mb_list_auth" class="td_mbstat">
<?php
if ($leave_msg || $intercept_msg) echo $leave_msg.' '.$intercept_msg;
else echo "정상";
?>
</td>
<td headers="mb_list_mobile" class="td_tel"><?php echo get_text($row['mb_hp']); ?></td>
<td headers="mb_list_lastcall" class="td_date"><?php echo substr($row['mb_today_login'],2,8); ?></td>
<td headers="mb_list_grp" class="td_numsmall"><?php echo $group ?></td>
<td headers="mb_list_mng" rowspan="2" class="td_mng td_mng_s"><?php echo $s_mod ?><?php echo $s_grp ?></td>
</tr>
<tr class="<?php echo $bg; ?>">
<td headers="mb_list_name" class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td headers="mb_list_nick" class="td_name sv_use"><div><?php echo $mb_nick ?></div></td>
<td headers="mb_list_sms">
<label for="mb_sms_<?php echo $i; ?>" class="sound_only">SMS수신</label>
<input type="checkbox" name="mb_sms[<?php echo $i; ?>]" <?php echo $row['mb_sms']?'checked':''; ?> value="1" id="mb_sms_<?php echo $i; ?>">
</td>
<td headers="mb_list_adultc">
<label for="mb_adult_<?php echo $i; ?>" class="sound_only">성인인증</label>
<input type="checkbox" name="mb_adult[<?php echo $i; ?>]" <?php echo $row['mb_adult']?'checked':''; ?> value="1" id="mb_adult_<?php echo $i; ?>">
</td>
<td headers="mb_list_deny">
<?php if(empty($row['mb_leave_date'])){ ?>
<input type="checkbox" name="mb_intercept_date[<?php echo $i; ?>]" <?php echo $row['mb_intercept_date']?'checked':''; ?> value="<?php echo $intercept_date ?>" id="mb_intercept_date_<?php echo $i ?>" title="<?php echo $intercept_title ?>">
<label for="mb_intercept_date_<?php echo $i; ?>" class="sound_only">접근차단</label>
<?php } ?>
</td>
<td headers="mb_list_auth" class="td_mbstat">
<?php echo get_member_level_select("mb_level[$i]", 1, $member['mb_level'], $row['mb_level']) ?>
</td>
<td headers="mb_list_tel" class="td_tel"><?php echo get_text($row['mb_tel']); ?></td>
<td headers="mb_list_join" class="td_date"><?php echo substr($row['mb_datetime'],2,8); ?></td>
<td headers="mb_list_point" class="td_num"><a href="point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo number_format($row['mb_point']) ?></a></td>
if ($i == 0) {
echo "<tr><td colspan=\"" . $colspan . "\" class=\"empty_table\">자료가 없습니다.</td></tr>";
}
?>
</tbody>
</table>
</div>
</tr>
<div class="btn_fixed_top">
<input type="submit" name="act_button" value="선택수정" onclick="document.pressed=this.value" class="btn btn_02">
<input type="submit" name="act_button" value="선택삭제" onclick="document.pressed=this.value" class="btn btn_02">
<?php if ($is_admin == 'super') { ?>
<a href="./member_form.php" id="member_add" class="btn btn_01">회원추가</a>
<?php } ?>
<?php
}
if ($i == 0)
echo "<tr><td colspan=\"".$colspan."\" class=\"empty_table\">자료가 없습니다.</td></tr>";
?>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<input type="submit" name="act_button" value="선택수정" onclick="document.pressed=this.value" class="btn btn_02">
<input type="submit" name="act_button" value="선택삭제" onclick="document.pressed=this.value" class="btn btn_02">
<?php if ($is_admin == 'super') { ?>
<a href="./member_form.php" id="member_add" class="btn btn_01">회원추가</a>
<?php } ?>
</div>
</div>
</form>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, '?'.$qstr.'&amp;page='); ?>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, '?' . $qstr . '&amp;page='); ?>
<script>
function fmemberlist_submit(f)
{
if (!is_checked("chk[]")) {
alert(document.pressed+" 하실 항목을 하나 이상 선택하세요.");
return false;
}
if(document.pressed == "선택삭제") {
if(!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
function fmemberlist_submit(f) {
if (!is_checked("chk[]")) {
alert(document.pressed + " 하실 항목을 하나 이상 선택하세요.");
return false;
}
}
return true;
}
if (document.pressed == "선택삭제") {
if (!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
return false;
}
}
return true;
}
</script>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+8 -8
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = "200100";
include_once("./_common.php");
require_once "./_common.php";
check_demo();
@@ -9,8 +9,7 @@ auth_check_menu($auth, $sub_menu, "d");
check_admin_token();
$msg = "";
for ($i=0; $i<count($chk); $i++)
{
for ($i = 0; $i < count($chk); $i++) {
// 실제 번호를 넘김
$k = $_POST['chk'][$i];
@@ -18,11 +17,11 @@ for ($i=0; $i<count($chk); $i++)
if (!$mb['mb_id']) {
$msg .= "{$mb['mb_id']} : 회원자료가 존재하지 않습니다.\\n";
} else if ($member['mb_id'] == $mb['mb_id']) {
} elseif ($member['mb_id'] == $mb['mb_id']) {
$msg .= "{$mb['mb_id']} : 로그인 중인 관리자는 삭제 할 수 없습니다.\\n";
} else if (is_admin($mb['mb_id']) == "super") {
} elseif (is_admin($mb['mb_id']) == "super") {
$msg .= "{$mb['mb_id']} : 최고 관리자는 삭제할 수 없습니다.\\n";
} else if ($is_admin != "super" && $mb['mb_level'] >= $member['mb_level']) {
} elseif ($is_admin != "super" && $mb['mb_level'] >= $member['mb_level']) {
$msg .= "{$mb['mb_id']} : 자신보다 권한이 높거나 같은 회원은 삭제할 수 없습니다.\\n";
} else {
// 회원자료 삭제
@@ -30,7 +29,8 @@ for ($i=0; $i<count($chk); $i++)
}
}
if ($msg)
if ($msg) {
echo "<script type='text/javascript'> alert('$msg'); </script>";
}
goto_url("./member_list.php?$qstr");
goto_url("./member_list.php?$qstr");
+285
View File
@@ -0,0 +1,285 @@
<?php
/*************************************************************************
**
** 내보내기 관련 상수 정의
**
*************************************************************************/
define('MEMBER_EXPORT_PAGE_SIZE', 10000); // 파일당 처리할 회원 수
define('MEMBER_EXPORT_MAX_SIZE', 300000); // 최대 처리할 회원 수
define('MEMBER_BASE_DIR', "member_list"); // 엑셀 베이스 폴더
// 폴더/파일명용 날짜 - 저장 경로가 추측되지 않도록 임의 문자열을 덧붙인다.
define('MEMBER_BASE_SALT', function_exists('get_random_token_string') ? get_random_token_string(8) : substr(md5(uniqid(mt_rand(), true)), 0, 8));
define('MEMBER_BASE_DATE', date('YmdHis') . '_' . MEMBER_BASE_SALT);
define('MEMBER_EXPORT_DIR', G5_DATA_PATH . "/" . MEMBER_BASE_DIR . "/" . MEMBER_BASE_DATE); // 엑셀 파일 저장 경로
define('MEMBER_LOG_DIR', G5_DATA_PATH . "/" . MEMBER_BASE_DIR . "/" . "log"); // 로그 파일 저장 경로
/*************************************************************************
**
** 공통 함수 정의
**
*************************************************************************/
/**
* 검색 옵션 설정
*/
function get_export_config($type = null)
{
$config = array(
'sfl_list' => array(
'mb_id'=>'아이디',
'mb_name'=>'이름',
'mb_nick'=>'닉네임',
'mb_email'=>'이메일',
'mb_tel'=>'전화번호',
'mb_hp'=>'휴대폰번호',
'mb_addr1'=>'주소'
),
'point_cond_map' => array(
'gte'=>'≥',
'lte'=>'≤',
'eq'=>'='
),
'intercept_list' => array(
'exclude'=>'차단회원 제외',
'only'=>'차단회원만'
),
'ad_range_list' => array(
'all' => '수신동의 회원 전체',
'mailling_only' => '이메일 수신동의 회원만',
'sms_only' => 'SMS/카카오톡 수신동의 회원만',
'month_confirm' => date('m월').' 수신동의 확인 대상만',
'custom_period' => '수신동의 기간 직접 입력'
),
);
return $type ? (isset($config[$type]) ? $config[$type] : array()) : $config;
}
/**
* 파라미터 수집 및 유효성 검사
*/
function get_member_export_params()
{
$params = array(
'page' => 1,
'use_stx' => isset($_GET['use_stx']) ? $_GET['use_stx'] : 0,
'stx_cond' => clean_xss_tags(isset($_GET['stx_cond']) ? $_GET['stx_cond'] : 'like'),
'sfl' => clean_xss_tags(isset($_GET['sfl']) ? $_GET['sfl'] : ''),
'stx' => clean_xss_tags(isset($_GET['stx']) ? $_GET['stx'] : ''),
'use_level' => isset($_GET['use_level']) ? $_GET['use_level'] : 0,
'level_start' => (int)(isset($_GET['level_start']) ? $_GET['level_start'] : 1),
'level_end' => (int)(isset($_GET['level_end']) ? $_GET['level_end'] : 10),
'use_date' => isset($_GET['use_date']) ? $_GET['use_date'] : 0,
'date_start' => clean_xss_tags(isset($_GET['date_start']) ? $_GET['date_start'] : ''),
'date_end' => clean_xss_tags(isset($_GET['date_end']) ? $_GET['date_end'] : ''),
'use_point' => isset($_GET['use_point']) ? $_GET['use_point'] : 0,
'point' => isset($_GET['point']) ? $_GET['point'] : '',
'point_cond' => isset($_GET['point_cond']) ? $_GET['point_cond'] : 'gte',
'use_hp_exist' => isset($_GET['use_hp_exist']) ? $_GET['use_hp_exist'] : 0,
'ad_range_only' => isset($_GET['ad_range_only']) ? $_GET['ad_range_only'] : 0,
'ad_range_type' => clean_xss_tags(isset($_GET['ad_range_type']) ? $_GET['ad_range_type'] : 'all'),
'ad_mailling' => isset($_GET['ad_mailling']) ? $_GET['ad_mailling'] : 0,
'ad_sms' => isset($_GET['ad_sms']) ? $_GET['ad_sms'] : 0,
'agree_date_start' => clean_xss_tags(isset($_GET['agree_date_start']) ? $_GET['agree_date_start'] : ''),
'agree_date_end' => clean_xss_tags(isset($_GET['agree_date_end']) ? $_GET['agree_date_end'] : ''),
'use_intercept' => isset($_GET['use_intercept']) ? $_GET['use_intercept'] : 0,
'intercept' => clean_xss_tags(isset($_GET['intercept']) ? $_GET['intercept'] : 'exclude'),
);
// 레벨 범위 검증
if ($params['level_start'] > $params['level_end']) {
$tmp_level = $params['level_start'];
$params['level_start'] = $params['level_end'];
$params['level_end'] = $tmp_level;
}
// 가입기간 - 날짜 범위 검증
if ($params['use_date'] && $params['date_start'] && $params['date_end']) {
if ($params['date_start'] > $params['date_end']) {
$tmp_date = $params['date_start'];
$params['date_start'] = $params['date_end'];
$params['date_end'] = $tmp_date;
}
}
// 수신동의기간 - 날짜 범위 검증
if ($params['ad_range_type'] == 'custom_period' && $params['agree_date_start'] && $params['agree_date_end']) {
if ($params['agree_date_start'] > $params['agree_date_end']) {
$tmp_agree_date = $params['agree_date_start'];
$params['agree_date_start'] = $params['agree_date_end'];
$params['agree_date_end'] = $tmp_agree_date;
}
}
return $params;
}
/**
* 전체 데이터 개수 조회
*/
function member_export_get_total_count($params)
{
global $g5;
$where = member_export_build_where($params);
$sql = "SELECT COUNT(*) as cnt FROM {$g5['member_table']} {$where}";
$result = sql_query($sql);
if (!$result) {
throw new Exception("데이터 조회에 실패하였습니다. 다시 시도해주세요.");
}
$row = sql_fetch_array($result);
return (int)$row['cnt'];
}
/**
* WHERE 조건절 생성
*/
function member_export_build_where($params)
{
global $config;
$conditions = array();
// 기본 조건 - 탈퇴하지 않은 사용자
$conditions[] = "mb_leave_date = ''";
// 검색어 조건 (sql_escape_string 사용으로 보안 강화)
if (!empty($params['use_stx']) && $params['use_stx'] === '1') {
$sfl_list = get_export_config('sfl_list');
$sfl = in_array($params['sfl'], array_keys($sfl_list)) ? $params['sfl'] : '';
$stx = sql_escape_string($params['stx']);
if(!empty($sfl) && !empty($stx)){
if ($params['stx_cond'] === 'like') {
$conditions[] = "{$sfl} LIKE '%{$stx}%'";
} else {
$conditions[] = "{$sfl} = '{$stx}'";
}
}
}
// 권한 조건
if (!empty($params['use_level']) && $params['use_level'] === '1') {
$level_start = max(1, (int)$params['level_start']);
$level_end = min(10, (int)$params['level_end']);
$conditions[] = "(mb_level BETWEEN {$level_start} AND {$level_end})";
}
// 가입기간 조건
if (!empty($params['use_date']) && $params['use_date'] === '1') {
$date_start = isset($params['date_start']) ? sql_escape_string(trim($params['date_start'])) : '';
$date_end = isset($params['date_end']) ? sql_escape_string(trim($params['date_end'])) : '';
if ($date_start && $date_end) {
$conditions[] = "mb_datetime BETWEEN '{$date_start} 00:00:00' AND '{$date_end} 23:59:59'";
} elseif ($date_start) {
$conditions[] = "mb_datetime >= '{$date_start} 00:00:00'";
} elseif ($date_end) {
$conditions[] = "mb_datetime <= '{$date_end} 23:59:59'";
}
}
// 포인트 조건
if (!empty($params['use_point']) && $params['use_point'] === '1') {
$point = $params['point'];
$point_cond = $params['point_cond'];
if ($point != '') {
$point = (int)$point; // 정수로 캐스팅
switch ($point_cond) {
case 'lte':
$conditions[] = "mb_point <= {$point}";
break;
case 'eq':
$conditions[] = "mb_point = {$point}";
break;
default:
$conditions[] = "mb_point >= {$point}";
break;
}
}
}
// 휴대폰 번호 존재 조건
if (!empty($params['use_hp_exist']) && $params['use_hp_exist'] === '1') {
$conditions[] = "(mb_hp is not null and mb_hp != '')";
}
// 정보수신동의 조건
if (!empty($params['ad_range_only']) && $params['ad_range_only'] === '1') {
$range = isset($params['ad_range_type']) ? $params['ad_range_type'] : '';
// 공통: 마케팅 목적 수집·이용 동의 + (필요 시) 제3자 동의
$thirdparty_clause = $config['cf_sms_use'] !== '' ? " AND mb_thirdparty_agree = 1" : "";
$base_marketing = "mb_marketing_agree = 1{$thirdparty_clause}";
if ($range === 'all') {
// 마케팅 동의 + (이메일 OR SMS 동의)
$conditions[] = "({$base_marketing} AND (mb_mailling = 1 OR mb_sms = 1))";
} elseif ($range === 'mailling_only') {
// 마케팅 동의 + 이메일 동의
$conditions[] = "({$base_marketing} AND mb_mailling = 1)";
} elseif ($range === 'sms_only') {
// 마케팅 동의 + SMS/카카오톡 동의
$conditions[] = "({$base_marketing} AND mb_sms = 1)";
} elseif ($range === 'month_confirm' || $range === 'custom_period') {
// 채널 필터 체크
$useEmail = !empty($params['ad_mailling']);
$useSms = !empty($params['ad_sms']);
if ($range === 'month_confirm') {
// 23개월 전 그 달
$start = date('Y-m-01 00:00:00', strtotime('-23 months'));
$end = date('Y-m-t 23:59:59', strtotime('-23 months'));
$emailDateCond = "mb_mailling_date BETWEEN '{$start}' AND '{$end}'";
$smsDateCond = "mb_sms_date BETWEEN '{$start}' AND '{$end}'";
} else {
// 수신동의기간 직접 입력 - custom_period
$date_start = isset($params['agree_date_start']) ? sql_escape_string(trim($params['agree_date_start'])) : '';
$date_end = isset($params['agree_date_end']) ? sql_escape_string(trim($params['agree_date_end'])) : '';
if ($date_start && $date_end) {
$emailDateCond = "mb_mailling_date BETWEEN '{$date_start} 00:00:00' AND '{$date_end} 23:59:59'";
$smsDateCond = "mb_sms_date BETWEEN '{$date_start} 00:00:00' AND '{$date_end} 23:59:59'";
} elseif ($date_start) {
$emailDateCond = "mb_mailling_date >= '{$date_start} 00:00:00'";
$smsDateCond = "mb_sms_date >= '{$date_start} 00:00:00'";
} elseif ($date_end) {
$emailDateCond = "mb_mailling_date <= '{$date_end} 23:59:59'";
$smsDateCond = "mb_sms_date <= '{$date_end} 23:59:59'";
} else {
$emailDateCond = "mb_mailling_date <> '0000-00-00 00:00:00'";
$smsDateCond = "mb_sms_date <> '0000-00-00 00:00:00'";
}
}
if (!$useEmail && !$useSms) {
$conditions[] = "0=1"; // 둘 다 해제 ⇒ 결과 0건
} else {
// 조건 조립
$parts = array();
if ($useEmail) $parts[] = "(mb_mailling = 1 AND {$emailDateCond})";
if ($useSms) $parts[] = "(mb_sms = 1 AND {$smsDateCond})";
$conditions[] = !empty($parts) ? '(' . implode(' OR ', $parts) . ')' : '';
}
}
}
// 차단 회원 조건
if (!empty($params['use_intercept']) && $params['use_intercept'] === '1') {
switch ($params['intercept']) {
case 'exclude':
$conditions[] = "mb_intercept_date = ''";
break;
case 'only':
$conditions[] = "mb_intercept_date != ''";
break;
}
}
return empty($conditions) ? '' : 'WHERE ' . implode(' AND ', $conditions);
}
+457
View File
@@ -0,0 +1,457 @@
<?php
$sub_menu = "200400";
require_once './_common.php';
require_once './member_list_exel.lib.php'; // 회원관리파일 공통 라이브러리
auth_check_menu($auth, $sub_menu, 'r');
// 파라미터 수집 및 유효성 검사
$params = get_member_export_params();
// 총건수
$total_count = 0;
$total_error = "";
try {
$total_count = member_export_get_total_count($params);
} catch (Exception $e) {
$total_error = $e->getMessage(); // 메서드 호출 괄호 필수
}
$g5['title'] = '회원관리파일';
require_once './admin.head.php';
$colspan = 14;
?>
<h2>회원 엑셀 생성</h2>
<div class="local_desc01 local_desc">
<p><b>회원수 <?php echo number_format(MEMBER_EXPORT_PAGE_SIZE);?>건 초과 시</b> <?php echo number_format(MEMBER_EXPORT_PAGE_SIZE);?>건 단위로 분리 저장되며, <b>엑셀 생성 최대 건수는 <?php echo number_format(MEMBER_EXPORT_MAX_SIZE);?>건</b>입니다. 초과 시 조건 추가 설정 후 재시도하시기 바랍니다.</p>
<p><b>수신동의 확인 대상은 만료일까지 1달 미만인 회원</b>을 기준으로 필터링됩니다.</p>
<br>
<p>파일 생성 시 서버에 임시 생성된 파일 중 <b>오늘 날짜를 제외 한 파일은 자동 삭제</b>되며, 수동 삭제 필요 시 <a href="<?php echo G5_ADMIN_URL;?>/member_list_file_delete.php"><b>회원관리파일 일괄삭제</b></a>에서 진행하시기 바랍니다.</p>
<p>회원 정보 수정은 <a href="<?php echo G5_ADMIN_URL;?>/member_list.php" class="link"><b>회원 관리</b></a>에서 진행하실 수 있습니다.</p>
</div>
<div class="local_ov01 local_ov">
<span class="btn_ov01">
<span class="ov_txt">총건수 </span>
<?php if($total_error != "") { ?>
<span class="ov_num"> <?php echo $total_error ?></span>
<?php } else {?>
<span class="ov_num"> <?php echo number_format($total_count) ?>건</span>
<?php } ?>
</span>
</div>
<!-- 회원 검색 필터링 폼 -->
<form id="fsearch" name="fsearch" class="member_list_data" method="get">
<input type="hidden" name="token" value="<?php echo get_token(); ?>">
<fieldset>
<legend class="sound_only">회원 검색 필터링</legend>
<div class="sch_table">
<!-- 검색어 적용 -->
<div class="sch_row">
<div class="label">
<label>
<input type="checkbox" name="use_stx" value="1" <?php echo isset($_GET['use_stx']) ? 'checked' : ''; ?>>
검색어 적용
</label>
</div>
<div class="field">
<select name="sfl">
<?php
// 검색어 옵션 : [정의] get_export_config() - adm/member_list_exel.lib.php;
foreach (get_export_config('sfl_list') as $val => $label) {
$selected = (isset($_GET['sfl']) && $_GET['sfl'] === $val) ? 'selected' : '';
echo "<option value=\"$val\" $selected>$label</option>";
}
?>
</select>
<input type="text" name="stx" value="<?php echo htmlspecialchars(isset($_GET['stx']) ? $_GET['stx'] : ''); ?>" placeholder="검색어 입력">
<span class="radio_group">
<label><input type="radio" name="stx_cond" value="like" <?php echo (isset($_GET['stx_cond']) ? $_GET['stx_cond'] : 'like') === 'like' ? 'checked' : ''; ?>> 포함</label>
<label><input type="radio" name="stx_cond" value="equal" <?php echo (isset($_GET['stx_cond']) ? $_GET['stx_cond'] : '') === 'equal' ? 'checked' : ''; ?>> 일치</label>
</span>
</div>
</div>
<!-- 레벨 적용 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="use_level" value="1" <?php echo isset($_GET['use_level']) ? 'checked' : ''; ?>> 레벨 적용</label>
</div>
<div class="field">
<select name="level_start">
<?php for ($i = 1; $i <= 10; $i++): ?>
<option value="<?php echo $i; ?>" <?php echo (isset($_GET['level_start']) && $_GET['level_start'] == $i) ? 'selected' : ''; ?>><?php echo $i; ?></option>
<?php endfor; ?>
</select> ~
<select name="level_end">
<?php for ($i = 1; $i <= 10; $i++): ?>
<option value="<?php echo $i; ?>" <?php echo (isset($_GET['level_end']) && $_GET['level_end'] == $i) ? 'selected' : ''; ?>><?php echo $i; ?></option>
<?php endfor; ?>
</select>
</div>
</div>
<!-- 가입기간 적용 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="use_date" value="1" <?php echo isset($_GET['use_date']) ? 'checked' : ''; ?>> 가입기간 적용</label>
</div>
<div class="field">
<input type="date" name="date_start" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['date_start']) ? $_GET['date_start'] : ''); ?>"> ~
<input type="date" name="date_end" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['date_end']) ? $_GET['date_end'] : ''); ?>">
</div>
</div>
<!-- 포인트 적용 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="use_point" value="1" <?php echo isset($_GET['use_point']) ? 'checked' : ''; ?>> 포인트 적용</label>
</div>
<div class="field">
<input type="number" name="point" value="<?php echo htmlspecialchars(isset($_GET['point']) ? $_GET['point'] : ''); ?>" placeholder="포인트 입력">
<span class="radio_group">
<label><input type="radio" name="point_cond" value="gte" <?php echo (isset($_GET['point_cond']) ? $_GET['point_cond'] : 'gte') === 'gte' ? 'checked' : ''; ?>> 이상</label>
<label><input type="radio" name="point_cond" value="lte" <?php echo (isset($_GET['point_cond']) ? $_GET['point_cond'] : '') === 'lte' ? 'checked' : ''; ?>> 이하</label>
<label><input type="radio" name="point_cond" value="eq" <?php echo (isset($_GET['point_cond']) ? $_GET['point_cond'] : '') === 'eq' ? 'checked' : ''; ?>> 일치</label>
</span>
</div>
</div>
<!-- 차단회원 조건 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="use_intercept" value="1" <?php echo isset($_GET['use_intercept']) ? 'checked' : ''; ?>> 차단회원</label>
</div>
<div class="field">
<select name="intercept" id="intercept">
<?php
// 차단회원 옵션 : [정의] get_export_config() - adm/member_list_exel.lib.php
foreach (get_export_config('intercept_list') as $val => $label) {
$selected = ((isset($_GET['intercept']) ? $_GET['intercept'] : '') === $val) ? 'selected' : '';
echo "<option value=\"$val\" $selected>$label</option>";
}
?>
</select>
</div>
</div>
<!-- 휴대폰 번호 조건 - 초기세팅(설정에 휴대폰번호가 보이기/필수입력이면 기본값 checked로 설정) -->
<div class="sch_row">
<div class="label">
<label>
<?php $use_hp_checked = isset($_GET['token']) ? (isset($_GET['use_hp_exist']) ? 'checked' : '') : (($config['cf_use_hp'] || $config['cf_req_hp']) ? 'checked' : '');?>
<input type="checkbox" name="use_hp_exist" value="1" <?php echo $use_hp_checked; ?>> 휴대폰 번호 있는 경우만
</label>
</div>
</div>
<!-- 정보수신동의 조건 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="ad_range_only" value="1" <?php echo isset($_GET['ad_range_only']) ? 'checked' : ''; ?>> 정보수신동의에 동의한 경우만</label>
</div>
<!-- 안내 문구 -->
<div class="field">
<p class="sch_notice">「정보통신망이용촉진및정보보호등에관한법률」에 따라 <b>광고성 정보 수신동의 여부</b>를 <b>매2년</b>마다 확인해야 합니다.</p>
</div>
</div>
<div class="sch_row <?php echo isset($_GET['ad_range_only']) ? '' : 'is-hidden'; ?>">
<div class="ad_range_wrap">
<div class="ad_range_box">
<div class="label">
<label for="ad_range_type">회원범위</label>
</div>
<div class="field">
<select name="ad_range_type" id="ad_range_type">
<?php
foreach (get_export_config('ad_range_list') as $val => $label) {
$selected = ((isset($_GET['ad_range_type']) ? $_GET['ad_range_type'] : '') === $val) ? 'selected' : '';
echo "<option value=\"$val\" $selected>$label</option>";
}
?>
</select>
<div class="ad_range_wrap">
<!-- 기간 직접 입력 -->
<div class="ad_range_box <?php echo isset($_GET['ad_range_only']) && (isset($_GET['ad_range_type']) ? $_GET['ad_range_type'] : '') == 'custom_period' ? '' : 'is-hidden'; ?>">
<div class="field">
<input type="date" name="agree_date_start" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['agree_date_start']) ? $_GET['agree_date_start'] : date('Y-m-d', strtotime('-1 month'))); ?>"> ~
<input type="date" name="agree_date_end" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['agree_date_end']) ? $_GET['agree_date_end'] : date('Y-m-d')); ?>">
<p>* 광고성 정보 수신(<b>이메일 또는 SMS/카카오톡</b>) 동의일자 기준</p>
</div>
</div>
<!-- 설명 문구 -->
<?php
$thirdpartyLbl = (!empty($config['cf_sms_use'])) ? ' / <b>개인정보 제3자 제공</b>' : '';
$ad_range_text = array(
'all' => "* <b>광고성 정보 수신(이메일 또는 SMS/카카오톡)</b> / <b>마케팅 목적의 개인정보 수집 및 이용</b>{$thirdpartyLbl}에 모두 동의한 회원을 선택합니다.",
'mailling_only' => "* <b>광고성 이메일 수신</b> / <b>마케팅 목적의 개인정보 수집 및 이용</b>{$thirdpartyLbl}에 모두 동의한 회원을 선택합니다.",
'sms_only' => "* <b>광고성 SMS/카카오톡 수신</b> / <b>마케팅 목적의 개인정보 수집 및 이용</b>{$thirdpartyLbl}에 모두 동의한 회원을 선택합니다.",
'month_confirm' => "* 23개월 전(" . date('Y년 m월', strtotime('-23 month')) . ") <b>광고성 정보 수신 동의(이메일 또는 SMS/카카오톡)</b>한 회원을 선택합니다."
);
if (isset($_GET['ad_range_only'], $_GET['ad_range_type']) && isset($ad_range_text[$_GET['ad_range_type']])) {
echo '<div class="ad_range_box"><p>' . $ad_range_text[$_GET['ad_range_type']] . '</p></div>';
}
?>
</div>
<br>
</div>
</div>
</div>
</div>
<!-- 채널 체크박스 -->
<div class="sch_row <?php echo isset($_GET['ad_range_only']) && in_array($_GET['ad_range_type'], array('month_confirm', 'custom_period')) ? '' : 'is-hidden'; ?>">
<div class="ad_range_wrap">
<div class="ad_range_box">
<div class="label">
</div>
<div class="field">
<?php $ad_mailling_checked = isset($_GET['token']) ? (isset($_GET['ad_mailling']) ? 'checked' : '') : 'checked';?>
<?php $ad_sms_checked = isset($_GET['token']) ? (isset($_GET['ad_sms']) ? 'checked' : '') : 'checked';?>
<label><input type="checkbox" name="ad_mailling" value="1" <?php echo $ad_mailling_checked; ?>> 광고성 이메일 수신</label>
<label><input type="checkbox" name="ad_sms" value="1" <?php echo $ad_sms_checked; ?>> 광고성 SMS/카카오톡 수신</label>
</div>
</div>
</div>
</div>
<div class="sch_btn">
<button type="button" id="btnExcelDownload">엑셀파일 다운로드</button>
<button type="button" class="btn_reset" onclick="location.href='?'">초기화</button>
</div>
</div>
</fieldset>
</form>
<script>
document.querySelector('input[name="ad_range_only"]').addEventListener('change', function () {
document.querySelectorAll('.ad_range_wrap').forEach(el => {
el.classList.toggle('is-hidden', !this.checked);
});
});
document.querySelectorAll('#fsearch input, #fsearch select').forEach(el => {
const submit = () => document.getElementById('fsearch').submit();
el.addEventListener(el.type === 'date' ? 'blur' : 'change', submit);
el.addEventListener('keydown', e => {
if (e.key === 'Enter') {
e.preventDefault();
submit();
}
});
});
</script>
<script>
let eventSource = null;
// 일반 엑셀 다운로드 버튼 클릭
document.getElementById('btnExcelDownload').addEventListener('click', () => {
startExcelDownload();
});
// 엑셀 다운로드 실행
// 1. 기존 SSE 종료
function closePreviousEventSource() {
if (eventSource) {
eventSource.close();
eventSource = null;
}
}
// 2. FormData QueryString 변환
function buildDownloadParams() {
const formData = new FormData(document.getElementById('fsearch'));
const params = new URLSearchParams(formData);
params.append('mode', 'start');
return params.toString();
}
// 3. 메인 함수
function startExcelDownload() {
closePreviousEventSource();
const query = buildDownloadParams();
showDownloadPopup();
eventSource = new EventSource(`member_list_exel_export.php?${query}`);
eventSource.onmessage = handleProgressUpdate();
eventSource.onerror = handleDownloadError();
}
// 다운로드 팝업 표시
function showDownloadPopup() {
const bodyHTML = `
<div class="excel-download-progress">
<div class="progress-desc">
<p class="progress-summary">총 <strong>0</strong>개 파일로 분할됩니다</p>
<p class="progress-message"><strong>(0 / 0)</strong> 파일 다운로드 중</p>
<p class="progress-error"></p>
</div>
<div class="progress-spinner">
<div class="spinner"></div>
<p class="loading-message">
엑셀 파일을 생성 중입니다. 잠시만 기다려주세요.<br>
현재 데이터 기준으로 <strong id="estimatedTimeText"></strong> 정도 소요될 수 있습니다.<br>
<strong>페이지를 벗어나거나 닫으면 다운로드가 중단</strong>되니, 작업 완료까지 기다려 주세요.
</p>
</div>
<div class="progress-box">
<div class="progress-download-box"></div>
</div>
</div>
`;
PopupManager.render('엑셀 다운로드 진행 중', bodyHTML, '', { disableOutsideClose: true });
// 닫기 버튼 이벤트 핸들링
const closeBtn = document.querySelector('.popup-close-btn');
if (closeBtn) {
closeBtn.removeAttribute('onclick');
closeBtn.addEventListener('click', handlePopupCloseWithConfirm);
}
}
// 닫기 버튼 클릭 시 다운로드 중단 여부 확인
function handlePopupCloseWithConfirm(e) {
if (eventSource) {
const confirmClose = confirm("엑셀 다운로드가 진행 중입니다.\n정말 중지하시겠습니까?");
if (!confirmClose) {
e.preventDefault();
return;
}
eventSource.close();
eventSource = null;
alert("엑셀 다운로드가 중단되었습니다.");
}
PopupManager.close('popupOverlay');
}
// 엑셀 생성 및 다운로드 실행
function handleProgressUpdate() {
return function(e) {
const data = JSON.parse(e.data);
const { status, downloadType, message, total, current, totalChunks, currentChunk, zipFile, files, filePath } = data;
// DOM 요소 캐싱
const titleEl = document.getElementById('popupTitle');
const summaryEl = document.querySelector('.progress-summary');
const messageEl = document.querySelector('.progress-message');
const spinnerEl = document.querySelector('.progress-spinner');
const resultEl = document.querySelector('.loading-message');
const downloadBoxEl = document.querySelector('.progress-download-box');
const errorEl = document.querySelector('.progress-error');
if (status === "progress")
{
summaryEl.innerHTML = `총 <strong>${totalChunks}</strong>개 파일로 ` + (downloadType === 2 ? `분할 생성됩니다` : `다운로드됩니다`) + ` (총 ${total.toLocaleString('ko-KR')}건)`;
messageEl.innerHTML = downloadType === 2 ? `<strong>(${currentChunk} / ${totalChunks})</strong> 파일 생성 중` : `엑셀 파일 생성 중`;
/* 작업 소요 시간 : 예상 시간 (1만건당 10초) */
const sec = Math.max(5, Math.ceil(total * 0.0012 * 1.2)); // 최소 5초 보장
const text = `예상 처리 시간은 약 ${sec >= 60 ? `${Math.floor(sec / 60)}분 ${sec % 60}초` : `${sec}초`}`;
document.getElementById('estimatedTimeText').innerText = text;
}
else if (status === "zipping")
{
summaryEl.innerHTML = `총 <strong>${totalChunks}</strong>개 파일이 압축파일로 생성됩니다`;
messageEl.innerHTML = `<strong>${totalChunks}</strong> 파일 압축하는 중`;
}
else if (status === "zippingError")
{
errorEl.innerHTML = message;
}
else if (status === "error")
{
summaryEl.innerHTML = `엑셀 파일 다운로드 실패`;
resultEl.innerHTML = '';
spinnerEl?.classList.add('is-hidden');
const parts = message.split(/<br\s*\/?>/i);
messageEl.innerHTML = parts[0] || '';
errorEl.innerHTML = parts.slice(1).join('<br>') || '';
// SSE 작업 닫기
eventSource?.close();
eventSource = null;
}
else if (status === "done")
{
// SSE 작업 닫기
eventSource?.close();
eventSource = null;
titleEl.textContent = '엑셀 파일 다운로드 완료';
messageEl.innerHTML = `<strong>총 ${total.toLocaleString('ko-KR')}건의 데이터 다운로드가 완료되었습니다!</strong>`;
spinnerEl?.classList.add('is-hidden');
let html = '<p>* 자동으로 다운로드가 되지 않았다면 아래 버튼을 클릭해주세요.</p>';
const baseUrl = `<?php echo G5_DATA_URL; ?>/member_list/<?php echo date('Ymdhis'); ?>/`; // 공통 URL 분리
if (zipFile) {
const url = `${filePath}/${zipFile}`;
html += `<a href="${url}" class="btn btn_03" download>압축파일 다운로드</a>`;
downloadBoxEl.innerHTML = html;
triggerAutoDownload(url, zipFile);
} else if (files?.length) {
files.forEach((file, index) => {
const url = `${filePath}/${file}`;
html += `<a class="btn btn_03" href="${url}" download>엑셀파일 다운로드 ${index + 1}</a>`;
});
downloadBoxEl.innerHTML = html;
if (files.length === 1) {
const url = `${filePath}/${files[0]}`;
triggerAutoDownload(url, files[0]);
} else {
summaryEl.innerHTML = `총 <strong>${totalChunks}</strong>개 파일이 생성되었습니다. 아래 버튼을 눌러 다운로드 받아주세요.`;
}
}
}
}
}
// SSE 오류 처리
function handleDownloadError() {
return function(e){
const errorMessage = e?.message || e?.data || '알 수 없는 오류가 발생했습니다.';
document.querySelector('.progress-summary').innerHTML = `엑셀 파일 다운로드 실패`;
document.querySelector('.progress-message').innerHTML = `엑셀 파일 다운로드에 실패하였습니다`;
document.querySelector('.progress-error').innerHTML = errorMessage;
document.querySelector('.loading-message').innerHTML = '';
document.querySelector('.progress-spinner').classList.add('is-hidden');
if (eventSource) {
eventSource.close();
eventSource = null;
}
}
}
// 자동 다운로드 실행
function triggerAutoDownload(url, filename) {
const a = document.createElement('a');
a.href = url;
a.download = filename;
document.body.appendChild(a);
a.click();
document.body.removeChild(a);
}
</script>
<?php
require_once './admin.tail.php';
+565
View File
@@ -0,0 +1,565 @@
<?php
$sub_menu = "200400";
require_once './_common.php';
require_once './member_list_exel.lib.php'; // 회원관리파일 공통 라이브러리 (상수, 검색 옵션 설정, SQL WHERE 등)
include_once(G5_LIB_PATH.'/PHPExcel.php');
check_demo();
auth_check_menu($auth, $sub_menu, 'w');
ini_set('memory_limit', '-1');
session_write_close(); // 세션 종료 및 잠금 해제 (백그라운드 작업을 위해 필요)
// 파라미터 수집 및 유효성 검사
$params = get_member_export_params();
if (!$params || !is_array($params)) {
member_export_send_progress("error", "데이터가 올바르게 전달되지 않아 작업에 실패하였습니다.");
member_export_write_log(array(), array('success' => false, 'error' => '데이터가 올바르게 전달되지 않아 작업에 실패하였습니다.'));
exit;
}
// 기존 생성된 엑셀 파일 삭제 - LOG 및 오늘 날짜 폴더 제외
$resultExcelDelete = member_export_delete();
// 서버 전송 이벤트(SSE)를 위한 헤더 설정
member_export_set_sse_headers();
// 모드 확인
$mode = isset($_GET['mode']) ? $_GET['mode'] : '';
if ($mode !== 'start') {
member_export_send_progress("error", "잘못된 요청 입니다.");
member_export_write_log($params, array('success' => false, 'error' => '잘못된 요청 입니다.'));
exit;
}
/**
* 회원 내보내기 처리 실행 (예외 처리 포함)
*/
try {
main_member_export($params);
}
catch (Exception $e)
{
// 에러 로그 저장 및 SSE 에러 전송
error_log("[Member Export Error] " . $e->getMessage());
member_export_send_progress("error", $e->getMessage());
member_export_write_log($params, array('success' => false, 'error' => $e->getMessage()));
}
/**
* 메인 내보내기 프로세스
*/
function main_member_export($params)
{
$total = member_export_get_total_count($params);
if($total > MEMBER_EXPORT_MAX_SIZE){
throw new Exception("엑셀 다운로드 가능 범위(최대 " . number_format(MEMBER_EXPORT_MAX_SIZE) . "건)를 초과했습니다.<br>조건을 추가로 설정하신 후 다시 시도해 주세요.");
}
if($total <= 0){
throw new Exception("조회된 데이터가 없어 엑셀 파일을 생성할 수 없습니다.<br>조건을 추가로 설정하신 후 다시 시도해 주세요.");
}
$fileName = 'member_'.MEMBER_BASE_DATE;
$fileList = array();
$zipFileName = '';
if ($total > MEMBER_EXPORT_PAGE_SIZE) {
// 대용량 데이터 - 분할 처리
$pages = (int)ceil($total / MEMBER_EXPORT_PAGE_SIZE);
member_export_send_progress("progress", "", 2, $total, 0, $pages, 0);
for ($i = 1; $i <= $pages; $i++) {
$params['page'] = $i;
member_export_send_progress("progress", "", 2, $total, ($pages == $i ? $total : $i * MEMBER_EXPORT_PAGE_SIZE), $pages, $i);
try {
$data = member_export_get_data($params);
$fileList[] = member_export_create_excel($data, $fileName, $i);
} catch (Exception $e) {
throw new Exception("총 {$pages}개 중 {$i}번째 파일을 생성하지 못했습니다<br>" . $e->getMessage());
}
}
// 압축 파일 생성
if (count($fileList) > 1) {
member_export_send_progress("zipping", "", 2, $total, $total, $pages, $i);
$zipResult = member_export_create_zip($fileList, $fileName); // 압축 파일 생성
if($zipResult['error']){
member_export_write_log($params, array('success' => false, 'error' => $zipResult['error']));
member_export_send_progress("zippingError", $zipResult['error']);
}
if ($zipResult && $zipResult['result']) {
member_export_delete($fileList); // 압축 후 엑셀 파일 제거
$zipFileName = $zipResult['zipFile'];
}
}
} else {
// 소용량 데이터 - 단일 파일
member_export_send_progress("progress", "", 1, $total, 0);
$data = member_export_get_data($params);
member_export_send_progress("progress", "", 1, $total, $total/2);
$fileList[] = member_export_create_excel($data, $fileName, 0);
member_export_send_progress("progress", "", 1, $total, $total);
}
member_export_write_log($params, array('success' => true, 'total' => $total, 'files' => $fileList, 'zip' => isset($zipFileName) ? $zipFileName : null));
member_export_send_progress("done", "", 2, $total, $total, $pages, $pages, $fileList, $zipFileName);
}
/**
* 진행률 전송
*/
function member_export_send_progress($status, $message = "", $downloadType = 1, $total = 1, $current = 1, $totalChunks = 1, $currentChunk = 1, $files = array(), $zipFile = '')
{
// 연결 상태 확인
if (connection_aborted()) return;
$data = array(
'status' => $status,
'message' => $message,
'downloadType' => $downloadType,
'total' => $total,
'current' => $current,
'totalChunks' => $totalChunks,
'currentChunk' => $currentChunk,
'files' => $files,
'zipFile' => $zipFile,
'filePath' => G5_DATA_URL . "/" . MEMBER_BASE_DIR . "/" . MEMBER_BASE_DATE,
);
$json_options = defined('JSON_UNESCAPED_UNICODE') ? JSON_UNESCAPED_UNICODE : 0;
echo "data: " . json_encode($data, $json_options) . "\n\n";
// 더 안정적인 플러시
if (ob_get_level()) ob_end_flush();
flush();
}
/**
* 엑셀 내보내기 설정
*/
function member_export_get_config()
{
$type = 1;
$configs = array(
1 => array(
'title' => array("회원관리파일(일반)"),
'headers' => array('아이디', '이름', '닉네임', '휴대폰번호', '전화번호', '이메일', '주소', '회원권한', '포인트', '가입일', '차단',
'광고성 이메일 수신동의', '광고성 이메일 동의일자', '광고성 SMS/카카오톡 수신동의', '광고성 SMS/카카오톡 동의일자',
'마케팅목적의개인정보수집및이용동의', '마케팅목적의개인정보수집및이용동의일자', '개인정보제3자제공동의', '개인정보제3자제공동의일자'),
'fields' => array('mb_id', 'mb_name', 'mb_nick', 'mb_hp', 'mb_tel', 'mb_email', 'mb_addr1', 'mb_level', 'mb_point', 'mb_datetime', 'mb_intercept_date',
'mb_mailling','mb_mailling_date', 'mb_sms','mb_sms_date', 'mb_marketing_agree',
'mb_marketing_date', 'mb_thirdparty_agree', 'mb_thirdparty_date'),
'widths' => array(20, 20, 20, 20, 20, 30, 30, 10, 15, 25, 10, 20, 25, 20, 25, 20, 25, 20, 25),
),
);
return isset($configs[$type]) ? $configs[$type] : $configs[1];
}
/**
* SSE 헤더 설정
*/
function member_export_set_sse_headers()
{
header('Content-Type: text/event-stream');
header('Cache-Control: no-cache');
header('Connection: keep-alive');
header('X-Accel-Buffering: no');
if (ob_get_level()) ob_end_flush();
ob_implicit_flush(true);
}
/**
* 엑셀 컬럼 문자 반환
*/
function member_export_column_char($i)
{
return chr(65 + $i);
}
/**
* 회원 데이터 조회
*/
function member_export_get_data($params)
{
global $g5;
$config = member_export_get_config();
$fields = $config['fields'];
$fields = array_unique($fields);
// SQL 변환 맵 (가공이 필요한 필드만 정의)
$sqlTransformMap = array(
'mb_datetime' => "IF(mb_datetime = '0000-00-00 00:00:00', '', mb_datetime) AS mb_datetime",
'mb_intercept_date' => "IF(mb_intercept_date != '', '차단됨', '정상') AS mb_intercept_date",
'mb_sms' => "IF(mb_sms = '1', '동의', '미동의') AS mb_sms",
'mb_sms_date' => "IF(mb_sms != '1' OR mb_sms_date = '0000-00-00 00:00:00', '', mb_sms_date) AS mb_sms_date",
'mb_mailling' => "IF(mb_mailling = '1', '동의', '미동의') AS mb_mailling",
'mb_mailling_date' => "IF(mb_mailling != '1' OR mb_mailling_date = '0000-00-00 00:00:00', '', mb_mailling_date) AS mb_mailling_date",
'mb_marketing_agree' => "IF(mb_marketing_agree = '1', '동의', '미동의') AS mb_marketing_agree",
'mb_marketing_date' => "IF(mb_marketing_agree != '1' OR mb_marketing_date = '0000-00-00 00:00:00', '', mb_marketing_date) AS mb_marketing_date",
'mb_thirdparty_agree' => "IF(mb_thirdparty_agree = '1', '동의', '미동의') AS mb_thirdparty_agree",
'mb_thirdparty_date' => "IF(mb_thirdparty_agree != '1' OR mb_thirdparty_date = '0000-00-00 00:00:00', '', mb_thirdparty_date) AS mb_thirdparty_date",
);
// SQL 필드 생성
$sqlFields = array();
foreach ($fields as $field) {
$sqlFields[] = isset($sqlTransformMap[$field]) ? $sqlTransformMap[$field] : $field;
}
$field_list = implode(', ', $sqlFields);
$where = member_export_build_where($params);
$page = (int)(isset($params['page']) ? $params['page'] : 1);
if ($page < 1) $page = 1;
$offset = ($page - 1) * MEMBER_EXPORT_PAGE_SIZE;
$sql = "SELECT {$field_list} FROM {$g5['member_table']} {$where} ORDER BY mb_no DESC LIMIT {$offset}, " . MEMBER_EXPORT_PAGE_SIZE;
$result = sql_query($sql);
if (!$result) {
throw new Exception("데이터 조회에 실패하였습니다");
}
$excelData = array($config['title'], $config['headers']);
while ($row = sql_fetch_array($result)) {
$rowData = array();
foreach ($fields as $field) {
if (isset($row[$field])) {
$rowData[] = function_exists('csv_safe_cell') ? csv_safe_cell($row[$field]) : $row[$field];
} else {
$rowData[] = '';
}
}
$excelData[] = $rowData;
}
return $excelData;
}
/**
* 엑셀 파일 생성
*/
function member_export_create_excel($data, $fileName, $index = 0)
{
$config = member_export_get_config();
if (!class_exists('PHPExcel')) {
error_log('[Member Export Error] PHPExcel 라이브러리를 찾을 수 없습니다.');
throw new Exception('파일 생성 중 내부 오류가 발생했습니다: PHPExcel 라이브러리를 찾을 수 없습니다.');
}
// 현재 설정값 백업
$currentCache = PHPExcel_Settings::getCacheStorageMethod();
// 캐싱 모드 설정 (엑셀 생성 전용)
$cacheMethods = array(
PHPExcel_CachedObjectStorageFactory::cache_to_discISAM,
PHPExcel_CachedObjectStorageFactory::cache_in_memory_serialized
);
foreach ($cacheMethods as $method) {
if (PHPExcel_Settings::setCacheStorageMethod($method)) {
break;
}
}
try {
$excel = new PHPExcel();
$sheet = $excel->setActiveSheetIndex(0);
// 헤더 스타일 적용
$last_char = member_export_column_char(count($config['headers']) - 1);
$sheet->getStyle("A2:{$last_char}2")->applyFromArray(array(
'fill' => array(
'type' => PHPExcel_Style_Fill::FILL_SOLID,
'startcolor' => array('rgb' => 'D9E1F2'), // 연파랑 배경
),
));
// 셀 정렬 및 줄바꿈 설정
$sheet->getStyle("A:{$last_char}")->getAlignment()->setVertical(PHPExcel_Style_Alignment::VERTICAL_CENTER)->setWrapText(true);
// 컬럼 너비 설정
foreach ($config['widths'] as $i => $width) {
$sheet->getColumnDimension(member_export_column_char($i))->setWidth($width);
}
// 데이터 입력
$sheet->fromArray($data, NULL, 'A1');
// 디렉토리 확인
member_export_ensure_directory(MEMBER_EXPORT_DIR);
// 파일명 생성
$subname = $index == 0 ? 'all' : sprintf("%02d", $index);
$filename = $fileName . "_" . $subname . ".xlsx";
$filePath = MEMBER_EXPORT_DIR . "/" . $filename;
// 파일 저장
$writer = PHPExcel_IOFactory::createWriter($excel, 'Excel2007');
$writer->setPreCalculateFormulas(false);
$writer->save($filePath);
unset($excel, $sheet, $writer); // 생성 완료 후 메모리 해제
}
catch (Exception $e)
{
if ($currentCache) {
PHPExcel_Settings::setCacheStorageMethod($currentCache);
}
throw new Exception("엑셀 파일 생성에 실패하였습니다: " . $e->getMessage());
}
// 캐싱 모드 원래 상태로 복원
if ($currentCache) {
PHPExcel_Settings::setCacheStorageMethod($currentCache);
}
return $filename;
}
/**
* 압축 파일 생성
*/
function member_export_create_zip($files, $zipFileName)
{
if (!class_exists('ZipArchive')) {
error_log('[Member Export Error] ZipArchive 클래스를 사용할 수 없습니다.');
return array('error' => '파일을 압축하는 중 문제가 발생했습니다. 개별 파일로 제공됩니다.<br>: ZipArchive 클래스를 사용할 수 없습니다.');
}
member_export_ensure_directory(MEMBER_EXPORT_DIR);
$destinationZipPath = rtrim(MEMBER_EXPORT_DIR, "/") . "/" . $zipFileName . ".zip";
$zip = new ZipArchive();
if ($zip->open($destinationZipPath, ZipArchive::CREATE | ZipArchive::OVERWRITE) !== TRUE) {
return array('error' => "파일을 압축하는 중 문제가 발생했습니다. 개별 파일로 제공됩니다.");
}
foreach ($files as $file) {
$filePath = MEMBER_EXPORT_DIR . "/" . $file;
if (file_exists($filePath)) {
$zip->addFile($filePath, basename($filePath));
}
}
$result = $zip->close();
return array(
'result' => $result,
'zipFile' => $zipFileName . ".zip",
'zipPath' => $destinationZipPath,
);
}
/**
* 디렉토리 생성 및 확인
*/
function member_export_ensure_directory($dir)
{
if (!is_dir($dir)) {
if (!@mkdir($dir, G5_DIR_PERMISSION, true)) {
throw new Exception("디렉토리 생성 실패");
}
@chmod($dir, G5_DIR_PERMISSION);
}
if (!is_writable($dir)) {
throw new Exception("디렉토리 쓰기 권한 없음");
}
}
/**
* 파일 삭제 - 값이 있으면 해당 파일만 삭제, 없으면 디렉토리 내 모든 파일 삭제
* - 알집 생성 완료 시 엑셀 파일 제거
* - 작업 전 오늘 날짜 폴더 및 log 폴더를 제외한 나머지 파일 모두 제거
*/
function member_export_delete($fileList = array())
{
$cnt = 0;
// 파일 리스트가 있는 경우 -> 해당 파일만 삭제
if (!empty($fileList)) {
foreach ($fileList as $file) {
$filePath = rtrim(MEMBER_EXPORT_DIR, DIRECTORY_SEPARATOR) . DIRECTORY_SEPARATOR . $file;
if (file_exists($filePath) && is_file($filePath) && @unlink($filePath)) {
$cnt++;
}
}
}
// 파일 리스트가 없는 경우 -> 디렉토리 내 모든 파일 삭제
else {
$files = glob(rtrim(G5_DATA_PATH . "/" . MEMBER_BASE_DIR, '/') . '/*');
function deleteFolder($dir) {
foreach (glob($dir . '/{.,}*', GLOB_BRACE) as $item) {
if (in_array(basename($item), array('.', '..'))) continue;
is_dir($item) ? deleteFolder($item) : unlink($item);
}
rmdir($dir);
}
foreach ($files as $file) {
$name = basename($file);
// log 폴더와 오늘 날짜로 시작하는 폴더는 제외
if ($name === 'log' || preg_match('/^' . date('Ymd') . '\d{6}(_[A-Za-z0-9]+)?$/', $name)) continue;
if (is_file($file) && pathinfo($file, PATHINFO_EXTENSION) !== 'log' && @unlink($file)) {
$cnt++;
} elseif (is_dir($file)) {
deleteFolder($file); // 재귀 폴더 삭제 함수 사용
$cnt++;
}
}
}
return $cnt;
}
/**
* 로그 작성
*/
function member_export_write_log($params, $result = array())
{
global $member;
$maxSize = 1024 * 1024 * 2; // 2MB
$maxFiles = 10; // 최대 로그 파일 수 (필요시 조정)
$username = isset($member['mb_id']) ? $member['mb_id'] : 'guest';
$datetime = date("Y-m-d H:i:s");
if (!is_dir(MEMBER_LOG_DIR)) {
@mkdir(MEMBER_LOG_DIR, G5_DIR_PERMISSION, true);
@chmod(MEMBER_LOG_DIR, G5_DIR_PERMISSION);
}
$logFiles = glob(MEMBER_LOG_DIR . "/export_log_*.log");
if (!$logFiles) {
$logFiles = array();
}
// 최신 파일 기준 정렬 (최신 → 오래된)
usort($logFiles, 'member_export_compare_log_mtime');
$latestLogFile = isset($logFiles[0]) ? $logFiles[0] : null;
// 용량 기준으로 새 파일 생성
if (!$latestLogFile || filesize($latestLogFile) >= $maxSize) {
$latestLogFile = MEMBER_LOG_DIR . "/export_log_" . date("YmdHi") . ".log";
file_put_contents($latestLogFile, '');
array_unshift($logFiles, $latestLogFile);
}
// 최대 파일 수 초과 시 오래된 파일 제거
if (count($logFiles) > $maxFiles) {
$filesToDelete = array_slice($logFiles, $maxFiles);
foreach ($filesToDelete as $file) {
@unlink($file);
}
}
$success = isset($result['success']) && $result['success'] === true;
$status = $success ? '성공' : '실패';
// 조건 정리
$condition = array();
// 검색 조건
if ($params['use_stx'] == 1 && !empty($params['stx'])) {
$sfl_list = get_export_config('sfl_list');
$label = isset($sfl_list[$params['sfl']]) ? $sfl_list[$params['sfl']] : '';
$condition[] = "검색({$params['stx_cond']}) : {$label} - {$params['stx']}";
}
// 레벨 조건
if ($params['use_level'] == 1 && ($params['level_start'] || $params['level_end'])) {
$condition[] = "레벨: {$params['level_start']}~{$params['level_end']}";
}
// 가입일 조건
if ($params['use_date'] == 1 && ($params['date_start'] || $params['date_end'])) {
$condition[] = "가입일: {$params['date_start']}~{$params['date_end']}";
}
// 포인트 조건
if ($params['use_point'] == 1 && $params['point'] !== '') {
$point_cond_map = get_export_config('point_cond_map');
$symbol = isset($point_cond_map[$params['point_cond']]) ? $point_cond_map[$params['point_cond']] : '≥';
$condition[] = "포인트 {$symbol} {$params['point']}";
}
// 휴대폰 여부
if ($params['use_hp_exist'] == 1) {
$condition[] = "휴대폰번호 있는 경우만";
}
// 광고 수신 동의
if ($params['ad_range_only'] == 1) {
$ad_range_list = get_export_config('ad_range_list');
$label = isset($ad_range_list[$params['ad_range_type']]) ? $ad_range_list[$params['ad_range_type']] : '';
$condition[] = "수신동의: 예 ({$label})";
if ($params['ad_range_type'] == "custom_period" && ($params['agree_date_start'] || $params['agree_date_end'])) {
$condition[] = "수신동의일: {$params['agree_date_start']}~{$params['agree_date_end']}";
}
if (in_array($params['ad_range_type'], array("month_confirm", "custom_period"))){
$channels = array_filter(array(
!empty($params['ad_mailling']) && (int)$params['ad_mailling'] === 1 ? '이메일' : null,
!empty($params['ad_sms']) && (int)$params['ad_sms'] === 1 ? 'SMS/카카오톡' : null,
));
if ($channels) {
$condition[] = '수신채널: ' . implode(', ', $channels);
}
}
}
// 차단회원 처리
if ($params['use_intercept'] == 1) {
$intercept_list = get_export_config('intercept_list');
$label = isset($intercept_list[$params['intercept']]) ? $intercept_list[$params['intercept']] : '';
if ($label) $condition[] = $label;
}
$conditionStr = !empty($condition) ? implode(', ', $condition) : '없음';
$line1 = "[{$datetime}] [{$status}] 관리자: {$username}";
// 성공일 경우 추가 정보
if ($success) {
$total = isset($result['total']) ? $result['total'] : 0;
$fileCount = isset($result['zip']) ? 1 : count(isset($result['files']) ? $result['files'] : array());
$line1 .= " | 총 {$total}건 | 파일: {$fileCount}개";
}
$logEntry = $line1 . PHP_EOL;
$logEntry .= "조건: {$conditionStr}" . PHP_EOL;
if (!$success && !empty($result['error'])) {
$logEntry .= "오류 메시지: {$result['error']}" . PHP_EOL;
}
$logEntry .= PHP_EOL;
// 파일에 기록
if (@file_put_contents($latestLogFile, $logEntry, FILE_APPEND | LOCK_EX) === false) {
error_log("[Member Export Error] 로그 파일 기록 실패: {$latestLogFile}");
}
}
function member_export_compare_log_mtime($a, $b)
{
return filemtime($b) - filemtime($a);
}
+72
View File
@@ -0,0 +1,72 @@
<?php
$sub_menu = '100930';
include_once('./_common.php');
if ($is_admin != 'super')
alert('최고관리자만 접근 가능합니다.', G5_URL);
$g5['title'] = '회원관리파일 일괄삭제';
include_once(G5_ADMIN_PATH.'/admin.head.php');
?>
<div class="local_desc02 local_desc">
<p>
완료 메세지가 나오기 전에 프로그램의 실행을 중지하지 마십시오.
</p>
</div>
<?php
flush();
if (!$dir = @opendir(G5_DATA_PATH . '/member_list')) {
echo '<p>회원관리파일를 열지못했습니다.</p>';
}
$cnt = 0;
echo '<ul class="session_del">' . PHP_EOL;
$files = glob(G5_DATA_PATH . '/member_list/*');
$cnt = 0;
// 폴더 및 하위 파일 재귀 삭제 함수
function deleteFolder($folderPath) {
$items = glob($folderPath . '/*');
foreach ($items as $item) {
if (is_dir($item)) {
deleteFolder($item);
} else {
unlink($item);
}
}
rmdir($folderPath); // 폴더 자체 삭제
}
if (is_array($files)) {
foreach ($files as $member_list_file) {
// log 확장자가 아닌 파일/디렉토리 처리
$ext = strtolower(pathinfo($member_list_file, PATHINFO_EXTENSION));
$basename = basename($member_list_file);
if (is_file($member_list_file) && $ext !== 'log') {
unlink($member_list_file);
echo '<li>파일 삭제: ' . $member_list_file . '</li>' . PHP_EOL;
$cnt++;
} elseif (is_dir($member_list_file) && $basename !== 'log') {
deleteFolder($member_list_file);
echo '<li>폴더 삭제: ' . $member_list_file . '</li>' . PHP_EOL;
$cnt++;
}
flush();
if ($cnt % 10 == 0) {
echo PHP_EOL;
}
}
}
echo '<li>완료됨</li></ul>' . PHP_EOL;
echo '<div class="local_desc01 local_desc"><p><strong>회원관리파일 ' . $cnt . '건 삭제 완료됐습니다.</strong><br>프로그램의 실행을 끝마치셔도 좋습니다.</p></div>' . PHP_EOL;
?>
<?php
include_once(G5_ADMIN_PATH.'/admin.tail.php');
+62 -36
View File
@@ -1,11 +1,11 @@
<?php
$sub_menu = "200100";
include_once('./_common.php');
require_once './_common.php';
check_demo();
if (! (isset($_POST['chk']) && is_array($_POST['chk']))) {
alert($_POST['act_button']." 하실 항목을 하나 이상 체크하세요.");
if (!(isset($_POST['chk']) && is_array($_POST['chk']))) {
alert($_POST['act_button'] . " 하실 항목을 하나 이상 체크하세요.");
}
auth_check_menu($auth, $sub_menu, 'w');
@@ -16,12 +16,10 @@ $mb_datas = array();
$msg = '';
if ($_POST['act_button'] == "선택수정") {
for ($i=0; $i<count($_POST['chk']); $i++)
{
for ($i = 0; $i < count($_POST['chk']); $i++) {
// 실제 번호를 넘김
$k = isset($_POST['chk'][$i]) ? (int) $_POST['chk'][$i] : 0;
$post_mb_certify = (isset($_POST['mb_certify'][$k]) && $_POST['mb_certify'][$k]) ? clean_xss_tags($_POST['mb_certify'][$k], 1, 1, 20) : '';
$post_mb_level = isset($_POST['mb_level'][$k]) ? (int) $_POST['mb_level'][$k] : 0;
$post_mb_intercept_date = (isset($_POST['mb_intercept_date'][$k]) && $_POST['mb_intercept_date'][$k]) ? clean_xss_tags($_POST['mb_intercept_date'][$k], 1, 1, 8) : '';
@@ -29,50 +27,77 @@ if ($_POST['act_button'] == "선택수정") {
$post_mb_sms = isset($_POST['mb_sms'][$k]) ? (int) $_POST['mb_sms'][$k] : 0;
$post_mb_open = isset($_POST['mb_open'][$k]) ? (int) $_POST['mb_open'][$k] : 0;
$agree_items = array();
// 광고성 이메일 수신동의 일자 추가
$post_mb_mailling_default = isset($_POST['mb_mailling_default'][$k]) ? (int) $_POST['mb_mailling_default'][$k] : 0;
$sql_mailling_date = "";
if ($post_mb_mailling_default != $post_mb_mailling) {
$sql_mailling_date = " , mb_mailling_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 이메일 수신(" . ($post_mb_mailling == 1 ? "동의" : "철회") . ")";
}
// 광고성 SMS/카카오톡 수신동의 일자 추가
$post_mb_sms_default = isset($_POST['mb_sms_default'][$k]) ? (int) $_POST['mb_sms_default'][$k] : 0;
$sql_sms_date = "";
if ($post_mb_sms_default != $post_mb_sms) {
$sql_sms_date = " , mb_sms_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 SMS/카카오톡 수신(" . ($post_mb_sms == 1 ? "동의" : "철회") . ")";
}
// 동의 로그 추가
$sql_agree_log = "";
if (!empty($agree_items)) {
$agree_log = "[".G5_TIME_YMDHIS.", 회원관리 선택수정] " . implode(' | ', $agree_items) . "\n";
$sql_agree_log .= " , mb_agree_log = CONCAT('{$agree_log}', IFNULL(mb_agree_log, ''))";
}
$mb_datas[] = $mb = get_member($_POST['mb_id'][$k]);
if (! (isset($mb['mb_id']) && $mb['mb_id'])) {
$msg .= $mb['mb_id'].' : 회원자료가 존재하지 않습니다.\\n';
} else if ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level']) {
$msg .= $mb['mb_id'].' : 자신보다 권한이 높거나 같은 회원은 수정할 수 없습니다.\\n';
} else if ($member['mb_id'] == $mb['mb_id']) {
$msg .= $mb['mb_id'].' : 로그인 중인 관리자는 수정 할 수 없습니다.\\n';
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
$msg .= $mb['mb_id'] . ' : 회원자료가 존재하지 않습니다.\\n';
} elseif ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level']) {
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 회원은 수정할 수 없습니다.\\n';
} elseif ($is_admin != 'super' && $post_mb_level >= (int) $member['mb_level']) {
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.\\n';
} elseif ($member['mb_id'] == $mb['mb_id']) {
$msg .= $mb['mb_id'] . ' : 로그인 중인 관리자는 수정 할 수 없습니다.\\n';
} else {
if($post_mb_certify)
if ($post_mb_certify) {
$mb_adult = isset($_POST['mb_adult'][$k]) ? (int) $_POST['mb_adult'][$k] : 0;
else
} else {
$mb_adult = 0;
}
$sql = " update {$g5['member_table']}
set mb_level = '".$post_mb_level."',
mb_intercept_date = '".sql_real_escape_string($post_mb_intercept_date)."',
mb_mailling = '".$post_mb_mailling."',
mb_sms = '".$post_mb_sms."',
mb_open = '".$post_mb_open."',
mb_certify = '".sql_real_escape_string($post_mb_certify)."',
set mb_level = '" . $post_mb_level . "',
mb_intercept_date = '" . sql_real_escape_string($post_mb_intercept_date) . "',
mb_mailling = '" . $post_mb_mailling . "',
mb_sms = '" . $post_mb_sms . "',
mb_open = '" . $post_mb_open . "',
mb_certify = '" . sql_real_escape_string($post_mb_certify) . "',
mb_adult = '{$mb_adult}'
where mb_id = '".sql_real_escape_string($mb['mb_id'])."' ";
{$sql_mailling_date}
{$sql_sms_date}
{$sql_agree_log}
where mb_id = '" . sql_real_escape_string($mb['mb_id']) . "' ";
sql_query($sql);
}
}
} else if ($_POST['act_button'] == "선택삭제") {
for ($i=0; $i<count($_POST['chk']); $i++)
{
} elseif ($_POST['act_button'] == "선택삭제") {
for ($i = 0; $i < count($_POST['chk']); $i++) {
// 실제 번호를 넘김
$k = isset($_POST['chk'][$i]) ? (int) $_POST['chk'][$i] : 0;
$mb_datas[] = $mb = get_member($_POST['mb_id'][$k]);
if (!$mb['mb_id']) {
$msg .= $mb['mb_id'].' : 회원자료가 존재하지 않습니다.\\n';
} else if ($member['mb_id'] == $mb['mb_id']) {
$msg .= $mb['mb_id'].' : 로그인 중인 관리자는 삭제 할 수 없습니다.\\n';
} else if (is_admin($mb['mb_id']) == 'super') {
$msg .= $mb['mb_id'].' : 최고 관리자는 삭제할 수 없습니다.\\n';
} else if ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level']) {
$msg .= $mb['mb_id'].' : 자신보다 권한이 높거나 같은 회원은 삭제할 수 없습니다.\\n';
$msg .= $mb['mb_id'] . ' : 회원자료가 존재하지 않습니다.\\n';
} elseif ($member['mb_id'] == $mb['mb_id']) {
$msg .= $mb['mb_id'] . ' : 로그인 중인 관리자는 삭제 할 수 없습니다.\\n';
} elseif (is_admin($mb['mb_id']) == 'super') {
$msg .= $mb['mb_id'] . ' : 최고 관리자는 삭제할 수 없습니다.\\n';
} elseif ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level']) {
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 회원은 삭제할 수 없습니다.\\n';
} else {
// 회원자료 삭제
member_delete($mb['mb_id']);
@@ -80,10 +105,11 @@ if ($_POST['act_button'] == "선택수정") {
}
}
if ($msg)
if ($msg) {
//echo '<script> alert("'.$msg.'"); </script>';
alert($msg);
}
run_event('admin_member_list_update', $_POST['act_button'], $mb_datas);
goto_url('./member_list.php?'.$qstr);
goto_url('./member_list.php?' . $qstr);
+171 -157
View File
@@ -1,22 +1,24 @@
<?php
$sub_menu = "100290";
include_once('./_common.php');
require_once './_common.php';
if ($is_admin != 'super')
if ($is_admin != 'super') {
alert_close('최고관리자만 접근 가능합니다.');
}
$g5['title'] = '메뉴 추가';
include_once(G5_PATH.'/head.sub.php');
require_once G5_PATH . '/head.sub.php';
$new = isset($_GET['new']) ? clean_xss_tags($_GET['new'], 1, 1) : '';
$code = isset($_GET['code']) ? preg_replace('/[^0-9a-zA-Z]/', '', $_GET['code']) : '';
$new = isset($_GET['new']) ? clean_xss_tags($_GET['new'], 1, 1) : '';
$code = isset($_GET['code']) ? (string)preg_replace('/[^0-9a-zA-Z]/', '', $_GET['code']) : '';
// 코드
if($new == 'new' || !$code) {
$code = base_convert(substr($code,0, 2), 36, 10);
if ($new == 'new' || !$code) {
$code = (int)base_convert(substr($code, 0, 2), 36, 10);
$code += 36;
$code = base_convert($code, 10, 36);
$code = base_convert((string)$code, 10, 36);
}
?>
<div id="menu_frm" class="new_win">
@@ -24,174 +26,186 @@ if($new == 'new' || !$code) {
<form name="fmenuform" id="fmenuform" class="new_win_con">
<div class="new_win_desc">
<label for="me_type">대상선택</label>
<select name="me_type" id="me_type">
<option value="">직접입력</option>
<option value="group">게시판그룹</option>
<option value="board">게시판</option>
<option value="content">내용관리</option>
</select>
</div>
<div class="new_win_desc">
<label for="me_type">대상선택</label>
<select name="me_type" id="me_type">
<option value="">직접입력</option>
<option value="group">게시판그룹</option>
<option value="board">게시판</option>
<option value="content">내용관리</option>
</select>
</div>
<div id="menu_result"></div>
<div id="menu_result"></div>
</form>
</div>
<script>
$(function() {
$("#menu_result").load(
"./menu_form_search.php"
);
function link_checks_all_chage(){
var $links = $(opener.document).find("#menulist input[name='me_link[]']"),
$o_link = $(".td_mngsmall input[name='link[]']"),
hrefs = [],
menu_exist = false;
if( $links.length ){
$links.each(function( index ) {
hrefs.push( $(this).val() );
});
$o_link.each(function( index ) {
if( $.inArray( $(this).val(), hrefs ) != -1 ){
$(this).closest("tr").find("td:eq( 0 )").addClass("exist_menu_link");
menu_exist = true;
}
});
}
if( menu_exist ){
$(".menu_exists_tip").show();
} else {
$(".menu_exists_tip").hide();
}
}
function menu_result_change( type ){
var dfd = new $.Deferred();
$("#menu_result").empty().load(
"./menu_form_search.php",
{ type : type },
function(){
dfd.resolve('Finished');
}
$(function() {
$("#menu_result").load(
"./menu_form_search.php"
);
return dfd.promise();
}
function link_checks_all_chage() {
$("#me_type").on("change", function() {
var type = $(this).val();
var $links = $(opener.document).find("#menulist input[name='me_link[]']"),
$o_link = $(".td_mngsmall input[name='link[]']"),
hrefs = [],
menu_exist = false;
var promise = menu_result_change( type );
if ($links.length) {
$links.each(function(index) {
hrefs.push($(this).val());
});
$o_link.each(function(index) {
if ($.inArray($(this).val(), hrefs) != -1) {
$(this).closest("tr").find("td:eq( 0 )").addClass("exist_menu_link");
menu_exist = true;
}
});
}
if (menu_exist) {
$(".menu_exists_tip").show();
} else {
$(".menu_exists_tip").hide();
}
}
function menu_result_change(type) {
var dfd = new $.Deferred();
$("#menu_result").empty().load(
"./menu_form_search.php", {
type: type
},
function() {
dfd.resolve('Finished');
}
);
return dfd.promise();
}
$("#me_type").on("change", function() {
var type = $(this).val();
var promise = menu_result_change(type);
promise.done(function(message) {
link_checks_all_chage(type);
});
promise.done(function(message) {
link_checks_all_chage(type);
});
$(document).on("click", "#add_manual", function() {
var me_name = $.trim($("#me_name").val());
var me_link = $.trim($("#me_link").val());
add_menu_list(me_name, me_link, "<?php echo $code; ?>");
});
$(document).on("click", ".add_select", function() {
var me_name = $.trim($(this).siblings("input[name='subject[]']").val());
var me_link = $.trim($(this).siblings("input[name='link[]']").val());
add_menu_list(me_name, me_link, "<?php echo $code; ?>");
});
});
$(document).on("click", "#add_manual", function() {
var me_name = $.trim($("#me_name").val());
var me_link = $.trim($("#me_link").val());
add_menu_list(me_name, me_link, "<?php echo $code; ?>");
});
$(document).on("click", ".add_select", function() {
var me_name = $.trim($(this).siblings("input[name='subject[]']").val());
var me_link = $.trim($(this).siblings("input[name='link[]']").val());
add_menu_list(me_name, me_link, "<?php echo $code; ?>");
});
});
function add_menu_list(name, link, code)
{
var $menulist = $("#menulist", opener.document);
var ms = new Date().getTime();
var sub_menu_class;
<?php if($new == 'new') { ?>
sub_menu_class = " class=\"td_category\"";
<?php } else { ?>
sub_menu_class = " class=\"td_category sub_menu_class\"";
<?php } ?>
var list = "<tr class=\"menu_list menu_group_<?php echo $code; ?>\">";
list += "<td"+sub_menu_class+">";
list += "<label for=\"me_name_"+ms+"\" class=\"sound_only\">메뉴<strong class=\"sound_only\"> 필수</strong></label>";
list += "<input type=\"hidden\" name=\"code[]\" value=\"<?php echo $code; ?>\">";
list += "<input type=\"text\" name=\"me_name[]\" value=\""+name+"\" id=\"me_name_"+ms+"\" required class=\"required frm_input full_input\">";
list += "</td>";
list += "<td>";
list += "<label for=\"me_link_"+ms+"\" class=\"sound_only\">링크<strong class=\"sound_only\"> 필수</strong></label>";
list += "<input type=\"text\" name=\"me_link[]\" value=\""+link+"\" id=\"me_link_"+ms+"\" required class=\"required frm_input full_input\">";
list += "</td>";
list += "<td class=\"td_mng\">";
list += "<label for=\"me_target_"+ms+"\" class=\"sound_only\">새창</label>";
list += "<select name=\"me_target[]\" id=\"me_target_"+ms+"\">";
list += "<option value=\"self\">사용안함</option>";
list += "<option value=\"blank\">사용함</option>";
list += "</select>";
list += "</td>";
list += "<td class=\"td_numsmall\">";
list += "<label for=\"me_order_"+ms+"\" class=\"sound_only\">순서<strong class=\"sound_only\"> 필수</strong></label>";
list += "<input type=\"text\" name=\"me_order[]\" value=\"0\" id=\"me_order_"+ms+"\" required class=\"required frm_input\" size=\"5\">";
list += "</td>";
list += "<td class=\"td_mngsmall\">";
list += "<label for=\"me_use_"+ms+"\" class=\"sound_only\">PC사용</label>";
list += "<select name=\"me_use[]\" id=\"me_use_"+ms+"\">";
list += "<option value=\"1\">사용함</option>";
list += "<option value=\"0\">사용안함</option>";
list += "</select>";
list += "</td>";
list += "<td class=\"td_mngsmall\">";
list += "<label for=\"me_mobile_use_"+ms+"\" class=\"sound_only\">모바일사용</label>";
list += "<select name=\"me_mobile_use[]\" id=\"me_mobile_use_"+ms+"\">";
list += "<option value=\"1\">사용함</option>";
list += "<option value=\"0\">사용안함</option>";
list += "</select>";
list += "</td>";
list += "<td class=\"td_mng\">";
<?php if($new == 'new') { ?>
list += "<button type=\"button\" class=\"btn_add_submenu btn_03\">추가</button>\n";
<?php } ?>
list += "<button type=\"button\" class=\"btn_del_menu btn_02\">삭제</button>";
list += "</td>";
list += "</tr>";
var $menu_last = null;
if(code)
$menu_last = $menulist.find("tr.menu_group_"+code+":last");
else
$menu_last = $menulist.find("tr.menu_list:last");
if($menu_last.length > 0) {
$menu_last.after(list);
} else {
if($menulist.find("#empty_menu_list").length > 0)
$menulist.find("#empty_menu_list").remove();
$menulist.find("table tbody").append(list);
function htmlEscape(str) {
return str
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;');
}
$menulist.find("tr.menu_list").each(function(index) {
$(this).removeClass("bg0 bg1")
.addClass("bg"+(index % 2));
});
function add_menu_list(name, link, code) {
var $menulist = $("#menulist", opener.document);
var ms = new Date().getTime();
var sub_menu_class;
<?php if ($new == 'new') { ?>
sub_menu_class = " class=\"td_category\"";
<?php } else { ?>
sub_menu_class = " class=\"td_category sub_menu_class\"";
<?php } ?>
name = htmlEscape(name);
link = htmlEscape(link);
var list = "<tr class=\"menu_list menu_group_<?php echo $code; ?>\">";
list += "<td" + sub_menu_class + ">";
list += "<label for=\"me_name_" + ms + "\" class=\"sound_only\">메뉴<strong class=\"sound_only\"> 필수</strong></label>";
list += "<input type=\"hidden\" name=\"code[]\" value=\"<?php echo $code; ?>\">";
list += "<input type=\"text\" name=\"me_name[]\" value=\"" + name + "\" id=\"me_name_" + ms + "\" required class=\"required frm_input full_input\">";
list += "</td>";
list += "<td>";
list += "<label for=\"me_link_" + ms + "\" class=\"sound_only\">링크<strong class=\"sound_only\"> 필수</strong></label>";
list += "<input type=\"text\" name=\"me_link[]\" value=\"" + link + "\" id=\"me_link_" + ms + "\" required class=\"required frm_input full_input\">";
list += "</td>";
list += "<td class=\"td_mng\">";
list += "<label for=\"me_target_" + ms + "\" class=\"sound_only\">새창</label>";
list += "<select name=\"me_target[]\" id=\"me_target_" + ms + "\">";
list += "<option value=\"self\">사용안함</option>";
list += "<option value=\"blank\">사용함</option>";
list += "</select>";
list += "</td>";
list += "<td class=\"td_numsmall\">";
list += "<label for=\"me_order_" + ms + "\" class=\"sound_only\">순서<strong class=\"sound_only\"> 필수</strong></label>";
list += "<input type=\"text\" name=\"me_order[]\" value=\"0\" id=\"me_order_" + ms + "\" required class=\"required frm_input\" size=\"5\">";
list += "</td>";
list += "<td class=\"td_mngsmall\">";
list += "<label for=\"me_use_" + ms + "\" class=\"sound_only\">PC사용</label>";
list += "<select name=\"me_use[]\" id=\"me_use_" + ms + "\">";
list += "<option value=\"1\">사용함</option>";
list += "<option value=\"0\">사용안함</option>";
list += "</select>";
list += "</td>";
list += "<td class=\"td_mngsmall\">";
list += "<label for=\"me_mobile_use_" + ms + "\" class=\"sound_only\">모바일사용</label>";
list += "<select name=\"me_mobile_use[]\" id=\"me_mobile_use_" + ms + "\">";
list += "<option value=\"1\">사용함</option>";
list += "<option value=\"0\">사용안함</option>";
list += "</select>";
list += "</td>";
list += "<td class=\"td_mng\">";
<?php if ($new == 'new') { ?>
list += "<button type=\"button\" class=\"btn_add_submenu btn_03\">추가</button>\n";
<?php } ?>
list += "<button type=\"button\" class=\"btn_del_menu btn_02\">삭제</button>";
list += "</td>";
list += "</tr>";
window.close();
}
var $menu_last = null;
if (code)
$menu_last = $menulist.find("tr.menu_group_" + code + ":last");
else
$menu_last = $menulist.find("tr.menu_list:last");
if ($menu_last.length > 0) {
$menu_last.after(list);
} else {
if ($menulist.find("#empty_menu_list").length > 0)
$menulist.find("#empty_menu_list").remove();
$menulist.find("table tbody").append(list);
}
$menulist.find("tr.menu_list").each(function(index) {
$(this).removeClass("bg0 bg1")
.addClass("bg" + (index % 2));
});
window.close();
}
</script>
<?php
include_once(G5_PATH.'/tail.sub.php');
require_once G5_PATH . '/tail.sub.php';
+56 -57
View File
@@ -1,12 +1,13 @@
<?php
include_once('./_common.php');
require_once './_common.php';
if ($is_admin != 'super')
if ($is_admin != 'super') {
die('최고관리자만 접근 가능합니다.');
}
$type = isset($_REQUEST['type']) ? preg_replace('/[^0-9a-z_]/i', '', $_REQUEST['type']) : '';
switch($type) {
switch ($type) {
case 'group':
$sql = " select gr_id as id, gr_subject as subject
from {$g5['group_table']}
@@ -27,32 +28,31 @@ switch($type) {
break;
}
if($sql) {
if ($sql) {
$result = sql_query($sql);
for($i=0; $row=sql_fetch_array($result); $i++) {
if($i == 0) {
$bbs_subject_title = ($type == 'board') ? '게시판제목' : '제목';
?>
for ($i = 0; $row = sql_fetch_array($result); $i++) {
if ($i == 0) {
$bbs_subject_title = ($type == 'board') ? '게시판제목' : '제목';
?>
<div class="tbl_head01 tbl_wrap">
<table>
<thead>
<tr>
<th scope="col"><?php echo $bbs_subject_title; ?></th>
<?php if($type == 'board'){ ?>
<th scope="col">게시판 그룹</th>
<?php } ?>
<th scope="col">선택</th>
</tr>
</thead>
<tbody>
<thead>
<tr>
<th scope="col"><?php echo $bbs_subject_title; ?></th>
<?php if ($type == 'board') { ?>
<th scope="col">게시판 그룹</th>
<?php } ?>
<th scope="col">선택</th>
</tr>
</thead>
<tbody>
<?php }
switch($type) {
<?php }
switch ($type) {
case 'group':
$link = G5_BBS_URL.'/group.php?gr_id='.$row['id'];
$link = G5_BBS_URL . '/group.php?gr_id=' . $row['id'];
break;
case 'board':
$link = get_pretty_url($row['id']);
@@ -64,26 +64,26 @@ if($sql) {
$link = '';
break;
}
?>
<tr>
<td><?php echo $row['subject']; ?></td>
<?php
if($type == 'board'){
$group = get_call_func_cache('get_group', array($row['gr_id']));
?>
<td><?php echo $group['gr_subject']; ?></td>
<?php } ?>
<td class="td_mngsmall">
<input type="hidden" name="subject[]" value="<?php echo preg_replace('/[\'\"]/', '', $row['subject']); ?>">
<input type="hidden" name="link[]" value="<?php echo $link; ?>">
<button type="button" class="add_select btn btn_03"><span class="sound_only"><?php echo $row['subject']; ?> </span>선택</button>
</td>
</tr>
<?php } ?>
<tr>
<td><?php echo $row['subject']; ?></td>
<?php
if ($type == 'board') {
$group = get_call_func_cache('get_group', array($row['gr_id']));
?>
<td><?php echo $group['gr_subject']; ?></td>
<?php } ?>
<td class="td_mngsmall">
<input type="hidden" name="subject[]" value="<?php echo preg_replace('/[\'\"]/', '', $row['subject']); ?>">
<input type="hidden" name="link[]" value="<?php echo $link; ?>">
<button type="button" class="add_select btn btn_03"><span class="sound_only"><?php echo $row['subject']; ?> </span>선택</button>
</td>
</tr>
</tbody>
<?php } ?>
</tbody>
</table>
</div>
@@ -96,26 +96,25 @@ if($sql) {
</div>
<?php } else { ?>
<div class="tbl_frm01 tbl_wrap">
<table>
<colgroup>
<col class="grid_2">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="me_name">메뉴<strong class="sound_only"> 필수</strong></label></th>
<td><input type="text" name="me_name" id="me_name" required class="frm_input required"></td>
</tr>
<tr>
<th scope="row"><label for="me_link">링크<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('링크는 http://를 포함해서 입력해 주세요.'); ?>
<input type="text" name="me_link" id="me_link" required class="frm_input full_input required">
</td>
</tr>
</tbody>
<colgroup>
<col class="grid_2">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="me_name">메뉴<strong class="sound_only"> 필수</strong></label></th>
<td><input type="text" name="me_name" id="me_name" required class="frm_input required"></td>
</tr>
<tr>
<th scope="row"><label for="me_link">링크<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('링크는 http://를 포함해서 입력해 주세요.'); ?>
<input type="text" name="me_link" id="me_link" required class="frm_input full_input required">
</td>
</tr>
</tbody>
</table>
</div>
+159 -174
View File
@@ -1,34 +1,22 @@
<?php
$sub_menu = "100290";
include_once('./_common.php');
require_once './_common.php';
if ($is_admin != 'super')
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
// 메뉴테이블 생성
if( !isset($g5['menu_table']) ){
if (!isset($g5['menu_table'])) {
die('<meta charset="utf-8">dbconfig.php 파일에 <strong>$g5[\'menu_table\'] = G5_TABLE_PREFIX.\'menu\';</strong> 를 추가해 주세요.');
}
if(!sql_query(" DESCRIBE {$g5['menu_table']} ", false)) {
sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['menu_table']}` (
`me_id` int(11) NOT NULL AUTO_INCREMENT,
`me_code` varchar(255) NOT NULL DEFAULT '',
`me_name` varchar(255) NOT NULL DEFAULT '',
`me_link` varchar(255) NOT NULL DEFAULT '',
`me_target` varchar(255) NOT NULL DEFAULT '0',
`me_order` int(11) NOT NULL DEFAULT '0',
`me_use` tinyint(4) NOT NULL DEFAULT '0',
`me_mobile_use` tinyint(4) NOT NULL DEFAULT '0',
PRIMARY KEY (`me_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8 ", true);
}
$sql = " select * from {$g5['menu_table']} order by me_id ";
$result = sql_query($sql);
$g5['title'] = "메뉴설정";
include_once('./admin.head.php');
require_once './admin.head.php';
$colspan = 7;
$sub_menu_info = '';
@@ -39,181 +27,178 @@ $sub_menu_info = '';
</div>
<form name="fmenulist" id="fmenulist" method="post" action="./menu_list_update.php" onsubmit="return fmenulist_submit(this);">
<input type="hidden" name="token" value="">
<input type="hidden" name="token" value="">
<div id="menulist" class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">메뉴</th>
<th scope="col">링크</th>
<th scope="col">새창</th>
<th scope="col">순서</th>
<th scope="col">PC사용</th>
<th scope="col">모바일사용</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++)
{
$bg = 'bg'.($i%2);
$sub_menu_class = '';
if(strlen($row['me_code']) == 4) {
$sub_menu_class = ' sub_menu_class';
$sub_menu_info = '<span class="sound_only">'.$row['me_name'].'의 서브</span>';
$sub_menu_ico = '<span class="sub_menu_ico"></span>';
}
<div id="menulist" class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">메뉴</th>
<th scope="col">링크</th>
<th scope="col">새창</th>
<th scope="col">순서</th>
<th scope="col">PC사용</th>
<th scope="col">모바일사용</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$bg = 'bg' . ($i % 2);
$sub_menu_class = '';
if (strlen($row['me_code']) == 4) {
$sub_menu_class = ' sub_menu_class';
$sub_menu_info = '<span class="sound_only">' . $row['me_name'] . '의 서브</span>';
$sub_menu_ico = '<span class="sub_menu_ico"></span>';
}
$search = array('"', "'");
$replace = array('&#034;', '&#039;');
$me_name = str_replace($search, $replace, $row['me_name']);
?>
<tr class="<?php echo $bg; ?> menu_list menu_group_<?php echo substr($row['me_code'], 0, 2); ?>">
<td class="td_category<?php echo $sub_menu_class; ?>">
<input type="hidden" name="code[]" value="<?php echo substr($row['me_code'], 0, 2) ?>">
<label for="me_name_<?php echo $i; ?>" class="sound_only"><?php echo $sub_menu_info; ?> 메뉴<strong class="sound_only"> 필수</strong></label>
<input type="text" name="me_name[]" value="<?php echo get_sanitize_input($me_name); ?>" id="me_name_<?php echo $i; ?>" required class="required tbl_input full_input">
</td>
<td>
<label for="me_link_<?php echo $i; ?>" class="sound_only">링크<strong class="sound_only"> 필수</strong></label>
<input type="text" name="me_link[]" value="<?php echo $row['me_link'] ?>" id="me_link_<?php echo $i; ?>" required class="required tbl_input full_input">
</td>
<td class="td_mng">
<label for="me_target_<?php echo $i; ?>" class="sound_only">새창</label>
<select name="me_target[]" id="me_target_<?php echo $i; ?>">
<option value="self"<?php echo get_selected($row['me_target'], 'self', true); ?>>사용안함</option>
<option value="blank"<?php echo get_selected($row['me_target'], 'blank', true); ?>>사용함</option>
</select>
</td>
<td class="td_num">
<label for="me_order_<?php echo $i; ?>" class="sound_only">순서</label>
<input type="text" name="me_order[]" value="<?php echo $row['me_order'] ?>" id="me_order_<?php echo $i; ?>" class="tbl_input" size="5">
</td>
<td class="td_mng">
<label for="me_use_<?php echo $i; ?>" class="sound_only">PC사용</label>
<select name="me_use[]" id="me_use_<?php echo $i; ?>">
<option value="1"<?php echo get_selected($row['me_use'], '1', true); ?>>사용함</option>
<option value="0"<?php echo get_selected($row['me_use'], '0', true); ?>>사용안함</option>
</select>
</td>
<td class="td_mng">
<label for="me_mobile_use_<?php echo $i; ?>" class="sound_only">모바일사용</label>
<select name="me_mobile_use[]" id="me_mobile_use_<?php echo $i; ?>">
<option value="1"<?php echo get_selected($row['me_mobile_use'], '1', true); ?>>사용함</option>
<option value="0"<?php echo get_selected($row['me_mobile_use'], '0', true); ?>>사용안함</option>
</select>
</td>
<td class="td_mng">
<?php if(strlen($row['me_code']) == 2) { ?>
<button type="button" class="btn_add_submenu btn_03 ">추가</button>
<?php } ?>
<button type="button" class="btn_del_menu btn_02">삭제</button>
</td>
</tr>
<?php
}
$search = array('"', "'");
$replace = array('&#034;', '&#039;');
$me_name = str_replace($search, $replace, $row['me_name']);
?>
<tr class="<?php echo $bg; ?> menu_list menu_group_<?php echo substr($row['me_code'], 0, 2); ?>">
<td class="td_category<?php echo $sub_menu_class; ?>">
<input type="hidden" name="code[]" value="<?php echo substr($row['me_code'], 0, 2) ?>">
<label for="me_name_<?php echo $i; ?>" class="sound_only"><?php echo $sub_menu_info; ?> 메뉴<strong class="sound_only"> 필수</strong></label>
<input type="text" name="me_name[]" value="<?php echo get_sanitize_input($me_name); ?>" id="me_name_<?php echo $i; ?>" required class="required tbl_input full_input">
</td>
<td>
<label for="me_link_<?php echo $i; ?>" class="sound_only">링크<strong class="sound_only"> 필수</strong></label>
<input type="text" name="me_link[]" value="<?php echo $row['me_link'] ?>" id="me_link_<?php echo $i; ?>" required class="required tbl_input full_input">
</td>
<td class="td_mng">
<label for="me_target_<?php echo $i; ?>" class="sound_only">새창</label>
<select name="me_target[]" id="me_target_<?php echo $i; ?>">
<option value="self" <?php echo get_selected($row['me_target'], 'self', true); ?>>사용안함</option>
<option value="blank" <?php echo get_selected($row['me_target'], 'blank', true); ?>>사용함</option>
</select>
</td>
<td class="td_num">
<label for="me_order_<?php echo $i; ?>" class="sound_only">순서</label>
<input type="text" name="me_order[]" value="<?php echo $row['me_order'] ?>" id="me_order_<?php echo $i; ?>" class="tbl_input" size="5">
</td>
<td class="td_mng">
<label for="me_use_<?php echo $i; ?>" class="sound_only">PC사용</label>
<select name="me_use[]" id="me_use_<?php echo $i; ?>">
<option value="1" <?php echo get_selected($row['me_use'], '1', true); ?>>사용함</option>
<option value="0" <?php echo get_selected($row['me_use'], '0', true); ?>>사용안함</option>
</select>
</td>
<td class="td_mng">
<label for="me_mobile_use_<?php echo $i; ?>" class="sound_only">모바일사용</label>
<select name="me_mobile_use[]" id="me_mobile_use_<?php echo $i; ?>">
<option value="1" <?php echo get_selected($row['me_mobile_use'], '1', true); ?>>사용함</option>
<option value="0" <?php echo get_selected($row['me_mobile_use'], '0', true); ?>>사용안함</option>
</select>
</td>
<td class="td_mng">
<?php if (strlen($row['me_code']) == 2) { ?>
<button type="button" class="btn_add_submenu btn_03 ">추가</button>
<?php } ?>
<button type="button" class="btn_del_menu btn_02">삭제</button>
</td>
</tr>
<?php
}
if ($i==0)
echo '<tr id="empty_menu_list"><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
if ($i == 0) {
echo '<tr id="empty_menu_list"><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<button type="button" onclick="return add_menu();" class="btn btn_02">메뉴추가<span class="sound_only"> 새창</span></button>
<input type="submit" name="act_button" value="확인" class="btn_submit btn ">
</div>
<div class="btn_fixed_top">
<button type="button" onclick="return add_menu();" class="btn btn_02">메뉴추가<span class="sound_only"> 새창</span></button>
<input type="submit" name="act_button" value="확인" class="btn_submit btn ">
</div>
</form>
<script>
$(function() {
$(document).on("click", ".btn_add_submenu", function() {
var code = $(this).closest("tr").find("input[name='code[]']").val().substr(0, 2);
add_submenu(code);
});
$(document).on("click", ".btn_del_menu", function() {
if(!confirm("메뉴를 삭제하시겠습니까?"))
return false;
var $tr = $(this).closest("tr");
if($tr.find("td.sub_menu_class").length > 0) {
$tr.remove();
} else {
$(function() {
$(document).on("click", ".btn_add_submenu", function() {
var code = $(this).closest("tr").find("input[name='code[]']").val().substr(0, 2);
$("tr.menu_group_"+code).remove();
}
add_submenu(code);
});
if($("#menulist tr.menu_list").length < 1) {
var list = "<tr id=\"empty_menu_list\"><td colspan=\"<?php echo $colspan; ?>\" class=\"empty_table\">자료가 없습니다.</td></tr>\n";
$("#menulist table tbody").append(list);
} else {
$("#menulist tr.menu_list").each(function(index) {
$(this).removeClass("bg0 bg1")
.addClass("bg"+(index % 2));
});
}
});
});
$(document).on("click", ".btn_del_menu", function() {
if (!confirm("메뉴를 삭제하시겠습니까?\n메뉴 삭제후 메뉴설정의 확인 버튼을 눌러 메뉴를 저장해 주세요."))
return false;
function add_menu()
{
var max_code = base_convert(0, 10, 36);
$("#menulist tr.menu_list").each(function() {
var me_code = $(this).find("input[name='code[]']").val().substr(0, 2);
if(max_code < me_code)
max_code = me_code;
var $tr = $(this).closest("tr");
if ($tr.find("td.sub_menu_class").length > 0) {
$tr.remove();
} else {
var code = $(this).closest("tr").find("input[name='code[]']").val().substr(0, 2);
$("tr.menu_group_" + code).remove();
}
if ($("#menulist tr.menu_list").length < 1) {
var list = "<tr id=\"empty_menu_list\"><td colspan=\"<?php echo $colspan; ?>\" class=\"empty_table\">자료가 없습니다.</td></tr>\n";
$("#menulist table tbody").append(list);
} else {
$("#menulist tr.menu_list").each(function(index) {
$(this).removeClass("bg0 bg1")
.addClass("bg" + (index % 2));
});
}
});
});
var url = "./menu_form.php?code="+max_code+"&new=new";
window.open(url, "add_menu", "left=100,top=100,width=550,height=650,scrollbars=yes,resizable=yes");
return false;
}
function add_menu() {
var max_code = base_convert(0, 10, 36);
$("#menulist tr.menu_list").each(function() {
var me_code = $(this).find("input[name='code[]']").val().substr(0, 2);
if (max_code < me_code)
max_code = me_code;
});
function add_submenu(code)
{
var url = "./menu_form.php?code="+code;
window.open(url, "add_menu", "left=100,top=100,width=550,height=650,scrollbars=yes,resizable=yes");
return false;
}
function base_convert(number, frombase, tobase) {
// discuss at: http://phpjs.org/functions/base_convert/
// original by: Philippe Baumann
// improved by: Rafał Kukawski (http://blog.kukawski.pl)
// example 1: base_convert('A37334', 16, 2);
// returns 1: '101000110111001100110100'
return parseInt(number + '', frombase | 0)
.toString(tobase | 0);
}
function fmenulist_submit(f)
{
var me_links = document.getElementsByName('me_link[]');
var reg = /^javascript/;
for (i=0; i<me_links.length; i++){
if( reg.test(me_links[i].value) ){
alert('링크에 자바스크립트문을 입력할수 없습니다.');
me_links[i].focus();
return false;
}
var url = "./menu_form.php?code=" + max_code + "&new=new";
window.open(url, "add_menu", "left=100,top=100,width=550,height=650,scrollbars=yes,resizable=yes");
return false;
}
return true;
}
function add_submenu(code) {
var url = "./menu_form.php?code=" + code;
window.open(url, "add_menu", "left=100,top=100,width=550,height=650,scrollbars=yes,resizable=yes");
return false;
}
function base_convert(number, frombase, tobase) {
// discuss at: http://phpjs.org/functions/base_convert/
// original by: Philippe Baumann
// improved by: Rafał Kukawski (http://blog.kukawski.pl)
// example 1: base_convert('A37334', 16, 2);
// returns 1: '101000110111001100110100'
return parseInt(number + '', frombase | 0)
.toString(tobase | 0);
}
function fmenulist_submit(f) {
var me_links = document.getElementsByName('me_link[]');
var reg = /^javascript/;
for (i = 0; i < me_links.length; i++) {
if (reg.test(me_links[i].value)) {
alert('링크에 자바스크립트문을 입력할수 없습니다.');
me_links[i].focus();
return false;
}
}
return true;
}
</script>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+26 -24
View File
@@ -1,11 +1,12 @@
<?php
$sub_menu = "100290";
include_once('./_common.php');
require_once './_common.php';
check_demo();
if ($is_admin != 'super')
if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
check_admin_token();
@@ -15,46 +16,47 @@ sql_query($sql);
$group_code = null;
$primary_code = null;
$count = count($_POST['code']);
$count = isset($_POST['code']) ? count($_POST['code']) : 0;
for ($i=0; $i<$count; $i++)
{
for ($i = 0; $i < $count; $i++) {
$_POST = array_map_deep('trim', $_POST);
if(preg_match('/^javascript/i', preg_replace('/[ ]{1,}|[\t]/', '', $_POST['me_link'][$i]))){
if (preg_match('/^javascript/i', preg_replace('/[ ]{1,}|[\t]/', '', $_POST['me_link'][$i]))) {
$_POST['me_link'][$i] = G5_URL;
}
$_POST['me_link'][$i] = is_array($_POST['me_link']) ? clean_xss_tags(clean_xss_attributes(preg_replace('/[ ]{2,}|[\t]/', '', $_POST['me_link'][$i]), 1)) : '';
$_POST['me_link'][$i] = html_purifier($_POST['me_link'][$i]);
$code = is_array($_POST['code']) ? strip_tags($_POST['code'][$i]) : '';
$me_name = is_array($_POST['me_name']) ? strip_tags($_POST['me_name'][$i]) : '';
$me_link = (preg_match('/^javascript/i', $_POST['me_link'][$i]) || preg_match('/script:/i', $_POST['me_link'][$i])) ? G5_URL : strip_tags(clean_xss_attributes($_POST['me_link'][$i]));
if(!$code || !$me_name || !$me_link)
$me_link = (preg_match('/^javascript/i', $_POST['me_link'][$i]) || preg_match('/script:/i', $_POST['me_link'][$i])) ? G5_URL : addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['me_link'][$i]))));
if (!$code || !$me_name || !$me_link) {
continue;
}
$sub_code = '';
if($group_code == $code) {
if ($group_code == $code) {
$sql = " select MAX(SUBSTRING(me_code,3,2)) as max_me_code
from {$g5['menu_table']}
where SUBSTRING(me_code,1,2) = '$primary_code' ";
$row = sql_fetch($sql);
$sub_code = base_convert($row['max_me_code'], 36, 10);
$sub_code = (int)base_convert($row['max_me_code'], 36, 10);
$sub_code += 36;
$sub_code = base_convert($sub_code, 10, 36);
$sub_code = base_convert((string)$sub_code, 10, 36);
$me_code = $primary_code.$sub_code;
$me_code = $primary_code . $sub_code;
} else {
$sql = " select MAX(SUBSTRING(me_code,1,2)) as max_me_code
from {$g5['menu_table']}
where LENGTH(me_code) = '2' ";
$row = sql_fetch($sql);
$me_code = base_convert($row['max_me_code'], 36, 10);
$me_code = (int)base_convert($row['max_me_code'], 36, 10);
$me_code += 36;
$me_code = base_convert($me_code, 10, 36);
$me_code = base_convert((string)$me_code, 10, 36);
$group_code = $code;
$primary_code = $me_code;
@@ -62,16 +64,16 @@ for ($i=0; $i<$count; $i++)
// 메뉴 등록
$sql = " insert into {$g5['menu_table']}
set me_code = '".$me_code."',
me_name = '".$me_name."',
me_link = '".$me_link."',
me_target = '".sql_real_escape_string(strip_tags($_POST['me_target'][$i]))."',
me_order = '".sql_real_escape_string(strip_tags($_POST['me_order'][$i]))."',
me_use = '".sql_real_escape_string(strip_tags($_POST['me_use'][$i]))."',
me_mobile_use = '".sql_real_escape_string(strip_tags($_POST['me_mobile_use'][$i]))."' ";
set me_code = '" . $me_code . "',
me_name = '" . $me_name . "',
me_link = '" . $me_link . "',
me_target = '" . sql_real_escape_string(strip_tags($_POST['me_target'][$i])) . "',
me_order = '" . sql_real_escape_string(strip_tags($_POST['me_order'][$i])) . "',
me_use = '" . sql_real_escape_string(strip_tags($_POST['me_use'][$i])) . "',
me_mobile_use = '" . sql_real_escape_string(strip_tags($_POST['me_mobile_use'][$i])) . "' ";
sql_query($sql);
}
run_event('admin_menu_list_update');
goto_url('./menu_list.php');
goto_url('./menu_list.php');
+170 -174
View File
@@ -1,174 +1,170 @@
<?php
$sub_menu = '100310';
include_once('./_common.php');
include_once(G5_EDITOR_LIB);
auth_check_menu($auth, $sub_menu, "w");
$nw_id = isset($_REQUEST['nw_id']) ? preg_replace('/[^0-9]/', '', $_REQUEST['nw_id']) : 0;
$nw = array(
'nw_begin_time'=>'',
'nw_end_time'=>'',
'nw_subject'=>'',
'nw_content'=>'',
'nw_division'=>'',
);
$html_title = "팝업레이어";
// 팝업레이어 테이블에 쇼핑몰, 커뮤니티 인지 구분하는 여부 필드 추가
$sql = " ALTER TABLE `{$g5['new_win_table']}` ADD `nw_division` VARCHAR(10) NOT NULL DEFAULT 'both' ";
sql_query($sql, false);
if ($w == "u")
{
$html_title .= " 수정";
$sql = " select * from {$g5['new_win_table']} where nw_id = '$nw_id' ";
$nw = sql_fetch($sql);
if (! (isset($nw['nw_id']) && $nw['nw_id'])) alert("등록된 자료가 없습니다.");
}
else
{
$html_title .= " 입력";
$nw['nw_device'] = 'both';
$nw['nw_disable_hours'] = 24;
$nw['nw_left'] = 10;
$nw['nw_top'] = 10;
$nw['nw_width'] = 450;
$nw['nw_height'] = 500;
$nw['nw_content_html'] = 2;
}
$g5['title'] = $html_title;
include_once (G5_ADMIN_PATH.'/admin.head.php');
?>
<form name="frmnewwin" action="./newwinformupdate.php" onsubmit="return frmnewwin_check(this);" method="post">
<input type="hidden" name="w" value="<?php echo $w; ?>">
<input type="hidden" name="nw_id" value="<?php echo $nw_id; ?>">
<input type="hidden" name="token" value="">
<div class="local_desc01 local_desc">
<p>초기화면 접속 시 자동으로 뜰 팝업레이어를 설정합니다.</p>
</div>
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="nw_division">구분</label></th>
<td>
<?php echo help("커뮤니티에 표시될 것인지 쇼핑몰에 표시될 것인지를 설정합니다."); ?>
<select name="nw_division" id="nw_division">
<option value="comm"<?php echo get_selected($nw['nw_division'], 'comm'); ?>>커뮤니티</option>
<?php if (defined('G5_USE_SHOP') && G5_USE_SHOP) { ?>
<option value="both"<?php echo get_selected($nw['nw_division'], 'both', true); ?>>커뮤니티와 쇼핑몰</option>
<option value="shop"<?php echo get_selected($nw['nw_division'], 'shop'); ?>>쇼핑몰</option>
<?php } ?>
</select>
</td>
</tr>
<tr>
<th scope="row"><label for="nw_device">접속기기</label></th>
<td>
<?php echo help("팝업레이어가 표시될 접속기기를 설정합니다."); ?>
<select name="nw_device" id="nw_device">
<option value="both"<?php echo get_selected($nw['nw_device'], 'both', true); ?>>PC와 모바일</option>
<option value="pc"<?php echo get_selected($nw['nw_device'], 'pc'); ?>>PC</option>
<option value="mobile"<?php echo get_selected($nw['nw_device'], 'mobile'); ?>>모바일</option>
</select>
</td>
</tr>
<tr>
<th scope="row"><label for="nw_disable_hours">시간<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help("고객이 다시 보지 않음을 선택할 시 몇 시간동안 팝업레이어를 보여주지 않을지 설정합니다."); ?>
<input type="text" name="nw_disable_hours" value="<?php echo $nw['nw_disable_hours']; ?>" id="nw_disable_hours" required class="frm_input required" size="5"> 시간
</td>
</tr>
<tr>
<th scope="row"><label for="nw_begin_time">시작일시<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_begin_time" value="<?php echo $nw['nw_begin_time']; ?>" id="nw_begin_time" required class="frm_input required" size="21" maxlength="19">
<input type="checkbox" name="nw_begin_chk" value="<?php echo date("Y-m-d 00:00:00", G5_SERVER_TIME); ?>" id="nw_begin_chk" onclick="if (this.checked == true) this.form.nw_begin_time.value=this.form.nw_begin_chk.value; else this.form.nw_begin_time.value = this.form.nw_begin_time.defaultValue;">
<label for="nw_begin_chk">시작일시를 오늘로</label>
</td>
</tr>
<tr>
<th scope="row"><label for="nw_end_time">종료일시<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_end_time" value="<?php echo $nw['nw_end_time']; ?>" id="nw_end_time" required class="frm_input required" size="21" maxlength="19">
<input type="checkbox" name="nw_end_chk" value="<?php echo date("Y-m-d 23:59:59", G5_SERVER_TIME+(60*60*24*7)); ?>" id="nw_end_chk" onclick="if (this.checked == true) this.form.nw_end_time.value=this.form.nw_end_chk.value; else this.form.nw_end_time.value = this.form.nw_end_time.defaultValue;">
<label for="nw_end_chk">종료일시를 오늘로부터 7일 후로</label>
</td>
</tr>
<tr>
<th scope="row"><label for="nw_left">팝업레이어 좌측 위치<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_left" value="<?php echo $nw['nw_left']; ?>" id="nw_left" required class="frm_input required" size="5"> px
</td>
</tr>
<tr>
<th scope="row"><label for="nw_top">팝업레이어 상단 위치<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_top" value="<?php echo $nw['nw_top']; ?>" id="nw_top" required class="frm_input required" size="5"> px
</td>
</tr>
<tr>
<th scope="row"><label for="nw_width">팝업레이어 넓이<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_width" value="<?php echo $nw['nw_width'] ?>" id="nw_width" required class="frm_input required" size="5"> px
</td>
</tr>
<tr>
<th scope="row"><label for="nw_height">팝업레이어 높이<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_height" value="<?php echo $nw['nw_height'] ?>" id="nw_height" required class="frm_input required" size="5"> px
</td>
</tr>
<tr>
<th scope="row"><label for="nw_subject">팝업 제목<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_subject" value="<?php echo get_sanitize_input($nw['nw_subject']); ?>" id="nw_subject" required class="frm_input required" size="80">
</td>
</tr>
<tr>
<th scope="row"><label for="nw_content">내용</label></th>
<td><?php echo editor_html('nw_content', get_text(html_purifier($nw['nw_content']), 0)); ?></td>
</tr>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<a href="./newwinlist.php" class=" btn btn_02">목록</a>
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
</div>
</form>
<script>
function frmnewwin_check(f)
{
errmsg = "";
errfld = "";
<?php echo get_editor_js('nw_content'); ?>
check_field(f.nw_subject, "제목을 입력하세요.");
if (errmsg != "") {
alert(errmsg);
errfld.focus();
return false;
}
return true;
}
</script>
<?php
include_once (G5_ADMIN_PATH.'/admin.tail.php');
<?php
$sub_menu = '100310';
require_once './_common.php';
require_once G5_EDITOR_LIB;
auth_check_menu($auth, $sub_menu, "w");
$nw_id = isset($_REQUEST['nw_id']) ? (string)preg_replace('/[^0-9]/', '', $_REQUEST['nw_id']) : 0;
$nw = array(
'nw_begin_time' => '',
'nw_end_time' => '',
'nw_subject' => '',
'nw_content' => '',
'nw_division' => '',
);
$html_title = "팝업레이어";
// 팝업레이어 테이블에 쇼핑몰, 커뮤니티 인지 구분하는 여부 필드 추가
if ($w == "u") {
$html_title .= " 수정";
$sql = " select * from {$g5['new_win_table']} where nw_id = '$nw_id' ";
$nw = sql_fetch($sql);
if (!(isset($nw['nw_id']) && $nw['nw_id'])) {
alert("등록된 자료가 없습니다.");
}
} else {
$html_title .= " 입력";
$nw['nw_device'] = 'both';
$nw['nw_disable_hours'] = 24;
$nw['nw_left'] = 10;
$nw['nw_top'] = 10;
$nw['nw_width'] = 450;
$nw['nw_height'] = 500;
$nw['nw_content_html'] = 2;
}
$g5['title'] = $html_title;
require_once G5_ADMIN_PATH . '/admin.head.php';
?>
<form name="frmnewwin" action="./newwinformupdate.php" onsubmit="return frmnewwin_check(this);" method="post">
<input type="hidden" name="w" value="<?php echo $w; ?>">
<input type="hidden" name="nw_id" value="<?php echo $nw_id; ?>">
<input type="hidden" name="token" value="">
<div class="local_desc01 local_desc">
<p>초기화면 접속 시 자동으로 뜰 팝업레이어를 설정합니다.</p>
</div>
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="nw_division">구분</label></th>
<td>
<?php echo help("커뮤니티에 표시될 것인지 쇼핑몰에 표시될 것인지를 설정합니다."); ?>
<select name="nw_division" id="nw_division">
<option value="comm" <?php echo get_selected($nw['nw_division'], 'comm'); ?>>커뮤니티</option>
<?php if (defined('G5_USE_SHOP') && G5_USE_SHOP) { ?>
<option value="both" <?php echo get_selected($nw['nw_division'], 'both', true); ?>>커뮤니티와 쇼핑몰</option>
<option value="shop" <?php echo get_selected($nw['nw_division'], 'shop'); ?>>쇼핑몰</option>
<?php } ?>
</select>
</td>
</tr>
<tr>
<th scope="row"><label for="nw_device">접속기기</label></th>
<td>
<?php echo help("팝업레이어가 표시될 접속기기를 설정합니다."); ?>
<select name="nw_device" id="nw_device">
<option value="both" <?php echo get_selected($nw['nw_device'], 'both', true); ?>>PC와 모바일</option>
<option value="pc" <?php echo get_selected($nw['nw_device'], 'pc'); ?>>PC</option>
<option value="mobile" <?php echo get_selected($nw['nw_device'], 'mobile'); ?>>모바일</option>
</select>
</td>
</tr>
<tr>
<th scope="row"><label for="nw_disable_hours">시간<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help("고객이 다시 보지 않음을 선택할 시 몇 시간동안 팝업레이어를 보여주지 않을지 설정합니다."); ?>
<input type="text" name="nw_disable_hours" value="<?php echo $nw['nw_disable_hours']; ?>" id="nw_disable_hours" required class="frm_input required" size="5"> 시간
</td>
</tr>
<tr>
<th scope="row"><label for="nw_begin_time">시작일시<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_begin_time" value="<?php echo $nw['nw_begin_time']; ?>" id="nw_begin_time" required class="frm_input required" size="21" maxlength="19">
<input type="checkbox" name="nw_begin_chk" value="<?php echo date("Y-m-d 00:00:00", G5_SERVER_TIME); ?>" id="nw_begin_chk" onclick="if (this.checked == true) this.form.nw_begin_time.value=this.form.nw_begin_chk.value; else this.form.nw_begin_time.value = this.form.nw_begin_time.defaultValue;">
<label for="nw_begin_chk">시작일시를 오늘로</label>
</td>
</tr>
<tr>
<th scope="row"><label for="nw_end_time">종료일시<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_end_time" value="<?php echo $nw['nw_end_time']; ?>" id="nw_end_time" required class="frm_input required" size="21" maxlength="19">
<input type="checkbox" name="nw_end_chk" value="<?php echo date("Y-m-d 23:59:59", G5_SERVER_TIME + (60 * 60 * 24 * 7)); ?>" id="nw_end_chk" onclick="if (this.checked == true) this.form.nw_end_time.value=this.form.nw_end_chk.value; else this.form.nw_end_time.value = this.form.nw_end_time.defaultValue;">
<label for="nw_end_chk">종료일시를 오늘로부터 7일 후로</label>
</td>
</tr>
<tr>
<th scope="row"><label for="nw_left">팝업레이어 좌측 위치<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_left" value="<?php echo $nw['nw_left']; ?>" id="nw_left" required class="frm_input required" size="5"> px
</td>
</tr>
<tr>
<th scope="row"><label for="nw_top">팝업레이어 상단 위치<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_top" value="<?php echo $nw['nw_top']; ?>" id="nw_top" required class="frm_input required" size="5"> px
</td>
</tr>
<tr>
<th scope="row"><label for="nw_width">팝업레이어 넓이<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_width" value="<?php echo $nw['nw_width'] ?>" id="nw_width" required class="frm_input required" size="5"> px
</td>
</tr>
<tr>
<th scope="row"><label for="nw_height">팝업레이어 높이<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_height" value="<?php echo $nw['nw_height'] ?>" id="nw_height" required class="frm_input required" size="5"> px
</td>
</tr>
<tr>
<th scope="row"><label for="nw_subject">팝업 제목<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="nw_subject" value="<?php echo get_sanitize_input($nw['nw_subject']); ?>" id="nw_subject" required class="frm_input required" size="80">
</td>
</tr>
<tr>
<th scope="row"><label for="nw_content">내용</label></th>
<td><?php echo editor_html('nw_content', get_text(html_purifier($nw['nw_content']), 0)); ?></td>
</tr>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<a href="./newwinlist.php" class=" btn btn_02">목록</a>
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
</div>
</form>
<script>
function frmnewwin_check(f) {
errmsg = "";
errfld = "";
<?php echo get_editor_js('nw_content'); ?>
check_field(f.nw_subject, "제목을 입력하세요.");
if (errmsg != "") {
alert(errmsg);
errfld.focus();
return false;
}
return true;
}
</script>
<?php
require_once G5_ADMIN_PATH . '/admin.tail.php';
+78 -82
View File
@@ -1,82 +1,78 @@
<?php
$sub_menu = '100310';
include_once('./_common.php');
$nw_id = isset($_REQUEST['nw_id']) ? preg_replace('/[^0-9]/', '', $_REQUEST['nw_id']) : 0;
if ($w == "u" || $w == "d")
check_demo();
if ($w == 'd')
auth_check_menu($auth, $sub_menu, "d");
else
auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
$nw_subject = isset($_POST['nw_subject']) ? strip_tags(clean_xss_attributes($_POST['nw_subject'])) : '';
$posts = array();
$check_keys = array(
'nw_device'=>'str',
'nw_division'=>'str',
'nw_begin_time'=>'str',
'nw_end_time'=>'str',
'nw_disable_hours'=>'int',
'nw_left'=>'int',
'nw_top'=>'int',
'nw_height'=>'int',
'nw_width'=>'int',
'nw_content'=>'text',
'nw_content_html'=>'text',
);
foreach($check_keys as $key=>$val){
if($val === 'int'){
$posts[$key] = isset($_POST[$key]) ? (int) $_POST[$key] : 0;
} else if ($val === 'str') {
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : 0;
} else {
$posts[$key] = isset($_POST[$key]) ? trim($_POST[$key]) : 0;
}
}
$sql_common = " nw_device = '{$posts['nw_device']}',
nw_division = '{$posts['nw_division']}',
nw_begin_time = '{$posts['nw_begin_time']}',
nw_end_time = '{$posts['nw_end_time']}',
nw_disable_hours = '{$posts['nw_disable_hours']}',
nw_left = '{$posts['nw_left']}',
nw_top = '{$posts['nw_top']}',
nw_height = '{$posts['nw_height']}',
nw_width = '{$posts['nw_width']}',
nw_subject = '{$nw_subject}',
nw_content = '{$posts['nw_content']}',
nw_content_html = '{$posts['nw_content_html']}' ";
if($w == "")
{
$sql = " insert {$g5['new_win_table']} set $sql_common ";
sql_query($sql);
$nw_id = sql_insert_id();
}
else if ($w == "u")
{
$sql = " update {$g5['new_win_table']} set $sql_common where nw_id = '$nw_id' ";
sql_query($sql);
}
else if ($w == "d")
{
$sql = " delete from {$g5['new_win_table']} where nw_id = '$nw_id' ";
sql_query($sql);
}
if ($w == "d")
{
goto_url('./newwinlist.php');
}
else
{
goto_url("./newwinform.php?w=u&amp;nw_id=$nw_id");
}
<?php
$sub_menu = '100310';
require_once './_common.php';
$nw_id = isset($_REQUEST['nw_id']) ? (string)preg_replace('/[^0-9]/', '', $_REQUEST['nw_id']) : 0;
if ($w == "u" || $w == "d") {
check_demo();
}
if ($w == 'd') {
auth_check_menu($auth, $sub_menu, "d");
} else {
auth_check_menu($auth, $sub_menu, "w");
}
check_admin_token();
$nw_subject = isset($_POST['nw_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['nw_subject'])))) : '';
$posts = array();
$check_keys = array(
'nw_device' => 'str',
'nw_division' => 'str',
'nw_begin_time' => 'str',
'nw_end_time' => 'str',
'nw_disable_hours' => 'int',
'nw_left' => 'int',
'nw_top' => 'int',
'nw_height' => 'int',
'nw_width' => 'int',
'nw_content' => 'text',
'nw_content_html' => 'text',
);
foreach ($check_keys as $key => $val) {
if ($val === 'int') {
$posts[$key] = isset($_POST[$key]) ? (int) $_POST[$key] : 0;
} elseif ($val === 'str') {
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : 0;
} else {
$posts[$key] = isset($_POST[$key]) ? trim($_POST[$key]) : 0;
}
}
$sql_common = " nw_device = '{$posts['nw_device']}',
nw_division = '{$posts['nw_division']}',
nw_begin_time = '{$posts['nw_begin_time']}',
nw_end_time = '{$posts['nw_end_time']}',
nw_disable_hours = '{$posts['nw_disable_hours']}',
nw_left = '{$posts['nw_left']}',
nw_top = '{$posts['nw_top']}',
nw_height = '{$posts['nw_height']}',
nw_width = '{$posts['nw_width']}',
nw_subject = '{$nw_subject}',
nw_content = '{$posts['nw_content']}',
nw_content_html = '{$posts['nw_content_html']}' ";
if ($w == "") {
$sql = " insert {$g5['new_win_table']} set $sql_common ";
sql_query($sql);
$nw_id = sql_insert_id();
run_event('admin_newwin_created', $nw_id);
} elseif ($w == "u") {
$sql = " update {$g5['new_win_table']} set $sql_common where nw_id = '$nw_id' ";
sql_query($sql);
run_event('admin_newwin_updated', $nw_id);
} elseif ($w == "d") {
$sql = " delete from {$g5['new_win_table']} where nw_id = '$nw_id' ";
sql_query($sql);
run_event('admin_newwin_deleted', $nw_id);
}
if ($w == "d") {
goto_url('./newwinlist.php');
} else {
goto_url("./newwinform.php?w=u&amp;nw_id=$nw_id");
}
+96 -118
View File
@@ -1,118 +1,96 @@
<?php
$sub_menu = '100310';
include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "r");
if( !isset($g5['new_win_table']) ){
die('<meta charset="utf-8">/data/dbconfig.php 파일에 <strong>$g5[\'new_win_table\'] = G5_TABLE_PREFIX.\'new_win\';</strong> 를 추가해 주세요.');
}
//내용(컨텐츠)정보 테이블이 있는지 검사한다.
if(!sql_query(" DESCRIBE {$g5['new_win_table']} ", false)) {
if(sql_query(" DESCRIBE {$g5['g5_shop_new_win_table']} ", false)) {
sql_query(" ALTER TABLE {$g5['g5_shop_new_win_table']} RENAME TO `{$g5['new_win_table']}` ;", false);
} else {
$query_cp = sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['new_win_table']}` (
`nw_id` int(11) NOT NULL AUTO_INCREMENT,
`nw_division` varchar(10) NOT NULL DEFAULT 'both',
`nw_device` varchar(10) NOT NULL DEFAULT 'both',
`nw_begin_time` datetime NOT NULL DEFAULT '0000-00-00 00:00:00',
`nw_end_time` datetime NOT NULL DEFAULT '0000-00-00 00:00:00',
`nw_disable_hours` int(11) NOT NULL DEFAULT '0',
`nw_left` int(11) NOT NULL DEFAULT '0',
`nw_top` int(11) NOT NULL DEFAULT '0',
`nw_height` int(11) NOT NULL DEFAULT '0',
`nw_width` int(11) NOT NULL DEFAULT '0',
`nw_subject` text NOT NULL,
`nw_content` text NOT NULL,
`nw_content_html` tinyint(4) NOT NULL DEFAULT '0',
PRIMARY KEY (`nw_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8 ", true);
}
}
$g5['title'] = '팝업레이어 관리';
include_once (G5_ADMIN_PATH.'/admin.head.php');
$sql_common = " from {$g5['new_win_table']} ";
// 테이블의 전체 레코드수만 얻음
$sql = " select count(*) as cnt " . $sql_common;
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql = "select * $sql_common order by nw_id desc ";
$result = sql_query($sql);
?>
<div class="local_ov01 local_ov"><span class="btn_ov01"><span class="ov_txt">전체 </span><span class="ov_num"> <?php echo $total_count; ?>건</span></span></div>
<div class="btn_fixed_top ">
<a href="./newwinform.php" class="btn btn_01">새창관리추가</a>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">번호</th>
<th scope="col">제목</th>
<th scope="col">접속기기</th>
<th scope="col">시작일시</th>
<th scope="col">종료일시</th>
<th scope="col">시간</th>
<th scope="col">Left</th>
<th scope="col">Top</th>
<th scope="col">Width</th>
<th scope="col">Height</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++) {
$bg = 'bg'.($i%2);
switch($row['nw_device']) {
case 'pc':
$nw_device = 'PC';
break;
case 'mobile':
$nw_device = '모바일';
break;
default:
$nw_device = '모두';
break;
}
?>
<tr class="<?php echo $bg; ?>">
<td class="td_num"><?php echo $row['nw_id']; ?></td>
<td class="td_left"><?php echo $row['nw_subject']; ?></td>
<td class="td_device"><?php echo $nw_device; ?></td>
<td class="td_datetime"><?php echo substr($row['nw_begin_time'],2,14); ?></td>
<td class="td_datetime"><?php echo substr($row['nw_end_time'],2,14); ?></td>
<td class="td_num"><?php echo $row['nw_disable_hours']; ?>시간</td>
<td class="td_num"><?php echo $row['nw_left']; ?>px</td>
<td class="td_num"><?php echo $row['nw_top']; ?>px</td>
<td class="td_num"><?php echo $row['nw_width']; ?>px</td>
<td class="td_num"><?php echo $row['nw_height']; ?>px</td>
<td class="td_mng td_mng_m">
<a href="./newwinform.php?w=u&amp;nw_id=<?php echo $row['nw_id']; ?>" class="btn btn_03"><span class="sound_only"><?php echo $row['nw_subject']; ?> </span>수정</a>
<a href="./newwinformupdate.php?w=d&amp;nw_id=<?php echo $row['nw_id']; ?>" onclick="return delete_confirm(this);" class="btn btn_02"><span class="sound_only"><?php echo $row['nw_subject']; ?> </span>삭제</a>
</td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="11" class="empty_table">자료가 한건도 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<?php
include_once (G5_ADMIN_PATH.'/admin.tail.php');
<?php
$sub_menu = '100310';
require_once './_common.php';
auth_check_menu($auth, $sub_menu, "r");
if (!isset($g5['new_win_table'])) {
die('<meta charset="utf-8">/data/dbconfig.php 파일에 <strong>$g5[\'new_win_table\'] = G5_TABLE_PREFIX.\'new_win\';</strong> 를 추가해 주세요.');
}
//내용(컨텐츠)정보 테이블이 있는지 검사한다.
$g5['title'] = '팝업레이어 관리';
require_once G5_ADMIN_PATH . '/admin.head.php';
$sql_common = " from {$g5['new_win_table']} ";
// 테이블의 전체 레코드수만 얻음
$sql = " select count(*) as cnt " . $sql_common;
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql = "select * $sql_common order by nw_id desc ";
$result = sql_query($sql);
?>
<div class="local_ov01 local_ov"><span class="btn_ov01"><span class="ov_txt">전체 </span><span class="ov_num"> <?php echo $total_count; ?>건</span></span></div>
<div class="btn_fixed_top ">
<a href="./newwinform.php" class="btn btn_01">새창관리추가</a>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">번호</th>
<th scope="col">제목</th>
<th scope="col">접속기기</th>
<th scope="col">시작일시</th>
<th scope="col">종료일시</th>
<th scope="col">시간</th>
<th scope="col">Left</th>
<th scope="col">Top</th>
<th scope="col">Width</th>
<th scope="col">Height</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$bg = 'bg' . ($i % 2);
switch ($row['nw_device']) {
case 'pc':
$nw_device = 'PC';
break;
case 'mobile':
$nw_device = '모바일';
break;
default:
$nw_device = '모두';
break;
}
?>
<tr class="<?php echo $bg; ?>">
<td class="td_num"><?php echo $row['nw_id']; ?></td>
<td class="td_left"><?php echo $row['nw_subject']; ?></td>
<td class="td_device"><?php echo $nw_device; ?></td>
<td class="td_datetime"><?php echo substr($row['nw_begin_time'], 2, 14); ?></td>
<td class="td_datetime"><?php echo substr($row['nw_end_time'], 2, 14); ?></td>
<td class="td_num"><?php echo $row['nw_disable_hours']; ?>시간</td>
<td class="td_num"><?php echo $row['nw_left']; ?>px</td>
<td class="td_num"><?php echo $row['nw_top']; ?>px</td>
<td class="td_num"><?php echo $row['nw_width']; ?>px</td>
<td class="td_num"><?php echo $row['nw_height']; ?>px</td>
<td class="td_mng td_mng_m">
<a href="./newwinform.php?w=u&amp;nw_id=<?php echo $row['nw_id']; ?>" class="btn btn_03"><span class="sound_only"><?php echo $row['nw_subject']; ?> </span>수정</a>
<a href="./newwinformupdate.php?w=d&amp;nw_id=<?php echo $row['nw_id']; ?>" onclick="return delete_confirm(this);" class="btn btn_02"><span class="sound_only"><?php echo $row['nw_subject']; ?> </span>삭제</a>
</td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="11" class="empty_table">자료가 한건도 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<?php
require_once G5_ADMIN_PATH . '/admin.tail.php';
+2 -2
View File
@@ -1,9 +1,9 @@
<?php
$sub_menu = "100500";
include_once('./_common.php');
require_once './_common.php';
check_demo();
auth_check_menu($auth, $sub_menu, 'r');
phpinfo();
phpinfo();
+161 -148
View File
@@ -1,20 +1,25 @@
<?php
$sub_menu = "200200";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
$sql_common = " from {$g5['point_table']} ";
$sql_common = " from {$g5['point_table']} po";
$allowed_sfl = array('mb_id', 'po_content');
if (!in_array($sfl, $allowed_sfl)) {
$sfl = 'mb_id';
}
$sql_search = " where (1) ";
if ($stx) {
$sql_search .= " and ( ";
switch ($sfl) {
case 'mb_id' :
$sql_search .= " ({$sfl} = '{$stx}') ";
case 'mb_id':
$sql_search .= " (po.{$sfl} = '{$stx}') ";
break;
default :
default:
$sql_search .= " ({$sfl} like '%{$stx}%') ";
break;
}
@@ -25,6 +30,9 @@ if (!$sst) {
$sst = "po_id";
$sod = "desc";
}
$allowed_sst = array('po_id', 'mb_id', 'po_content', 'po_point', 'po_datetime');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'po_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
@@ -36,36 +44,41 @@ $total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) $page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
if ($page < 1) {
$page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
}
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select *
$sql = " select po.*, mb.mb_name, mb.mb_nick, mb.mb_email, mb.mb_homepage, mb.mb_point
{$sql_common}
LEFT JOIN {$g5['member_table']} mb ON po.mb_id = mb.mb_id
{$sql_search}
{$sql_order}
limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목록</a>';
$listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall">전체목록</a>';
$mb = array();
if ($sfl == 'mb_id' && $stx)
if ($sfl == 'mb_id' && $stx) {
$mb = get_member($stx);
}
$g5['title'] = '포인트관리';
include_once ('./admin.head.php');
require_once './admin.head.php';
$colspan = 9;
$po_expire_term = '';
if($config['cf_point_term'] > 0) {
if ($config['cf_point_term'] > 0) {
$po_expire_term = $config['cf_point_term'];
}
if (strstr($sfl, "mb_id"))
if (strpos($sfl, "mb_id") !== false) {
$mb_id = $stx;
else
} else {
$mb_id = "";
}
?>
<div class="local_ov01 local_ov">
@@ -73,109 +86,110 @@ else
<span class="btn_ov01"><span class="ov_txt">전체 </span><span class="ov_num"> <?php echo number_format($total_count) ?> 건 </span></span>
<?php
if (isset($mb['mb_id']) && $mb['mb_id']) {
echo '&nbsp;<span class="btn_ov01"><span class="ov_txt">' . $mb['mb_id'] .' 님 포인트 합계 </span><span class="ov_num"> ' . number_format($mb['mb_point']) . '점</span></span>';
echo '&nbsp;<span class="btn_ov01"><span class="ov_txt">' . $mb['mb_id'] . ' 님 포인트 합계 </span><span class="ov_num"> ' . number_format($mb['mb_point']) . '점</span></span>';
} else {
$row2 = sql_fetch(" select sum(po_point) as sum_point from {$g5['point_table']} ");
echo '&nbsp;<span class="btn_ov01"><span class="ov_txt">전체 합계</span><span class="ov_num">'.number_format($row2['sum_point']).'점 </span></span>';
echo '&nbsp;<span class="btn_ov01"><span class="ov_txt">전체 합계</span><span class="ov_num">' . number_format($row2['sum_point']) . '점 </span></span>';
}
?>
</div>
<form name="fsearch" id="fsearch" class="local_sch01 local_sch" method="get">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="mb_id"<?php echo get_selected($sfl, "mb_id"); ?>>회원아이디</option>
<option value="po_content"<?php echo get_selected($sfl, "po_content"); ?>>내용</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" class="btn_submit" value="검색">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="mb_id" <?php echo get_selected($sfl, "mb_id"); ?>>회원아이디</option>
<option value="po_content" <?php echo get_selected($sfl, "po_content"); ?>>내용</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" class="btn_submit" value="검색">
</form>
<form name="fpointlist" id="fpointlist" method="post" action="./point_list_delete.php" onsubmit="return fpointlist_submit(this);">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">포인트 내역 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('mb_id') ?>회원아이디</a></th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col"><?php echo subject_sort_link('po_content') ?>포인트 내용</a></th>
<th scope="col"><?php echo subject_sort_link('po_point') ?>포인트</a></th>
<th scope="col"><?php echo subject_sort_link('po_datetime') ?>일시</a></th>
<th scope="col">만료일</th>
<th scope="col">포인트합</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++) {
if ($i==0 || ($row2['mb_id'] != $row['mb_id'])) {
$sql2 = " select mb_id, mb_name, mb_nick, mb_email, mb_homepage, mb_point from {$g5['member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
}
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">포인트 내역 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('mb_id') ?>회원아이디</a></th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col"><?php echo subject_sort_link('po_content') ?>포인트 내용</a></th>
<th scope="col"><?php echo subject_sort_link('po_point') ?>포인트</a></th>
<th scope="col"><?php echo subject_sort_link('po_datetime') ?>일시</a></th>
<th scope="col">만료일</th>
<th scope="col">포인트합</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$mb_nick = get_sideview($row['mb_id'], $row['mb_nick'], $row['mb_email'], $row['mb_homepage']);
$mb_nick = get_sideview($row['mb_id'], $row2['mb_nick'], $row2['mb_email'], $row2['mb_homepage']);
$link1 = $link2 = '';
if (!preg_match("/^\@/", $row['po_rel_table']) && $row['po_rel_table']) {
$link1 = '<a href="' . get_pretty_url($row['po_rel_table'], $row['po_rel_id']) . '" target="_blank">';
$link2 = '</a>';
}
$link1 = $link2 = '';
if (!preg_match("/^\@/", $row['po_rel_table']) && $row['po_rel_table']) {
$link1 = '<a href="'.get_pretty_url($row['po_rel_table'], $row['po_rel_id']).'" target="_blank">';
$link2 = '</a>';
}
$expr = '';
if ($row['po_expired'] == 1) {
$expr = ' txt_expired';
}
$expr = '';
if($row['po_expired'] == 1)
$expr = ' txt_expired';
$bg = 'bg' . ($i % 2);
?>
$bg = 'bg'.($i%2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<input type="hidden" name="mb_id[<?php echo $i ?>]" value="<?php echo $row['mb_id'] ?>" id="mb_id_<?php echo $i ?>">
<input type="hidden" name="po_id[<?php echo $i ?>]" value="<?php echo $row['po_id'] ?>" id="po_id_<?php echo $i ?>">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['po_content'] ?> 내역</label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_left"><a href="?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
<td class="td_left"><?php echo get_text($row['mb_name']); ?></td>
<td class="td_left sv_use">
<div><?php echo $mb_nick ?></div>
</td>
<td class="td_left"><?php echo $link1 ?><?php echo $row['po_content'] ?><?php echo $link2 ?></td>
<td class="td_num td_pt"><?php echo number_format($row['po_point']) ?></td>
<td class="td_datetime"><?php echo $row['po_datetime'] ?></td>
<td class="td_datetime2<?php echo $expr; ?>">
<?php if ($row['po_expired'] == 1) { ?>
만료<?php echo substr(str_replace('-', '', $row['po_expire_date']), 2); ?>
<?php } else {
echo $row['po_expire_date'] == '9999-12-31' ? '&nbsp;' : $row['po_expire_date'];
} ?>
</td>
<td class="td_num td_pt"><?php echo number_format($row['po_mb_point']) ?></td>
</tr>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<input type="hidden" name="mb_id[<?php echo $i ?>]" value="<?php echo $row['mb_id'] ?>" id="mb_id_<?php echo $i ?>">
<input type="hidden" name="po_id[<?php echo $i ?>]" value="<?php echo $row['po_id'] ?>" id="po_id_<?php echo $i ?>">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $row['po_content'] ?> 내역</label>
<input type="checkbox" name="chk[]" value="<?php echo $i ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_left"><a href="?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
<td class="td_left"><?php echo get_text($row2['mb_name']); ?></td>
<td class="td_left sv_use"><div><?php echo $mb_nick ?></div></td>
<td class="td_left"><?php echo $link1 ?><?php echo $row['po_content'] ?><?php echo $link2 ?></td>
<td class="td_num td_pt"><?php echo number_format($row['po_point']) ?></td>
<td class="td_datetime"><?php echo $row['po_datetime'] ?></td>
<td class="td_datetime2<?php echo $expr; ?>">
<?php if ($row['po_expired'] == 1) { ?>
만료<?php echo substr(str_replace('-', '', $row['po_expire_date']), 2); ?>
<?php } else echo $row['po_expire_date'] == '9999-12-31' ? '&nbsp;' : $row['po_expire_date']; ?>
</td>
<td class="td_num td_pt"><?php echo number_format($row['po_mb_point']) ?></td>
</tr>
<?php
}
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
if ($i == 0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<input type="submit" name="act_button" value="선택삭제" onclick="document.pressed=this.value" class="btn btn_02">
</div>
<div class="btn_fixed_top">
<input type="submit" name="act_button" value="선택삭제" onclick="document.pressed=this.value" class="btn btn_02">
</div>
</form>
@@ -185,67 +199,66 @@ else
<h2 class="h2_frm">개별회원 포인트 증감 설정</h2>
<form name="fpointlist2" method="post" id="fpointlist2" action="./point_update.php" autocomplete="off">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo isset($token) ? $token : ''; ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo isset($token) ? $token : ''; ?>">
<div class="tbl_frm01 tbl_wrap">
<table>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="mb_id">회원아이디<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="mb_id" value="<?php echo $mb_id ?>" id="mb_id" class="required frm_input" required></td>
</tr>
<tr>
<th scope="row"><label for="po_content">포인트 내용<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="po_content" id="po_content" required class="required frm_input" size="80"></td>
</tr>
<tr>
<th scope="row"><label for="po_point">포인트<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="po_point" id="po_point" required class="required frm_input"></td>
</tr>
<?php if($config['cf_point_term'] > 0) { ?>
<tr>
<th scope="row"><label for="po_expire_term">포인트 유효기간</label></th>
<td><input type="text" name="po_expire_term" value="<?php echo $po_expire_term; ?>" id="po_expire_term" class="frm_input" size="5"> 일</td>
</tr>
<?php } ?>
</tbody>
</table>
</div>
<div class="tbl_frm01 tbl_wrap">
<table>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="mb_id">회원아이디<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="mb_id" value="<?php echo $mb_id ?>" id="mb_id" class="required frm_input" required></td>
</tr>
<tr>
<th scope="row"><label for="po_content">포인트 내용<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="po_content" id="po_content" required class="required frm_input" size="80"></td>
</tr>
<tr>
<th scope="row"><label for="po_point">포인트<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="po_point" id="po_point" required class="required frm_input"></td>
</tr>
<?php if ($config['cf_point_term'] > 0) { ?>
<tr>
<th scope="row"><label for="po_expire_term">포인트 유효기간</label></th>
<td><input type="text" name="po_expire_term" value="<?php echo $po_expire_term; ?>" id="po_expire_term" class="frm_input" size="5"> 일</td>
</tr>
<?php } ?>
</tbody>
</table>
</div>
<div class="btn_confirm01 btn_confirm">
<input type="submit" value="확인" class="btn_submit btn">
</div>
<div class="btn_confirm01 btn_confirm">
<input type="submit" value="확인" class="btn_submit btn">
</div>
</form>
</section>
<script>
function fpointlist_submit(f)
{
if (!is_checked("chk[]")) {
alert(document.pressed+" 하실 항목을 하나 이상 선택하세요.");
return false;
}
if(document.pressed == "선택삭제") {
if(!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
function fpointlist_submit(f) {
if (!is_checked("chk[]")) {
alert(document.pressed + " 하실 항목을 하나 이상 선택하세요.");
return false;
}
}
return true;
}
if (document.pressed == "선택삭제") {
if (!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
return false;
}
}
return true;
}
</script>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+14 -12
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = '200200';
include_once('./_common.php');
require_once './_common.php';
check_demo();
@@ -9,11 +9,11 @@ auth_check_menu($auth, $sub_menu, 'd');
check_admin_token();
$count = (isset($_POST['chk']) && is_array($_POST['chk'])) ? count($_POST['chk']) : 0;
if(!$count)
alert($_POST['act_button'].' 하실 항목을 하나 이상 체크하세요.');
if (!$count) {
alert($_POST['act_button'] . ' 하실 항목을 하나 이상 체크하세요.');
}
for ($i=0; $i<$count; $i++)
{
for ($i = 0; $i < $count; $i++) {
// 실제 번호를 넘김
$k = $_POST['chk'][$i];
$po_id = (int) $_POST['po_id'][$k];
@@ -23,19 +23,21 @@ for ($i=0; $i<$count; $i++)
$sql = " select * from {$g5['point_table']} where po_id = '{$po_id}' ";
$row = sql_fetch($sql);
if(!$row['po_id'])
if (!$row['po_id']) {
continue;
}
if($row['po_point'] < 0) {
if ($row['po_point'] < 0) {
$mb_id = $row['mb_id'];
$po_point = abs($row['po_point']);
if($row['po_rel_table'] == '@expire')
if ($row['po_rel_table'] == '@expire') {
delete_expire_point($mb_id, $po_point);
else
} else {
delete_use_point($mb_id, $po_point);
}
} else {
if($row['po_use_point'] > 0) {
if ($row['po_use_point'] > 0) {
insert_use_point($row['mb_id'], $row['po_use_point'], $row['po_id']);
}
}
@@ -53,8 +55,8 @@ for ($i=0; $i<$count; $i++)
// 포인트 UPDATE
$sum_point = get_point_sum($_POST['mb_id'][$k]);
$sql= " update {$g5['member_table']} set mb_point = '$sum_point' where mb_id = '{$str_mb_id}' ";
$sql = " update {$g5['member_table']} set mb_point = '$sum_point' where mb_id = '{$str_mb_id}' ";
sql_query($sql);
}
goto_url('./point_list.php?'.$qstr);
goto_url('./point_list.php?' . $qstr);
+10 -8
View File
@@ -1,24 +1,26 @@
<?php
$sub_menu = "200200";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
$mb_id = isset($_POST['mb_id']) ? strip_tags(clean_xss_attributes($_POST['mb_id'])) : '';
$po_point = isset($_POST['po_point']) ? strip_tags(clean_xss_attributes($_POST['po_point'])) : 0;
$po_point = isset($_POST['po_point']) ? (int)strip_tags(clean_xss_attributes($_POST['po_point'])) : 0;
$po_content = isset($_POST['po_content']) ? strip_tags(clean_xss_attributes($_POST['po_content'])) : '';
$expire = isset($_POST['po_expire_term']) ? preg_replace('/[^0-9]/', '', $_POST['po_expire_term']) : '';
$mb = get_member($mb_id);
if (!$mb['mb_id'])
alert('존재하는 회원아이디가 아닙니다.', './point_list.php?'.$qstr);
if (!$mb['mb_id']) {
alert('존재하는 회원아이디가 아닙니다.', './point_list.php?' . $qstr);
}
if (($po_point < 0) && ($po_point * (-1) > $mb['mb_point']))
alert('포인트를 깎는 경우 현재 포인트보다 작으면 안됩니다.', './point_list.php?'.$qstr);
if (($po_point < 0) && ($po_point * (-1) > $mb['mb_point'])) {
alert('포인트를 깎는 경우 현재 포인트보다 작으면 안됩니다.', './point_list.php?' . $qstr);
}
insert_point($mb_id, $po_point, $po_content, '@passive', $mb_id, $member['mb_id'].'-'.uniqid(''), $expire);
insert_point($mb_id, $po_point, $po_content, '@passive', $mb_id, $member['mb_id'] . '-' . uniqid(''), $expire);
goto_url('./point_list.php?'.$qstr);
goto_url('./point_list.php?' . $qstr);
+5 -4
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = "200900";
include_once('./_common.php');
require_once './_common.php';
check_demo();
@@ -10,10 +10,11 @@ check_admin_token();
$count = (isset($_POST['chk']) && is_array($_POST['chk'])) ? count($_POST['chk']) : 0;
if(!$count)
if (!$count) {
alert('삭제할 투표목록을 1개이상 선택해 주세요.');
}
for($i=0; $i<$count; $i++) {
for ($i = 0; $i < $count; $i++) {
$po_id = isset($_POST['chk'][$i]) ? (int) $_POST['chk'][$i] : 0;
$sql = " delete from {$g5['poll_table']} where po_id = '$po_id' ";
@@ -23,4 +24,4 @@ for($i=0; $i<$count; $i++) {
sql_query($sql);
}
goto_url('./poll_list.php?'.$qstr);
goto_url('./poll_list.php?' . $qstr);
+93 -87
View File
@@ -1,121 +1,127 @@
<?php
$sub_menu = "200900";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'w');
$po_id = isset($po_id) ? (int) $po_id : 0;
$po = array(
'po_subject'=>'',
'po_etc'=>'',
'po_level'=>'',
'po_point'=>'',
'po_subject' => '',
'po_etc' => '',
'po_level' => '',
'po_point' => '',
);
$html_title = '투표';
if ($w == '')
if ($w == '') {
$html_title .= ' 생성';
else if ($w == 'u') {
} elseif ($w == 'u') {
$html_title .= ' 수정';
$sql = " select * from {$g5['poll_table']} where po_id = '{$po_id}' ";
$po = sql_fetch($sql);
} else
} else {
alert('w 값이 제대로 넘어오지 않았습니다.');
}
$g5['title'] = $html_title;
include_once('./admin.head.php');
require_once './admin.head.php';
?>
<form name="fpoll" id="fpoll" action="./poll_form_update.php" method="post" enctype="multipart/form-data">
<input type="hidden" name="po_id" value="<?php echo $po_id ?>">
<input type="hidden" name="w" value="<?php echo $w ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<input type="hidden" name="po_id" value="<?php echo $po_id ?>">
<input type="hidden" name="w" value="<?php echo $w ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<div class="tbl_frm01 tbl_wrap">
<div class="tbl_frm01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?></caption>
<tbody>
<tr>
<th scope="row"><label for="po_subject">투표 제목<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="po_subject" value="<?php echo get_sanitize_input($po['po_subject']); ?>" id="po_subject" required class="required frm_input" size="80" maxlength="125"></td>
</tr>
<table>
<caption><?php echo $g5['title']; ?></caption>
<tbody>
<tr>
<th scope="row"><label for="po_subject">투표 제목<strong class="sound_only">필수</strong></label></th>
<td><input type="text" name="po_subject" value="<?php echo get_sanitize_input($po['po_subject']); ?>" id="po_subject" required class="required frm_input" size="80" maxlength="125"></td>
</tr>
<?php
for ($i=1; $i<=9; $i++) {
$required = '';
if ($i==1 || $i==2) {
$required = 'required';
$sound_only = '<strong class="sound_only">필수</strong>';
}
<?php
for ($i = 1; $i <= 9; $i++) {
$required = '';
$sound_only = '';
if ($i == 1 || $i == 2) {
$required = 'required';
$sound_only = '<strong class="sound_only">필수</strong>';
}
$po_poll = isset($po['po_poll'.$i]) ? get_text($po['po_poll'.$i]) : '';
$po_cnt = isset($po['po_cnt'.$i]) ? get_text($po['po_cnt'.$i]) : 0;
?>
$po_poll = isset($po['po_poll' . $i]) ? get_text($po['po_poll' . $i]) : '';
$po_cnt = isset($po['po_cnt' . $i]) ? get_text($po['po_cnt' . $i]) : 0;
?>
<tr>
<th scope="row"><label for="po_poll<?php echo $i ?>">항목 <?php echo $i ?><?php echo $sound_only ?></label></th>
<td>
<input type="text" name="po_poll<?php echo $i ?>" value="<?php echo $po_poll ?>" id="po_poll<?php echo $i ?>" <?php echo $required ?> class="frm_input <?php echo $required ?>" maxlength="125">
<label for="po_cnt<?php echo $i ?>">항목 <?php echo $i ?> 투표수</label>
<input type="text" name="po_cnt<?php echo $i ?>" value="<?php echo $po_cnt; ?>" id="po_cnt<?php echo $i ?>" class="frm_input" size="3">
</td>
</tr>
<tr>
<th scope="row"><label for="po_poll<?php echo $i ?>">항목 <?php echo $i ?><?php echo $sound_only ?></label></th>
<td>
<input type="text" name="po_poll<?php echo $i ?>" value="<?php echo $po_poll ?>" id="po_poll<?php echo $i ?>" <?php echo $required ?> class="frm_input <?php echo $required ?>" maxlength="125">
<label for="po_cnt<?php echo $i ?>">항목 <?php echo $i ?> 투표수</label>
<input type="text" name="po_cnt<?php echo $i ?>" value="<?php echo $po_cnt; ?>" id="po_cnt<?php echo $i ?>" class="frm_input" size="3">
</td>
</tr>
<?php } ?>
<?php } ?>
<tr>
<th scope="row"><label for="po_etc">기타의견</label></th>
<td>
<?php echo help('기타 의견을 남길 수 있도록 하려면, 간단한 질문을 입력하세요.') ?>
<input type="text" name="po_etc" value="<?php echo get_text($po['po_etc']) ?>" id="po_etc" class="frm_input" size="80" maxlength="125">
</td>
</tr>
<tr>
<th scope="row"><label for="po_level">투표가능 회원레벨</label></th>
<td>
<?php echo help("레벨을 1로 설정하면 손님도 투표할 수 있습니다.") ?>
<?php echo get_member_level_select('po_level', 1, 10, $po['po_level']) ?> 이상 투표할 수 있음
</td>
</tr>
<tr>
<th scope="row"><label for="po_point">포인트</label></th>
<td>
<?php echo help('투표에 참여한 회원에게 포인트를 부여합니다.') ?>
<input type="text" name="po_point" value="<?php echo $po['po_point'] ?>" id="po_point" class="frm_input"> 점
</td>
</tr>
<tr>
<th scope="row"><label for="po_etc">기타의견</label></th>
<td>
<?php echo help('기타 의견을 남길 수 있도록 하려면, 간단한 질문을 입력하세요.') ?>
<input type="text" name="po_etc" value="<?php echo get_text($po['po_etc']) ?>" id="po_etc" class="frm_input" size="80" maxlength="125">
</td>
</tr>
<tr>
<th scope="row"><label for="po_level">투표가능 회원레벨</label></th>
<td>
<?php echo help("레벨을 1로 설정하면 손님도 투표할 수 있습니다.") ?>
<?php echo get_member_level_select('po_level', 1, 10, $po['po_level']) ?> 이상 투표할 수 있음
</td>
</tr>
<tr>
<th scope="row"><label for="po_point">포인트</label></th>
<td>
<?php echo help('투표에 참여한 회원에게 포인트를 부여합니다.') ?>
<input type="text" name="po_point" value="<?php echo $po['po_point'] ?>" id="po_point" class="frm_input"> 점
</td>
</tr>
<?php if ($w == 'u') { ?>
<tr>
<th scope="row">투표등록일</th>
<td><?php echo $po['po_date']; ?></td>
</tr>
<tr>
<th scope="row"><label for="po_ips">투표참가 IP</label></th>
<td><textarea name="po_ips" id="po_ips" readonly rows="10"><?php echo preg_replace("/\n/", " / ", $po['po_ips']) ?></textarea></td>
</tr>
<tr>
<th scope="row"><label for="mb_ids">투표참가 회원</label></th>
<td><textarea name="mb_ids" id="mb_ids" readonly rows="10"><?php echo preg_replace("/\n/", " / ", $po['mb_ids']) ?></textarea></td>
</tr>
<?php } ?>
</tbody>
</table>
<?php if ($w == 'u') { ?>
<tr>
<th scope="row">투표사용</th>
<td><input type="checkbox" name="po_use" id="po_use" value="1" <?php if ($po['po_use']) { echo 'checked="checked"'; } ?>> <label for="po_use">사용</label></td>
</tr>
<tr>
<th scope="row">투표등록일</th>
<td><?php echo $po['po_date']; ?></td>
</tr>
<tr>
<th scope="row"><label for="po_ips">투표참가 IP</label></th>
<td><textarea name="po_ips" id="po_ips" readonly rows="10"><?php echo html_purifier(preg_replace("/\n/", " / ", $po['po_ips'])); ?></textarea></td>
</tr>
<tr>
<th scope="row"><label for="mb_ids">투표참가 회원</label></th>
<td><textarea name="mb_ids" id="mb_ids" readonly rows="10"><?php echo html_purifier(preg_replace("/\n/", " / ", $po['mb_ids'])); ?></textarea></td>
</tr>
<?php } ?>
</tbody>
</table>
</div>
</div>
<div class="btn_fixed_top ">
<a href="./poll_list.php?<?php echo $qstr ?>" class="btn_02 btn">목록</a>
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
</div>
<div class="btn_fixed_top ">
<a href="./poll_list.php?<?php echo $qstr ?>" class="btn_02 btn">목록</a>
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
</div>
</form>
<?php
include_once('./admin.tail.php');
require_once './admin.tail.php';
+51 -44
View File
@@ -1,60 +1,67 @@
<?php
$sub_menu = "200900";
include_once('./_common.php');
require_once './_common.php';
$w = $_POST['w'];
if ($w == 'u' || $w == 'd')
if ($w == 'u' || $w == 'd') {
check_demo();
}
auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
$check_keys = array(
'po_subject',
'po_poll1',
'po_poll2',
'po_poll3',
'po_poll4',
'po_poll5',
'po_poll6',
'po_poll7',
'po_poll8',
'po_poll9',
'po_cnt1',
'po_cnt2',
'po_cnt3',
'po_cnt4',
'po_cnt5',
'po_cnt6',
'po_cnt7',
'po_cnt8',
'po_cnt9',
'po_etc',
'po_level',
'po_point',
'po_id'
'po_subject',
'po_poll1',
'po_poll2',
'po_poll3',
'po_poll4',
'po_poll5',
'po_poll6',
'po_poll7',
'po_poll8',
'po_poll9',
'po_cnt1',
'po_cnt2',
'po_cnt3',
'po_cnt4',
'po_cnt5',
'po_cnt6',
'po_cnt7',
'po_cnt8',
'po_cnt9',
'po_etc',
'po_level',
'po_point',
'po_id'
);
foreach( $_POST as $key=>$value ){
if( empty($value) ) continue;
foreach ($_POST as $key => $value) {
if (empty($value)) {
continue;
}
if( in_array($key, $check_keys) ) {
$_POST[$key] = strip_tags(clean_xss_attributes($value));
if (in_array($key, $check_keys)) {
if (preg_match('/^po_cnt[1-9]$/', $key) || in_array($key, array('po_level', 'po_point', 'po_id'), true)) {
$_POST[$key] = (int) $value;
} else {
$_POST[$key] = addslashes(strip_tags(clean_xss_attributes(stripslashes($value))));
}
}
}
if ($w == '')
{
$po_id = isset($_POST['po_id']) ? (int) $_POST['po_id'] : 0;
$_POST['po_use'] = isset($_POST['po_use']) ? (int) $_POST['po_use'] : 0;
if ($w == '') {
$sql = " insert {$g5['poll_table']}
( po_subject, po_poll1, po_poll2, po_poll3, po_poll4, po_poll5, po_poll6, po_poll7, po_poll8, po_poll9, po_cnt1, po_cnt2, po_cnt3, po_cnt4, po_cnt5, po_cnt6, po_cnt7, po_cnt8, po_cnt9, po_etc, po_level, po_point, po_date )
values ( '{$_POST['po_subject']}', '{$_POST['po_poll1']}', '{$_POST['po_poll2']}', '{$_POST['po_poll3']}', '{$_POST['po_poll4']}', '{$_POST['po_poll5']}', '{$_POST['po_poll6']}', '{$_POST['po_poll7']}', '{$_POST['po_poll8']}', '{$_POST['po_poll9']}', '{$_POST['po_cnt1']}', '{$_POST['po_cnt2']}', '{$_POST['po_cnt3']}', '{$_POST['po_cnt4']}', '{$_POST['po_cnt5']}', '{$_POST['po_cnt6']}', '{$_POST['po_cnt7']}', '{$_POST['po_cnt8']}', '{$_POST['po_cnt9']}', '{$_POST['po_etc']}', '{$_POST['po_level']}', '{$_POST['po_point']}', '".G5_TIME_YMD."' ) ";
( po_subject, po_poll1, po_poll2, po_poll3, po_poll4, po_poll5, po_poll6, po_poll7, po_poll8, po_poll9, po_cnt1, po_cnt2, po_cnt3, po_cnt4, po_cnt5, po_cnt6, po_cnt7, po_cnt8, po_cnt9, po_etc, po_level, po_point, po_date, po_use )
values ( '{$_POST['po_subject']}', '{$_POST['po_poll1']}', '{$_POST['po_poll2']}', '{$_POST['po_poll3']}', '{$_POST['po_poll4']}', '{$_POST['po_poll5']}', '{$_POST['po_poll6']}', '{$_POST['po_poll7']}', '{$_POST['po_poll8']}', '{$_POST['po_poll9']}', '{$_POST['po_cnt1']}', '{$_POST['po_cnt2']}', '{$_POST['po_cnt3']}', '{$_POST['po_cnt4']}', '{$_POST['po_cnt5']}', '{$_POST['po_cnt6']}', '{$_POST['po_cnt7']}', '{$_POST['po_cnt8']}', '{$_POST['po_cnt9']}', '{$_POST['po_etc']}', '{$_POST['po_level']}', '{$_POST['po_point']}', '" . G5_TIME_YMD . "', 1 ) ";
sql_query($sql);
$po_id = sql_insert_id();
}
else if ($w == 'u')
{
} elseif ($w == 'u') {
$sql = " update {$g5['poll_table']}
set po_subject = '{$_POST['po_subject']}',
po_poll1 = '{$_POST['po_poll1']}',
@@ -77,12 +84,11 @@ else if ($w == 'u')
po_cnt9 = '{$_POST['po_cnt9']}',
po_etc = '{$_POST['po_etc']}',
po_level = '{$_POST['po_level']}',
po_point = '{$_POST['po_point']}'
po_point = '{$_POST['po_point']}',
po_use = '{$_POST['po_use']}'
where po_id = '{$_POST['po_id']}' ";
sql_query($sql);
}
else if ($w == 'd')
{
} elseif ($w == 'd') {
$sql = " delete from {$g5['poll_table']} where po_id = '{$_POST['po_id']}' ";
sql_query($sql);
@@ -96,7 +102,8 @@ else if ($w == 'd')
$row = sql_fetch(" select max(po_id) as max_po_id from {$g5['poll_table']} ");
sql_query(" update {$g5['config_table']} set cf_max_po_id = '{$row['max_po_id']}' ");
if ($w == 'd')
goto_url('./poll_list.php?'.$qstr);
else
goto_url('./poll_form.php?w=u&po_id='.$po_id.'&amp;'.$qstr);
if ($w == 'd') {
goto_url('./poll_list.php?' . $qstr);
} else {
goto_url('./poll_form.php?w=u&po_id=' . $po_id . '&amp;' . $qstr);
}
+98 -84
View File
@@ -1,16 +1,21 @@
<?php
$sub_menu = "200900";
include_once('./_common.php');
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
$sql_common = " from {$g5['poll_table']} ";
$allowed_sfl = array('po_subject');
if (!in_array($sfl, $allowed_sfl)) {
$sfl = 'po_subject';
}
$sql_search = " where (1) ";
if ($stx) {
$sql_search .= " and ( ";
switch ($sfl) {
default :
default:
$sql_search .= " ({$sfl} like '%{$stx}%') ";
break;
}
@@ -18,9 +23,12 @@ if ($stx) {
}
if (!$sst) {
$sst = "po_id";
$sst = "po_id";
$sod = "desc";
}
$allowed_sst = array('po_id', 'po_subject', 'po_level', 'po_use', 'po_etc');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'po_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
@@ -32,7 +40,9 @@ $total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) $page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
if ($page < 1) {
$page = 1; // 페이지가 없으면 첫 페이지 (1 페이지)
}
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select *
@@ -42,12 +52,12 @@ $sql = " select *
limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목록</a>';
$listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall">전체목록</a>';
$g5['title'] = '투표관리';
include_once('./admin.head.php');
require_once './admin.head.php';
$colspan = 7;
$colspan = 8;
?>
<div class="local_ov01 local_ov">
@@ -56,102 +66,106 @@ $colspan = 7;
</div>
<form name="fsearch" id="fsearch" class="local_sch01 local_sch" method="get">
<div class="sch_last">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="po_subject"<?php echo get_selected($sfl, "po_subject"); ?>>제목</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" class="btn_submit" value="검색">
</div>
<div class="sch_last">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="po_subject" <?php echo get_selected($sfl, "po_subject"); ?>>제목</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" class="btn_submit" value="검색">
</div>
</form>
<form name="fpolllist" id="fpolllist" action="./poll_delete.php" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">현재 페이지 투표 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col">번호</th>
<th scope="col">제목</th>
<th scope="col">투표권한</th>
<th scope="col">투표수</th>
<th scope="col">기타의견</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++) {
$sql2 = " select sum(po_cnt1+po_cnt2+po_cnt3+po_cnt4+po_cnt5+po_cnt6+po_cnt7+po_cnt8+po_cnt9) as sum_po_cnt from {$g5['poll_table']} where po_id = '{$row['po_id']}' ";
$row2 = sql_fetch($sql2);
$po_etc = ($row['po_etc']) ? "사용" : "미사용";
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">현재 페이지 투표 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col">번호</th>
<th scope="col">제목</th>
<th scope="col">투표권한</th>
<th scope="col">투표수</th>
<th scope="col">기타의견</th>
<th scope="col">사용</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$sql2 = " select sum(po_cnt1+po_cnt2+po_cnt3+po_cnt4+po_cnt5+po_cnt6+po_cnt7+po_cnt8+po_cnt9) as sum_po_cnt from {$g5['poll_table']} where po_id = '{$row['po_id']}' ";
$row2 = sql_fetch($sql2);
$po_etc = ($row['po_etc']) ? "사용" : "미사용";
$po_use = ($row['po_use']) ? "사용" : "미사용";
$s_mod = '<a href="./poll_form.php?'.$qstr.'&amp;w=u&amp;po_id='.$row['po_id'].'" class="btn btn_03">수정</a>';
$s_mod = '<a href="./poll_form.php?' . $qstr . '&amp;w=u&amp;po_id=' . $row['po_id'] . '" class="btn btn_03">수정</a>';
$bg = 'bg'.($i%2);
?>
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo cut_str(get_text($row['po_subject']),70) ?> 투표</label>
<input type="checkbox" name="chk[]" value="<?php echo $row['po_id'] ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_num"><?php echo $row['po_id'] ?></td>
<td class="td_left"><?php echo cut_str(get_text($row['po_subject']),70) ?></td>
<td class="td_num"><?php echo $row['po_level'] ?></td>
<td class="td_num"><?php echo $row2['sum_po_cnt'] ?></td>
<td class="td_etc"><?php echo $po_etc ?></td>
<td class="td_mng td_mng_s"><?php echo $s_mod ?></td>
</tr>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo cut_str(get_text($row['po_subject']), 70) ?> 투표</label>
<input type="checkbox" name="chk[]" value="<?php echo $row['po_id'] ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_num"><?php echo $row['po_id'] ?></td>
<td class="td_left"><?php echo cut_str(get_text($row['po_subject']), 70) ?></td>
<td class="td_num"><?php echo $row['po_level'] ?></td>
<td class="td_num"><?php echo $row2['sum_po_cnt'] ?></td>
<td class="td_etc"><?php echo $po_etc ?></td>
<td class="td_use"><?php echo $po_use ?></td>
<td class="td_mng td_mng_s"><?php echo $s_mod ?></td>
</tr>
<?php
}
<?php
}
if ($i==0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<input type="submit" value="선택삭제" class="btn btn_02">
<a href="./poll_form.php" id="poll_add" class="btn btn_01">투표 추가</a>
</div>
<div class="btn_fixed_top">
<input type="submit" value="선택삭제" class="btn btn_02">
<a href="./poll_form.php" id="poll_add" class="btn btn_01">투표 추가</a>
</div>
</form>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page="); ?>
<script>
$(function() {
$('#fpolllist').submit(function() {
if(confirm("한번 삭제한 자료는 복구할 방법이 없습니다.\n\n정말 삭제하시겠습니까?")) {
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
$(function() {
$('#fpolllist').submit(function() {
if (confirm("한번 삭제한 자료는 복구할 방법이 없습니다.\n\n정말 삭제하시겠습니까?")) {
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
return false;
}
return true;
} else {
return false;
}
return true;
} else {
return false;
}
});
});
});
</script>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+180 -170
View File
@@ -1,170 +1,180 @@
<?php
$sub_menu = "300300";
include_once('./_common.php');
auth_check_menu($auth, $sub_menu, 'r');
// 체크된 자료 삭제
if (isset($_POST['chk']) && is_array($_POST['chk'])) {
for ($i=0; $i<count($_POST['chk']); $i++) {
$pp_id = (int) $_POST['chk'][$i];
sql_query(" delete from {$g5['popular_table']} where pp_id = '$pp_id' ", true);
}
}
$sql_common = " from {$g5['popular_table']} a ";
$sql_search = " where (1) ";
if ($stx) {
$sql_search .= " and ( ";
switch ($sfl) {
case "pp_word" :
$sql_search .= " ({$sfl} like '{$stx}%') ";
break;
case "pp_date" :
$sql_search .= " ({$sfl} = '{$stx}') ";
break;
default :
$sql_search .= " ({$sfl} like '%{$stx}%') ";
break;
}
$sql_search .= " ) ";
}
if (!$sst) {
$sst = "pp_id";
$sod = "desc";
}
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
{$sql_common}
{$sql_search}
{$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) { $page = 1; } // 페이지가 없으면 첫 페이지 (1 페이지)
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select *
{$sql_common}
{$sql_search}
{$sql_order}
limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목록</a>';
$g5['title'] = '인기검색어관리';
include_once('./admin.head.php');
$colspan = 4;
?>
<script>
var list_update_php = '';
var list_delete_php = 'popular_list.php';
</script>
<div class="local_ov01 local_ov">
<?php echo $listall ?>
<span class="btn_ov01"><span class="ov_txt">건수</span><span class="ov_num"> <?php echo number_format($total_count) ?>개</span></span>
</div>
<form name="fsearch" id="fsearch" class="local_sch01 local_sch" method="get">
<div class="sch_last">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="pp_word"<?php echo get_selected($sfl, "pp_word"); ?>>검색어</option>
<option value="pp_date"<?php echo get_selected($sfl, "pp_date"); ?>>등록일</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" value="검색" class="btn_submit">
</div>
</form>
<form name="fpopularlist" id="fpopularlist" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo isset($token) ? $token : ''; ?>">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">현재 페이지 인기검색어 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('pp_word') ?>검색어</a></th>
<th scope="col">등록일</th>
<th scope="col">등록IP</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++) {
$word = get_text($row['pp_word']);
$bg = 'bg'.($i%2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $word ?></label>
<input type="checkbox" name="chk[]" value="<?php echo $row['pp_id'] ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_left"><a href="<?php echo $_SERVER['SCRIPT_NAME'] ?>?sfl=pp_word&amp;stx=<?php echo $word ?>"><?php echo $word ?></a></td>
<td><?php echo $row['pp_date'] ?></td>
<td><?php echo $row['pp_ip'] ?></td>
</tr>
<?php
}
if ($i == 0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
<?php if ($is_admin == 'super'){ ?>
<div class=" btn_fixed_top">
<button type="submit" class="btn btn_02">선택삭제</button>
</div>
<?php } ?>
</form>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page="); ?>
<script>
$(function() {
$('#fpopularlist').submit(function() {
if(confirm("한번 삭제한 자료는 복구할 방법이 없습니다.\n\n정말 삭제하시겠습니까?")) {
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
return false;
}
return true;
} else {
return false;
}
});
});
</script>
<?php
include_once('./admin.tail.php');
<?php
$sub_menu = "300300";
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
// 체크된 자료 삭제
if (isset($_POST['chk']) && is_array($_POST['chk'])) {
check_admin_token();
for ($i = 0; $i < count($_POST['chk']); $i++) {
$pp_id = (int) $_POST['chk'][$i];
sql_query(" delete from {$g5['popular_table']} where pp_id = '$pp_id' ", true);
}
}
$sql_common = " from {$g5['popular_table']} a ";
$allowed_sfl = array('pp_word', 'pp_date');
if (!in_array($sfl, $allowed_sfl)) {
$sfl = 'pp_word';
}
$sql_search = " where (1) ";
if ($stx) {
$sql_search .= " and ( ";
switch ($sfl) {
case "pp_word":
$sql_search .= " ({$sfl} like '{$stx}%') ";
break;
case "pp_date":
$sql_search .= " ({$sfl} = '{$stx}') ";
break;
default:
$sql_search .= " ({$sfl} like '%{$stx}%') ";
break;
}
$sql_search .= " ) ";
}
if (!$sst) {
$sst = "pp_id";
$sod = "desc";
}
$allowed_sst = array('pp_id', 'pp_word', 'pp_date', 'pp_ip');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'pp_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
{$sql_common}
{$sql_search}
{$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) {
$page = 1;
} // 페이지가 없으면 첫 페이지 (1 페이지)
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select *
{$sql_common}
{$sql_search}
{$sql_order}
limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall">전체목록</a>';
$g5['title'] = '인기검색어관리';
require_once './admin.head.php';
$colspan = 4;
?>
<script>
var list_update_php = '';
var list_delete_php = 'popular_list.php';
</script>
<div class="local_ov01 local_ov">
<?php echo $listall ?>
<span class="btn_ov01"><span class="ov_txt">건수</span><span class="ov_num"> <?php echo number_format($total_count) ?>개</span></span>
</div>
<form name="fsearch" id="fsearch" class="local_sch01 local_sch" method="get">
<div class="sch_last">
<label for="sfl" class="sound_only">검색대상</label>
<select name="sfl" id="sfl">
<option value="pp_word" <?php echo get_selected($sfl, "pp_word"); ?>>검색어</option>
<option value="pp_date" <?php echo get_selected($sfl, "pp_date"); ?>>등록일</option>
</select>
<label for="stx" class="sound_only">검색어<strong class="sound_only"> 필수</strong></label>
<input type="text" name="stx" value="<?php echo $stx ?>" id="stx" required class="required frm_input">
<input type="submit" value="검색" class="btn_submit">
</div>
</form>
<form name="fpopularlist" id="fpopularlist" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo isset($token) ? $token : ''; ?>">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">
<label for="chkall" class="sound_only">현재 페이지 인기검색어 전체</label>
<input type="checkbox" name="chkall" value="1" id="chkall" onclick="check_all(this.form)">
</th>
<th scope="col"><?php echo subject_sort_link('pp_word') ?>검색어</a></th>
<th scope="col">등록일</th>
<th scope="col">등록IP</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$word = get_text($row['pp_word']);
$bg = 'bg' . ($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_chk">
<label for="chk_<?php echo $i; ?>" class="sound_only"><?php echo $word ?></label>
<input type="checkbox" name="chk[]" value="<?php echo $row['pp_id'] ?>" id="chk_<?php echo $i ?>">
</td>
<td class="td_left"><a href="<?php echo $_SERVER['SCRIPT_NAME'] ?>?sfl=pp_word&amp;stx=<?php echo $word ?>"><?php echo $word ?></a></td>
<td><?php echo $row['pp_date'] ?></td>
<td><?php echo $row['pp_ip'] ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<?php if ($is_admin == 'super') { ?>
<div class=" btn_fixed_top">
<button type="submit" class="btn btn_02">선택삭제</button>
</div>
<?php } ?>
</form>
<?php echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page="); ?>
<script>
$(function() {
$('#fpopularlist').submit(function() {
if (confirm("한번 삭제한 자료는 복구할 방법이 없습니다.\n\n정말 삭제하시겠습니까?")) {
if (!is_checked("chk[]")) {
alert("선택삭제 하실 항목을 하나 이상 선택하세요.");
return false;
}
return true;
} else {
return false;
}
});
});
</script>
<?php
require_once './admin.tail.php';
+122 -112
View File
@@ -1,112 +1,122 @@
<?php
$sub_menu = "300400";
include_once('./_common.php');
auth_check_menu($auth, $sub_menu, 'r');
$fr_date = isset($_REQUEST['fr_date']) ? $_REQUEST['fr_date'] : '';
$to_date = isset($_REQUEST['to_date']) ? $_REQUEST['to_date'] : '';
if (empty($fr_date) || ! preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $fr_date) ) $fr_date = G5_TIME_YMD;
if (empty($to_date) || ! preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $to_date) ) $to_date = G5_TIME_YMD;
$qstr = "fr_date={$fr_date}&amp;to_date={$to_date}";
$sql_common = " from {$g5['popular_table']} a ";
$sql_search = " where trim(pp_word) <> '' and pp_date between '{$fr_date}' and '{$to_date}' ";
$sql_group = " group by pp_word ";
$sql_order = " order by cnt desc ";
$sql = " select pp_word {$sql_common} {$sql_search} {$sql_group} ";
$result = sql_query($sql);
$total_count = sql_num_rows($result);
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) { $page = 1; } // 페이지가 없으면 첫 페이지 (1 페이지)
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select pp_word, count(*) as cnt {$sql_common} {$sql_search} {$sql_group} {$sql_order} limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목록</a>';
$g5['title'] = '인기검색어순위';
include_once('./admin.head.php');
include_once(G5_PLUGIN_PATH.'/jquery-ui/datepicker.php');
$colspan = 3;
?>
<script>
$(function(){
$("#fr_date, #to_date").datepicker({ changeMonth: true, changeYear: true, dateFormat: "yy-mm-dd", showButtonPanel: true, yearRange: "c-99:c+99", maxDate: "+0d" });
});
</script>
<div class="local_ov01 local_ov">
<?php echo $listall ?>
<span class="btn_ov01"><span class="ov_txt">건수</span><span class="ov_num"> <?php echo number_format($total_count) ?>개</span></span>
</div>
<form name="fsearch" id="fsearch" class="local_sch02 local_sch" method="get">
<div class="sch_last">
<strong>기간별검색</strong>
<input type="text" name="fr_date" value="<?php echo $fr_date ?>" id="fr_date" class="frm_input" size="11" maxlength="10">
<label for="fr_date" class="sound_only">시작일</label>
~
<input type="text" name="to_date" value="<?php echo $to_date ?>" id="to_date" class="frm_input" size="11" maxlength="10">
<label for="to_date" class="sound_only">종료일</label>
<input type="submit" class="btn_sch2" value="검색">
</div>
</form>
<form name="fpopularrank" id="fpopularrank" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo isset($token) ? $token : ''; ?>">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">순위</th>
<th scope="col">검색어</th>
<th scope="col">검색회수</th>
</tr>
</thead>
<tbody>
<?php
for ($i=0; $row=sql_fetch_array($result); $i++) {
$word = get_text($row['pp_word']);
$rank = ($i + 1 + ($rows * ($page - 1)));
?>
<tr>
<td class="td_num"><?php echo $rank ?></td>
<td class="td_left"><?php echo $word ?></td>
<td class="td_num"><?php echo $row['cnt'] ?></td>
</tr>
<?php
}
if ($i == 0)
echo '<tr><td colspan="'.$colspan.'" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
</form>
<?php
echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page=");
include_once('./admin.tail.php');
<?php
$sub_menu = "300400";
require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
$fr_date = isset($_REQUEST['fr_date']) ? $_REQUEST['fr_date'] : '';
$to_date = isset($_REQUEST['to_date']) ? $_REQUEST['to_date'] : '';
if (empty($fr_date) || !preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $fr_date)) {
$fr_date = G5_TIME_YMD;
}
if (empty($to_date) || !preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $to_date)) {
$to_date = G5_TIME_YMD;
}
$qstr = "fr_date={$fr_date}&amp;to_date={$to_date}";
$sql_common = " from {$g5['popular_table']} a ";
$sql_search = " where trim(pp_word) <> '' and pp_date between '{$fr_date}' and '{$to_date}' ";
$sql_group = " group by pp_word ";
$sql_order = " order by cnt desc ";
$sql = " select pp_word {$sql_common} {$sql_search} {$sql_group} ";
$result = sql_query($sql);
$total_count = sql_num_rows($result);
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
if ($page < 1) {
$page = 1;
} // 페이지가 없으면 첫 페이지 (1 페이지)
$from_record = ($page - 1) * $rows; // 시작 열을 구함
$sql = " select pp_word, count(*) as cnt {$sql_common} {$sql_search} {$sql_group} {$sql_order} limit {$from_record}, {$rows} ";
$result = sql_query($sql);
$listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall">전체목록</a>';
$g5['title'] = '인기검색어순위';
require_once './admin.head.php';
require_once G5_PLUGIN_PATH . '/jquery-ui/datepicker.php';
$colspan = 3;
?>
<script>
$(function() {
$("#fr_date, #to_date").datepicker({
changeMonth: true,
changeYear: true,
dateFormat: "yy-mm-dd",
showButtonPanel: true,
yearRange: "c-99:c+99",
maxDate: "+0d"
});
});
</script>
<div class="local_ov01 local_ov">
<?php echo $listall ?>
<span class="btn_ov01"><span class="ov_txt">건수</span><span class="ov_num"> <?php echo number_format($total_count) ?>개</span></span>
</div>
<form name="fsearch" id="fsearch" class="local_sch02 local_sch" method="get">
<div class="sch_last">
<strong>기간별검색</strong>
<input type="text" name="fr_date" value="<?php echo $fr_date ?>" id="fr_date" class="frm_input" size="11" maxlength="10">
<label for="fr_date" class="sound_only">시작일</label>
~
<input type="text" name="to_date" value="<?php echo $to_date ?>" id="to_date" class="frm_input" size="11" maxlength="10">
<label for="to_date" class="sound_only">종료일</label>
<input type="submit" class="btn_sch2" value="검색">
</div>
</form>
<form name="fpopularrank" id="fpopularrank" method="post">
<input type="hidden" name="sst" value="<?php echo $sst ?>">
<input type="hidden" name="sod" value="<?php echo $sod ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl ?>">
<input type="hidden" name="stx" value="<?php echo $stx ?>">
<input type="hidden" name="page" value="<?php echo $page ?>">
<input type="hidden" name="token" value="<?php echo isset($token) ? $token : ''; ?>">
<div class="tbl_head01 tbl_wrap">
<table>
<caption><?php echo $g5['title']; ?> 목록</caption>
<thead>
<tr>
<th scope="col">순위</th>
<th scope="col">검색어</th>
<th scope="col">검색회수</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$word = get_text($row['pp_word']);
$rank = ($i + 1 + ($rows * ($page - 1)));
?>
<tr>
<td class="td_num"><?php echo $rank ?></td>
<td class="td_left"><?php echo $word ?></td>
<td class="td_num"><?php echo $row['cnt'] ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
</form>
<?php
echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, "{$_SERVER['SCRIPT_NAME']}?$qstr&amp;page=");
require_once './admin.tail.php';
+264 -359
View File
@@ -1,94 +1,16 @@
<?php
$sub_menu = "300500";
include_once('./_common.php');
include_once(G5_EDITOR_LIB);
require_once './_common.php';
require_once G5_EDITOR_LIB;
auth_check_menu($auth, $sub_menu, 'r');
$g5['title'] = '1:1문의 설정';
include_once ('./admin.head.php');
// DB 테이블 생성
if(!sql_query(" DESCRIBE `{$g5['qa_config_table']}` ", false)) {
sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['qa_config_table']}` (
`qa_title` varchar(255) NOT NULL DEFAULT'',
`qa_category` varchar(255) NOT NULL DEFAULT'',
`qa_skin` varchar(255) NOT NULL DEFAULT '',
`qa_mobile_skin` varchar(255) NOT NULL DEFAULT '',
`qa_use_email` tinyint(4) NOT NULL DEFAULT '0',
`qa_req_email` tinyint(4) NOT NULL DEFAULT '0',
`qa_use_hp` tinyint(4) NOT NULL DEFAULT '0',
`qa_req_hp` tinyint(4) NOT NULL DEFAULT '0',
`qa_use_sms` tinyint(4) NOT NULL DEFAULT '0',
`qa_send_number` varchar(255) NOT NULL DEFAULT '',
`qa_admin_hp` varchar(255) NOT NULL DEFAULT '',
`qa_use_editor` tinyint(4) NOT NULL DEFAULT '0',
`qa_subject_len` int(11) NOT NULL DEFAULT '0',
`qa_mobile_subject_len` int(11) NOT NULL DEFAULT '0',
`qa_page_rows` int(11) NOT NULL DEFAULT '0',
`qa_mobile_page_rows` int(11) NOT NULL DEFAULT '0',
`qa_image_width` int(11) NOT NULL DEFAULT '0',
`qa_upload_size` int(11) NOT NULL DEFAULT '0',
`qa_insert_content` text NOT NULL,
`qa_include_head` varchar(255) NOT NULL DEFAULT '',
`qa_include_tail` varchar(255) NOT NULL DEFAULT '',
`qa_content_head` text NOT NULL,
`qa_content_tail` text NOT NULL,
`qa_mobile_content_head` text NOT NULL,
`qa_mobile_content_tail` text NOT NULL,
`qa_1_subj` varchar(255) NOT NULL DEFAULT '',
`qa_2_subj` varchar(255) NOT NULL DEFAULT '',
`qa_3_subj` varchar(255) NOT NULL DEFAULT '',
`qa_4_subj` varchar(255) NOT NULL DEFAULT '',
`qa_5_subj` varchar(255) NOT NULL DEFAULT '',
`qa_1` varchar(255) NOT NULL DEFAULT '',
`qa_2` varchar(255) NOT NULL DEFAULT '',
`qa_3` varchar(255) NOT NULL DEFAULT '',
`qa_4` varchar(255) NOT NULL DEFAULT '',
`qa_5` varchar(255) NOT NULL DEFAULT ''
)", true);
sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['qa_content_table']}` (
`qa_id` int(11) NOT NULL AUTO_INCREMENT,
`qa_num` int(11) NOT NULL DEFAULT '0',
`qa_parent` int(11) NOT NULL DEFAULT '0',
`qa_related` int(11) NOT NULL DEFAULT '0',
`mb_id` varchar(20) NOT NULL DEFAULT '',
`qa_name` varchar(255) NOT NULL DEFAULT '',
`qa_email` varchar(255) NOT NULL DEFAULT '',
`qa_hp` varchar(255) NOT NULL DEFAULT '',
`qa_type` tinyint(4) NOT NULL DEFAULT '0',
`qa_category` varchar(255) NOT NULL DEFAULT '',
`qa_email_recv` tinyint(4) NOT NULL DEFAULT '0',
`qa_sms_recv` tinyint(4) NOT NULL DEFAULT '0',
`qa_html` tinyint(4) NOT NULL DEFAULT '0',
`qa_subject` varchar(255) NOT NULL DEFAULT '',
`qa_content` text NOT NULL,
`qa_status` tinyint(4) NOT NULL DEFAULT '0',
`qa_file1` varchar(255) NOT NULL DEFAULT '',
`qa_source1` varchar(255) NOT NULL DEFAULT '',
`qa_file2` varchar(255) NOT NULL DEFAULT '',
`qa_source2` varchar(255) NOT NULL DEFAULT '',
`qa_ip` varchar(255) NOT NULL DEFAULT '',
`qa_datetime` datetime NOT NULL DEFAULT '0000-00-00 00:00:00',
`qa_1` varchar(255) NOT NULL DEFAULT '',
`qa_2` varchar(255) NOT NULL DEFAULT '',
`qa_3` varchar(255) NOT NULL DEFAULT '',
`qa_4` varchar(255) NOT NULL DEFAULT '',
`qa_5` varchar(255) NOT NULL DEFAULT '',
PRIMARY KEY (`qa_id`),
KEY `qa_num_parent` (`qa_num`,`qa_parent`)
)", true);
}
$sql = " SHOW COLUMNS FROM `{$g5['qa_content_table']}` LIKE 'qa_content' ";
$row = sql_fetch($sql);
if(strpos($row['Type'], 'text') === false) {
sql_query(" ALTER TABLE `{$g5['qa_content_table']}` CHANGE `qa_content` `qa_content` text NOT NULL ", true);
}
require_once './admin.head.php';
$qaconfig = get_qa_config();
if(empty($qaconfig)) {
if (empty($qaconfig)) {
$sql = " insert into `{$g5['qa_config_table']}`
( qa_title, qa_category, qa_skin, qa_mobile_skin, qa_use_email, qa_req_email, qa_use_hp, qa_req_hp, qa_use_editor, qa_subject_len, qa_mobile_subject_len, qa_page_rows, qa_mobile_page_rows, qa_image_width, qa_upload_size, qa_insert_content )
values
@@ -98,302 +20,285 @@ if(empty($qaconfig)) {
$qaconfig = get_qa_config();
}
// 관리자 이메일필드 추가
if(!isset($qaconfig['qa_admin_email'])) {
sql_query(" ALTER TABLE `{$g5['qa_config_table']}`
ADD `qa_admin_email` varchar(255) NOT NULL DEFAULT '' AFTER `qa_admin_hp` ", true);
}
// 상단 하단 설정 필드 추가
if(!isset($qaconfig['qa_include_head'])) {
sql_query(" ALTER TABLE `{$g5['qa_config_table']}`
ADD `qa_include_head` varchar(255) NOT NULL DEFAULT '' AFTER `qa_insert_content`,
ADD `qa_include_tail` varchar(255) NOT NULL DEFAULT '' AFTER `qa_include_head`,
ADD `qa_content_head` text NOT NULL AFTER `qa_include_tail`,
ADD `qa_content_tail` text NOT NULL AFTER `qa_content_head`,
ADD `qa_mobile_content_head` text NOT NULL AFTER `qa_content_tail`,
ADD `qa_mobile_content_tail` text NOT NULL AFTER `qa_mobile_content_head` ", true);
}
?>
<form name="fqaconfigform" id="fqaconfigform" method="post" onsubmit="return fqaconfigform_submit(this);" autocomplete="off">
<input type="hidden" name="token" value="" id="token">
<input type="hidden" name="token" value="" id="token">
<section id="anc_cf_qa_config">
<h2 class="h2_frm">1:1문의 설정</h2>
<section id="anc_cf_qa_config">
<h2 class="h2_frm">1:1문의 설정</h2>
<div class="tbl_frm01 tbl_wrap">
<table>
<caption>1:1문의 설정</caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="qa_title">타이틀<strong class="sound_only">필수</strong></label></th>
<td>
<input type="text" name="qa_title" value="<?php echo get_sanitize_input($qaconfig['qa_title']); ?>" id="qa_title" required class="required frm_input" size="40">
<a href="<?php echo G5_BBS_URL; ?>/qalist.php" class="btn_frmline">1:1문의 바로가기</a>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_category">분류<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo help('분류와 분류 사이는 | 로 구분하세요. (예: 질문|답변) 첫자로 #은 입력하지 마세요. (예: #질문|#답변 [X])') ?>
<input type="text" name="qa_category" value="<?php echo get_sanitize_input($qaconfig['qa_category']); ?>" id="qa_category" required class="required frm_input" size="70">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_skin">스킨 디렉토리<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo get_skin_select('qa', 'qa_skin', 'qa_skin', $qaconfig['qa_skin'], 'required'); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_skin">모바일 스킨 디렉토리<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo get_mobile_skin_select('qa', 'qa_mobile_skin', 'qa_mobile_skin', $qaconfig['qa_mobile_skin'], 'required'); ?>
</td>
</tr>
<tr>
<th scope="row">이메일 입력</th>
<td>
<input type="checkbox" name="qa_use_email" value="1" id="qa_use_email" <?php echo $qaconfig['qa_use_email']?'checked':''; ?>> <label for="qa_use_email">보이기</label>
<input type="checkbox" name="qa_req_email" value="1" id="qa_req_email" <?php echo $qaconfig['qa_req_email']?'checked':''; ?>> <label for="qa_req_email">필수입력</label>
</td>
</tr>
<tr>
<th scope="row">휴대폰 입력</th>
<td>
<input type="checkbox" name="qa_use_hp" value="1" id="qa_use_hp" <?php echo $qaconfig['qa_use_hp']?'checked':''; ?>> <label for="qa_use_hp">보이기</label>
<input type="checkbox" name="qa_req_hp" value="1" id="qa_req_hp" <?php echo $qaconfig['qa_req_hp']?'checked':''; ?>> <label for="qa_req_hp">필수입력</label>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_use_sms">SMS 알림</label></th>
<td>
<?php echo help('휴대폰 입력을 사용하실 경우 문의글 등록시 등록자가 답변등록시 SMS 알림 수신을 선택할 수 있도록 합니다.<br>SMS 알림을 사용하기 위해서는 기본환경설정 > <a href="'.G5_ADMIN_URL.'/config_form.php#anc_cf_sms">SMS 설정</a>을 하셔야 합니다.') ?>
<select name="qa_use_sms" id="qa_use_sms">
<?php echo option_selected(0, $qaconfig['qa_use_sms'], '사용안함'); ?>
<?php echo option_selected(1, $qaconfig['qa_use_sms'], '사용함'); ?>
</select>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_send_number">SMS 발신번호</label></th>
<td>
<?php echo help('SMS 알림 전송시 발신번호로 사용됩니다.'); ?>
<input type="text" name="qa_send_number" value="<?php echo get_sanitize_input($qaconfig['qa_send_number']); ?>" id="qa_send_number" class="frm_input" size="30">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_admin_hp">관리자 휴대폰번호</label></th>
<td>
<?php echo help('관리자 휴대폰번호를 입력하시면 문의글 등록시 등록하신 번호로 SMS 알림이 전송됩니다.<br>SMS 알림을 사용하지 않으시면 알림이 전송되지 않습니다.'); ?>
<input type="text" name="qa_admin_hp" value="<?php echo get_sanitize_input($qaconfig['qa_admin_hp']); ?>" id="qa_admin_hp" class="frm_input" size="30">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_admin_email">관리자 이메일</label></th>
<td>
<?php echo help('관리자 이메일을 입력하시면 문의글 등록시 등록하신 이메일로 알림이 전송됩니다.'); ?>
<input type="text" name="qa_admin_email" value="<?php echo get_sanitize_input($qaconfig['qa_admin_email']); ?>" id="qa_admin_email" class="frm_input" size="50">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_use_editor">DHTML 에디터 사용</label></th>
<td>
<?php echo help('글작성시 내용을 DHTML 에디터 기능으로 사용할 것인지 설정합니다. 스킨에 따라 적용되지 않을 수 있습니다.'); ?>
<select name="qa_use_editor" id="qa_use_editor">
<?php echo option_selected(0, $qaconfig['qa_use_editor'], '사용안함'); ?>
<?php echo option_selected(1, $qaconfig['qa_use_editor'], '사용함'); ?>
</select>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_subject_len">제목 길이<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('목록에서의 제목 글자수') ?>
<input type="text" name="qa_subject_len" value="<?php echo $qaconfig['qa_subject_len'] ?>" id="qa_subject_len" required class="required numeric frm_input" size="4">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_subject_len">모바일 제목 길이<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('목록에서의 제목 글자수') ?>
<input type="text" name="qa_mobile_subject_len" value="<?php echo $qaconfig['qa_mobile_subject_len'] ?>" id="qa_mobile_subject_len" required class="required numeric frm_input" size="4">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_page_rows">페이지당 목록 수<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="qa_page_rows" value="<?php echo $qaconfig['qa_page_rows'] ?>" id="qa_page_rows" required class="required numeric frm_input" size="4">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_page_rows">모바일 페이지당 목록 수<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="qa_mobile_page_rows" value="<?php echo $qaconfig['qa_mobile_page_rows'] ?>" id="qa_mobile_page_rows" required class="required numeric frm_input" size="4">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_image_width">이미지 폭 크기<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('게시판에서 출력되는 이미지의 폭 크기') ?>
<input type="text" name="qa_image_width" value="<?php echo $qaconfig['qa_image_width'] ?>" id="qa_image_width" required class="required numeric frm_input" size="4"> 픽셀
</td>
</tr>
<tr>
<th scope="row"><label for="qa_upload_size">파일 업로드 용량<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('최대 '.ini_get("upload_max_filesize").' 이하 업로드 가능, 1 MB = 1,048,576 bytes') ?>
업로드 파일 한개당 <input type="text" name="qa_upload_size" value="<?php echo $qaconfig['qa_upload_size'] ?>" id="qa_upload_size" required class="required numeric frm_input" size="10"> bytes 이하
</td>
</tr>
<tr>
<th scope="row"><label for="qa_include_head">상단 파일 경로</label></th>
<td>
<input type="text" name="qa_include_head" value="<?php echo $qaconfig['qa_include_head'] ?>" id="qa_include_head" class="frm_input" size="50">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_include_tail">하단 파일 경로</label></th>
<td>
<input type="text" name="qa_include_tail" value="<?php echo $qaconfig['qa_include_tail'] ?>" id="qa_include_tail" class="frm_input" size="50">
</td>
</tr>
<tr id="admin_captcha_box" style="display:none;">
<th scope="row">자동등록방지</th>
<td>
<?php
echo help("파일 경로를 입력 또는 수정시 캡챠를 반드시 입력해야 합니다.");
<div class="tbl_frm01 tbl_wrap">
<table>
<caption>1:1문의 설정</caption>
<colgroup>
<col class="grid_4">
<col>
</colgroup>
<tbody>
<tr>
<th scope="row"><label for="qa_title">타이틀<strong class="sound_only">필수</strong></label></th>
<td>
<input type="text" name="qa_title" value="<?php echo get_sanitize_input($qaconfig['qa_title']); ?>" id="qa_title" required class="required frm_input" size="40">
<a href="<?php echo G5_BBS_URL; ?>/qalist.php" class="btn_frmline">1:1문의 바로가기</a>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_category">분류<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo help('분류와 분류 사이는 | 로 구분하세요. (예: 질문|답변) 첫자로 #은 입력하지 마세요. (예: #질문|#답변 [X])') ?>
<input type="text" name="qa_category" value="<?php echo get_sanitize_input($qaconfig['qa_category']); ?>" id="qa_category" required class="required frm_input" size="70">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_skin">스킨 디렉토리<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo get_skin_select('qa', 'qa_skin', 'qa_skin', $qaconfig['qa_skin'], 'required'); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_skin">모바일 스킨 디렉토리<strong class="sound_only">필수</strong></label></th>
<td>
<?php echo get_mobile_skin_select('qa', 'qa_mobile_skin', 'qa_mobile_skin', $qaconfig['qa_mobile_skin'], 'required'); ?>
</td>
</tr>
<tr>
<th scope="row">이메일 입력</th>
<td>
<input type="checkbox" name="qa_use_email" value="1" id="qa_use_email" <?php echo $qaconfig['qa_use_email'] ? 'checked' : ''; ?>> <label for="qa_use_email">보이기</label>
<input type="checkbox" name="qa_req_email" value="1" id="qa_req_email" <?php echo $qaconfig['qa_req_email'] ? 'checked' : ''; ?>> <label for="qa_req_email">필수입력</label>
</td>
</tr>
<tr>
<th scope="row">휴대폰 입력</th>
<td>
<input type="checkbox" name="qa_use_hp" value="1" id="qa_use_hp" <?php echo $qaconfig['qa_use_hp'] ? 'checked' : ''; ?>> <label for="qa_use_hp">보이기</label>
<input type="checkbox" name="qa_req_hp" value="1" id="qa_req_hp" <?php echo $qaconfig['qa_req_hp'] ? 'checked' : ''; ?>> <label for="qa_req_hp">필수입력</label>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_use_sms">SMS 알림</label></th>
<td>
<?php echo help('휴대폰 입력을 사용하실 경우 문의글 등록시 등록자가 답변등록시 SMS 알림 수신을 선택할 수 있도록 합니다.<br>SMS 알림을 사용하기 위해서는 기본환경설정 > <a href="' . G5_ADMIN_URL . '/config_form.php#anc_cf_sms">SMS 설정</a>을 하셔야 합니다.') ?>
<select name="qa_use_sms" id="qa_use_sms">
<?php echo option_selected(0, $qaconfig['qa_use_sms'], '사용안함'); ?>
<?php echo option_selected(1, $qaconfig['qa_use_sms'], '사용함'); ?>
</select>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_send_number">SMS 발신번호</label></th>
<td>
<?php echo help('SMS 알림 전송시 발신번호로 사용됩니다.'); ?>
<input type="text" name="qa_send_number" value="<?php echo get_sanitize_input($qaconfig['qa_send_number']); ?>" id="qa_send_number" class="frm_input" size="30">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_admin_hp">관리자 휴대폰번호</label></th>
<td>
<?php echo help('관리자 휴대폰번호를 입력하시면 문의글 등록시 등록하신 번호로 SMS 알림이 전송됩니다.<br>SMS 알림을 사용하지 않으시면 알림이 전송되지 않습니다.'); ?>
<input type="text" name="qa_admin_hp" value="<?php echo get_sanitize_input($qaconfig['qa_admin_hp']); ?>" id="qa_admin_hp" class="frm_input" size="30">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_admin_email">관리자 이메일</label></th>
<td>
<?php echo help('관리자 이메일을 입력하시면 문의글 등록시 등록하신 이메일로 알림이 전송됩니다.'); ?>
<input type="text" name="qa_admin_email" value="<?php echo get_sanitize_input($qaconfig['qa_admin_email']); ?>" id="qa_admin_email" class="frm_input" size="50">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_use_editor">DHTML 에디터 사용</label></th>
<td>
<?php echo help('글작성시 내용을 DHTML 에디터 기능으로 사용할 것인지 설정합니다. 스킨에 따라 적용되지 않을 수 있습니다.'); ?>
<select name="qa_use_editor" id="qa_use_editor">
<?php echo option_selected(0, $qaconfig['qa_use_editor'], '사용안함'); ?>
<?php echo option_selected(1, $qaconfig['qa_use_editor'], '사용함'); ?>
</select>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_subject_len">제목 길이<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('목록에서의 제목 글자수') ?>
<input type="text" name="qa_subject_len" value="<?php echo $qaconfig['qa_subject_len'] ?>" id="qa_subject_len" required class="required numeric frm_input" size="4">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_subject_len">모바일 제목 길이<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('목록에서의 제목 글자수') ?>
<input type="text" name="qa_mobile_subject_len" value="<?php echo $qaconfig['qa_mobile_subject_len'] ?>" id="qa_mobile_subject_len" required class="required numeric frm_input" size="4">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_page_rows">페이지당 목록 수<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="qa_page_rows" value="<?php echo $qaconfig['qa_page_rows'] ?>" id="qa_page_rows" required class="required numeric frm_input" size="4">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_page_rows">모바일 페이지당 목록 수<strong class="sound_only"> 필수</strong></label></th>
<td>
<input type="text" name="qa_mobile_page_rows" value="<?php echo $qaconfig['qa_mobile_page_rows'] ?>" id="qa_mobile_page_rows" required class="required numeric frm_input" size="4">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_image_width">이미지 폭 크기<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('게시판에서 출력되는 이미지의 폭 크기') ?>
<input type="text" name="qa_image_width" value="<?php echo $qaconfig['qa_image_width'] ?>" id="qa_image_width" required class="required numeric frm_input" size="4"> 픽셀
</td>
</tr>
<tr>
<th scope="row"><label for="qa_upload_size">파일 업로드 용량<strong class="sound_only"> 필수</strong></label></th>
<td>
<?php echo help('최대 ' . ini_get("upload_max_filesize") . ' 이하 업로드 가능, 1 MB = 1,048,576 bytes') ?>
업로드 파일 한개당 <input type="text" name="qa_upload_size" value="<?php echo $qaconfig['qa_upload_size'] ?>" id="qa_upload_size" required class="required numeric frm_input" size="10"> bytes 이하
</td>
</tr>
<tr>
<th scope="row"><label for="qa_include_head">상단 파일 경로</label></th>
<td>
<input type="text" name="qa_include_head" value="<?php echo get_sanitize_input($qaconfig['qa_include_head']); ?>" id="qa_include_head" class="frm_input" size="50">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_include_tail">하단 파일 경로</label></th>
<td>
<input type="text" name="qa_include_tail" value="<?php echo get_sanitize_input($qaconfig['qa_include_tail']); ?>" id="qa_include_tail" class="frm_input" size="50">
</td>
</tr>
<tr id="admin_captcha_box" style="display:none;">
<th scope="row">자동등록방지</th>
<td>
<?php
echo help("파일 경로를 입력 또는 수정시 캡챠를 반드시 입력해야 합니다.");
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
$captcha_html = captcha_html();
$captcha_js = chk_captcha_js();
echo $captcha_html;
?>
<script>
jQuery("#captcha_key").removeAttr("required").removeClass("required");
</script>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_content_head">상단 내용</label></th>
<td>
<?php echo editor_html("qa_content_head", get_text(html_purifier($qaconfig['qa_content_head']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_content_tail">하단 내용</label></th>
<td>
<?php echo editor_html("qa_content_tail", get_text(html_purifier($qaconfig['qa_content_tail']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_content_head">모바일 상단 내용</label></th>
<td>
<?php echo editor_html("qa_mobile_content_head", get_text(html_purifier($qaconfig['qa_mobile_content_head']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_content_tail">모바일 하단 내용</label></th>
<td>
<?php echo editor_html("qa_mobile_content_tail", get_text(html_purifier($qaconfig['qa_mobile_content_tail']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_insert_content">글쓰기 기본 내용</label></th>
<td>
<textarea id="qa_insert_content" name="qa_insert_content" rows="5"><?php echo html_purifier($qaconfig['qa_insert_content']); ?></textarea>
</td>
</tr>
<?php for ($i=1; $i<=5; $i++) { ?>
<tr>
<th scope="row">여분필드<?php echo $i ?></th>
<td class="td_extra">
<label for="qa_<?php echo $i ?>_subj">여분필드 <?php echo $i ?> 제목</label>
<input type="text" name="qa_<?php echo $i ?>_subj" id="qa_<?php echo $i ?>_subj" value="<?php echo get_text($qaconfig['qa_'.$i.'_subj']) ?>" class="frm_input">
<label for="qa_<?php echo $i ?>">여분필드 <?php echo $i ?> 값</label>
<input type="text" name="qa_<?php echo $i ?>" value="<?php echo get_text($qaconfig['qa_'.$i]) ?>" id="qa_<?php echo $i ?>" class="frm_input">
</td>
</tr>
<?php } ?>
</tbody>
</table>
require_once G5_CAPTCHA_PATH . '/captcha.lib.php';
$captcha_html = captcha_html();
$captcha_js = chk_captcha_js();
echo $captcha_html;
?>
<script>
jQuery("#captcha_key").removeAttr("required").removeClass("required");
</script>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_content_head">상단 내용</label></th>
<td>
<?php echo editor_html("qa_content_head", get_text(html_purifier($qaconfig['qa_content_head']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_content_tail">하단 내용</label></th>
<td>
<?php echo editor_html("qa_content_tail", get_text(html_purifier($qaconfig['qa_content_tail']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_content_head">모바일 상단 내용</label></th>
<td>
<?php echo editor_html("qa_mobile_content_head", get_text(html_purifier($qaconfig['qa_mobile_content_head']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_mobile_content_tail">모바일 하단 내용</label></th>
<td>
<?php echo editor_html("qa_mobile_content_tail", get_text(html_purifier($qaconfig['qa_mobile_content_tail']), 0)); ?>
</td>
</tr>
<tr>
<th scope="row"><label for="qa_insert_content">글쓰기 기본 내용</label></th>
<td>
<textarea id="qa_insert_content" name="qa_insert_content" rows="5"><?php echo html_purifier($qaconfig['qa_insert_content']); ?></textarea>
</td>
</tr>
<?php for ($i = 1; $i <= 5; $i++) { ?>
<tr>
<th scope="row">여분필드<?php echo $i ?></th>
<td class="td_extra">
<label for="qa_<?php echo $i ?>_subj">여분필드 <?php echo $i ?> 제목</label>
<input type="text" name="qa_<?php echo $i ?>_subj" id="qa_<?php echo $i ?>_subj" value="<?php echo get_text($qaconfig['qa_' . $i . '_subj']) ?>" class="frm_input">
<label for="qa_<?php echo $i ?>">여분필드 <?php echo $i ?> 값</label>
<input type="text" name="qa_<?php echo $i ?>" value="<?php echo get_text($qaconfig['qa_' . $i]) ?>" id="qa_<?php echo $i ?>" class="frm_input">
</td>
</tr>
<?php } ?>
</tbody>
</table>
</div>
</section>
<div class="btn_fixed_top">
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
</div>
</section>
<div class="btn_fixed_top">
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
</div>
</form>
<script>
var captcha_chk = false,
qa_include_head = jQuery.trim(jQuery("#qa_include_head").val()),
qa_include_tail = jQuery.trim(jQuery("#qa_include_tail").val());
var captcha_chk = false;
function use_captcha_check() {
$.ajax({
type: "POST",
url: g5_admin_url + "/ajax.use_captcha.php",
data: {
admin_use_captcha: "1"
},
cache: false,
async: false,
dataType: "json",
success: function(data) {}
});
}
function use_captcha_check(){
$.ajax({
type: "POST",
url: g5_admin_url+"/ajax.use_captcha.php",
data: { admin_use_captcha: "1" },
cache: false,
async: false,
dataType: "json",
success: function(data) {
function frm_check_file() {
var head = jQuery.trim(jQuery("#qa_include_head").val());
var tail = jQuery.trim(jQuery("#qa_include_tail").val());
if (qa_include_head !== head || qa_include_tail !== tail) {
// 캡챠를 사용합니다.
jQuery("#admin_captcha_box").show();
captcha_chk = true;
use_captcha_check();
return false;
} else {
jQuery("#admin_captcha_box").hide();
}
return true;
}
jQuery(function($) {
if (window.self !== window.top) { // frame 또는 iframe을 사용할 경우 체크
$("#qa_include_head, #qa_include_tail").on("change paste keyup", function(e) {
frm_check_file();
});
use_captcha_check();
}
});
}
function frm_check_file(){
var qa_include_head = "<?php echo $qaconfig['qa_include_head']; ?>";
var qa_include_tail = "<?php echo $qaconfig['qa_include_tail']; ?>";
var head = jQuery.trim(jQuery("#qa_include_head").val());
var tail = jQuery.trim(jQuery("#qa_include_tail").val());
function fqaconfigform_submit(f) {
<?php echo get_editor_js("qa_content_head"); ?>
<?php echo get_editor_js("qa_content_tail"); ?>
<?php echo get_editor_js("qa_mobile_content_head"); ?>
<?php echo get_editor_js("qa_mobile_content_tail"); ?>
if(qa_include_head !== head || qa_include_tail !== tail){
// 캡챠를 사용합니다.
jQuery("#admin_captcha_box").show();
captcha_chk = true;
if (captcha_chk) {
<?php echo isset($captcha_js) ? $captcha_js : ''; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
}
use_captcha_check();
return false;
} else {
jQuery("#admin_captcha_box").hide();
f.action = "./qa_config_update.php";
return true;
}
return true;
}
jQuery(function($){
if( window.self !== window.top ){ // frame 또는 iframe을 사용할 경우 체크
$("#qa_include_head, #qa_include_tail").on("change paste keyup", function(e) {
frm_check_file();
});
use_captcha_check();
}
});
function fqaconfigform_submit(f)
{
<?php echo get_editor_js("qa_content_head"); ?>
<?php echo get_editor_js("qa_content_tail"); ?>
<?php echo get_editor_js("qa_mobile_content_head"); ?>
<?php echo get_editor_js("qa_mobile_content_tail"); ?>
if( captcha_chk ) {
<?php echo isset($captcha_js) ? $captcha_js : ''; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
}
f.action = "./qa_config_update.php";
return true;
}
</script>
<?php
include_once ('./admin.tail.php');
require_once './admin.tail.php';
+39 -21
View File
@@ -1,6 +1,6 @@
<?php
$sub_menu = "300500";
include_once('./_common.php');
require_once './_common.php';
check_demo();
@@ -14,51 +14,66 @@ $qaconfig = get_qa_config();
$check_keys = array('qa_title', 'qa_category', 'qa_skin', 'qa_mobile_skin', 'qa_use_email', 'qa_req_email', 'qa_use_hp', 'qa_req_hp', 'qa_use_sms', 'qa_send_number', 'qa_admin_hp', 'qa_admin_email', 'qa_subject_len', 'qa_mobile_subject_len', 'qa_page_rows', 'qa_mobile_page_rows', 'qa_image_width', 'qa_upload_size');
foreach($check_keys as $key){
$$key = $_POST[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
foreach ($check_keys as $key) {
$$key = $_POST[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
}
$qa_include_head = preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_head, 0, 255));
$qa_include_tail = preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_tail, 0, 255));
$qa_include_head = isset($qa_include_head) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_head, 0, 255)) : '';
$qa_include_tail = isset($qa_include_tail) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_tail, 0, 255)) : '';
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
if ($is_admin !== 'super') {
$qa_include_head = isset($qaconfig['qa_include_head']) ? $qaconfig['qa_include_head'] : '';
$qa_include_tail = isset($qaconfig['qa_include_tail']) ? $qaconfig['qa_include_tail'] : '';
}
// 관리자가 자동등록방지를 사용해야 할 경우
if ($board && ($qaconfig['qa_include_head'] !== $qa_include_head || $qaconfig['qa_include_tail'] !== $qa_include_tail) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()){
include_once(G5_CAPTCHA_PATH.'/captcha.lib.php');
if ($board && ($qaconfig['qa_include_head'] !== $qa_include_head || $qaconfig['qa_include_tail'] !== $qa_include_tail) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
include_once G5_CAPTCHA_PATH . '/captcha.lib.php';
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
}
if( $qa_include_head ){
// 저장·검증 전에 경로를 먼저 정규화하여, 검증 이후 경로가 달라지지 않도록 한다.
if (function_exists('filter_input_include_path')) {
$qa_include_head = filter_input_include_path($qa_include_head);
$qa_include_tail = filter_input_include_path($qa_include_tail);
}
if ($qa_include_head) {
$file_ext = pathinfo($qa_include_head, PATHINFO_EXTENSION);
if( ! $file_ext || ! in_array($file_ext, array('php', 'htm', 'html')) || ! preg_match('/^.*\.(php|htm|html)$/i', $qa_include_head) ) {
if (!$file_ext || !in_array($file_ext, array('php', 'htm', 'html')) || !preg_match('/^.*\.(php|htm|html)$/i', $qa_include_head)) {
alert('상단 파일 경로의 확장자는 php, htm, html 만 허용합니다.');
}
}
if( $qa_include_tail ){
if ($qa_include_tail) {
$file_ext = pathinfo($qa_include_tail, PATHINFO_EXTENSION);
if( ! $file_ext || ! in_array($file_ext, array('php', 'htm', 'html')) || ! preg_match('/^.*\.(php|htm|html)$/i', $qa_include_tail) ) {
if (!$file_ext || !in_array($file_ext, array('php', 'htm', 'html')) || !preg_match('/^.*\.(php|htm|html)$/i', $qa_include_tail)) {
alert('하단 파일 경로의 확장자는 php, htm, html 만 허용합니다.');
}
}
if( $qa_include_head && ! is_include_path_check($qa_include_head, 1) ){
if ($qa_include_head && !is_include_path_check($qa_include_head, 1)) {
$qa_include_head = '';
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 상단 파일 경로에 포함시킬수 없습니다.';
}
if( $qa_include_tail && ! is_include_path_check($qa_include_tail, 1) ){
if ($qa_include_tail && !is_include_path_check($qa_include_tail, 1)) {
$qa_include_tail = '';
$error_msg = '/data/file/ 또는 /data/editor/ 포함된 문자를 하단 파일 경로에 포함시킬수 없습니다.';
}
if( function_exists('filter_input_include_path') ){
$qa_include_head = filter_input_include_path($qa_include_head);
$qa_include_tail = filter_input_include_path($qa_include_tail);
if ($qa_include_head && function_exists('is_content_include_allowed') && !is_content_include_allowed($qa_include_head)) {
alert('상단 파일 경로로 사용할 수 없는 위치입니다.');
}
if ($qa_include_tail && function_exists('is_content_include_allowed') && !is_content_include_allowed($qa_include_tail)) {
alert('하단 파일 경로로 사용할 수 없는 위치입니다.');
}
// 분류에 & 나 = 는 사용이 불가하므로 2바이트로 바꾼다.
@@ -67,7 +82,7 @@ $dst_char = array('&', '〓');
$qa_category = str_replace($src_char, $dst_char, $_POST['qa_category']);
//https://github.com/gnuboard/gnuboard5/commit/f5f4925d4eb28ba1af728e1065fc2bdd9ce1da58 에 따른 조치
$qa_category = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\/\^\*]/", "", $qa_category);
$qa_category = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\/\^\*]/", "", (string)$qa_category);
$sql = " update {$g5['qa_config_table']}
set qa_title = '{$_POST['qa_title']}',
@@ -108,11 +123,14 @@ $sql = " update {$g5['qa_config_table']}
qa_5 = '{$_POST['qa_5']}' ";
sql_query($sql);
if(function_exists('get_admin_captcha_by'))
get_admin_captcha_by('remove');
run_event('admin_qa_config_updated');
if($error_msg){
if (function_exists('get_admin_captcha_by')) {
get_admin_captcha_by('remove');
}
if ($error_msg) {
alert($error_msg, './qa_config.php');
} else {
goto_url('./qa_config.php');
}
}
+11 -6
View File
@@ -1,16 +1,21 @@
<?php
if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가
if (!defined('_GNUBOARD_')) {
exit; // 개별 페이지 접근 불가
}
function social_log_file_delete($second=0){
$files = glob(G5_DATA_PATH.'/tmp/social_*');
function social_log_file_delete($second = 0)
{
$files = glob(G5_DATA_PATH . '/tmp/social_*');
if (is_array($files)) {
$before_time = $second ? G5_SERVER_TIME - $second : 0;
foreach ($files as $social_log_file) {
$modification_time = filemtime($log_file); // 파일접근시간
$modification_time = filemtime($social_log_file); // 파일접근시간
if ($before_time && $modification_time > $before_time) continue;
if ($before_time && $modification_time > $before_time) {
continue;
}
unlink($social_log_file);
}
}
}
}
+64 -22
View File
@@ -9,39 +9,76 @@ if (!$config['cf_email_use'])
include_once(G5_LIB_PATH.'/mailer.lib.php');
$token = get_token();
$g5['title'] = '메일 테스트';
include_once('./admin.head.php');
if (isset($_POST['email'])) {
check_admin_token();
$_POST['email'] = strip_tags($_POST['email']);
$email = explode(',', $_POST['email']);
$real_email = array();
$sent_email = array(); // 발송 요청 성공
$failed_email = array(); // 발송 실패 (메일 서버에서 거부/오류)
for ($i=0; $i<count($email); $i++){
if (!preg_match("/([0-9a-zA-Z_-]+)@([0-9a-zA-Z_-]+)\.([0-9a-zA-Z_-]+)/", $email[$i])) continue;
$real_email[] = $email[$i];
mailer($config['cf_admin_email_name'], $config['cf_admin_email'], trim($email[$i]), '[메일검사] 제목', '<span style="font-size:9pt;">[메일검사] 내용<p>이 내용이 제대로 보인다면 보내는 메일 서버에는 이상이 없는것입니다.<p>'.G5_TIME_YMDHIS.'<p>이 메일 주소로는 회신되지 않습니다.</span>', 1);
$to = trim($email[$i]);
$send_result = mailer($config['cf_admin_email_name'], $config['cf_admin_email'], $to, '[메일검사] 제목', '<span style="font-size:9pt;">[메일검사] 내용<p>이 내용이 제대로 보인다면 보내는 메일 서버에는 이상이 없는것입니다.<p>'.G5_TIME_YMDHIS.'<p>이 메일 주소로는 회신되지 않습니다.</span>', 1);
if ($send_result) {
$sent_email[] = $to;
} else {
$failed_email[] = $to;
}
}
if( $real_email ){
if( $sent_email || $failed_email ){
echo '<section>';
echo '<h2>결과메세지</h2>';
echo '<div class="local_desc01 local_desc"><p>';
echo '다음 '.count($real_email).'개의 메일 주소로 테스트 메일 발송이 완료되었습니다.';
echo '</p></div>';
echo '<ul>';
for ($i=0;$i<count($real_email);$i++) {
echo '<li>'.$real_email[$i].'</li>';
echo '<h2>결과 메시지</h2>';
if( $sent_email ){
echo '<div class="local_desc01 local_desc"><p>';
echo '다음 '.count($sent_email).'개의 메일 주소로 테스트 메일 <strong>발송 요청이 성공</strong>했습니다. <strong>수신함 도착 여부는 별도 확인이 필요합니다.</strong>';
echo '</p></div>';
echo '<ul>';
for ($i=0;$i<count($sent_email);$i++) {
echo '<li>'.get_text($sent_email[$i]).'</li>';
}
echo '</ul>';
echo '<div class="local_desc02 local_desc"><p>';
echo '<strong>발송 요청 성공은 사이트가 메일 서버에 메일을 넘겼다는 의미이며, 받은편지함 도착을 보장하지는 않습니다.</strong><br>';
echo '메일이 보이지 않는다면 아래 항목을 순서대로 확인해 주십시오.';
echo '</p></div>';
echo '<ol>';
echo '<li>받은편지함뿐 아니라 <strong>스팸함, 정크메일함, 프로모션함</strong>을 확인합니다.</li>';
echo '<li>네이버, 지메일, 회사메일 등 <strong>서로 다른 메일 주소</strong>로 다시 테스트합니다.</li>';
echo '<li>관리자 메일 주소가 사이트 도메인과 같은지 확인합니다. 도메인이 다르면 스팸으로 분류될 가능성이 높습니다.</li>';
echo '<li>도메인 메일을 사용한다면 <strong>SPF, DKIM, DMARC</strong> 설정을 확인합니다.</li>';
echo '<li>계속 도착하지 않으면 서버 개발자에게 메일 발송 로그를 확인해주세요.</li>';
echo '</ol>';
}
echo '</ul>';
echo '<div class="local_desc02 local_desc"><p>';
echo '해당 주소로 테스트 메일이 도착했는지 확인해 주십시오.<br>';
echo '만약, 테스트 메일이 오지 않는다면 더 다양한 계정의 메일 주소로 메일을 보내 보십시오.<br>';
echo '그래도 메일이 하나도 도착하지 않는다면 메일 서버(sendmail server)의 오류일 가능성이 높으니, 웹 서버관리자에게 문의하여 주십시오.<br>';
echo '</p></div>';
if( $failed_email ){
echo '<div class="local_desc01 local_desc" style="color:#d9534f"><p>';
echo '다음 '.count($failed_email).'개의 메일 주소는 <strong>발송에 실패</strong>했습니다.';
echo '</p></div>';
echo '<ul>';
for ($i=0;$i<count($failed_email);$i++) {
echo '<li>'.get_text($failed_email[$i]).'</li>';
}
echo '</ul>';
echo '<div class="local_desc02 local_desc"><p>';
echo '발송 실패는 받는 사람의 문제가 아니라 <strong>보내는 서버(메일 발송) 설정 문제</strong>일 가능성이 높습니다.<br>';
echo 'SMTP 정보(주소/포트/인증)가 올바른지, 서버에서 메일 발송(sendmail/mail 함수)이 허용되어 있는지 확인하시고, 웹 서버 관리자(호스팅 업체)에게 문의해 주십시오.<br>';
echo '자세한 오류 내용은 서버의 PHP error_log 에 기록됩니다.<br>';
echo '</p></div>';
}
echo '</section>';
}
}
@@ -51,11 +88,16 @@ if (isset($_POST['email'])) {
<h2>테스트 메일 발송</h2>
<div class="local_desc02 local_desc">
<p>
메일서버가 정상적으로 동작 중인지 확인할 수 있습니다.<br>
사이트에서 메일 서버로 메일을 전달할 수 있는지 확인합니다. 이 테스트는 받은편지함 도착을 보장하지 않습니다.<br>
아래 입력칸에 테스트 메일을 발송하실 메일 주소를 입력하시면, [메일검사] 라는 제목으로 테스트 메일을 발송합니다.<br>
보내는 메일주소 : <?php echo get_sanitize_input($config['cf_admin_email']); ?><br>
<?php if (function_exists('domain_mail_host') && $config['cf_admin_email'] && stripos($config['cf_admin_email'], domain_mail_host()) === false) { ?>
<?php echo '외부메일설정이나 기타 설정을 하지 않았다면, 도메인과 다른 헤더로 여겨 스팸이나 차단될 가능성이 있습니다.<br>외부메일설정이나 기타 설정을 하지 않았다면, 기본환경설정에서 관리자 메일 주소를 name'.domain_mail_host().' 과 같은 도메인 형식으로 설정할것을 권장합니다.'; ?>
<?php } ?>
</p>
</div>
<form name="fsendmailtest" method="post">
<input type="hidden" name="token" value="<?php echo $token; ?>">
<fieldset id="fsendmailtest">
<legend>테스트메일 발송</legend>
<label for="email">받는 메일주소<strong class="sound_only"> 필수</strong></label>
@@ -65,11 +107,11 @@ if (isset($_POST['email'])) {
</form>
<div class="local_desc02 local_desc">
<p>
만약 [메일검사] 라는 내용으로 테스트 메일이 도착하지 않는다면 보내는 메일서버 혹은 받는 메일서버 중 문제가 발생했을 가능성이 있습니다.<br>
따라서 보다 정확한 테스트를 원하신다면 여러 곳으로 테스트 메일을 발송하시기 바랍니다.<br>
테스트 결과가 발송 요청 성공으로 표시되어도 수신 메일 서버의 스팸 정책에 따라 도착하지 않을 수 있습니다.<br>
정확한 확인을 위해 여러 메일 서비스로 테스트하고, 도착하지 않으면 스팸함과 도메인 인증(SPF, DKIM, DMARC)을 확인해 주십시오.<br>
</p>
</div>
</section>
<?php
include_once('./admin.tail.php');
include_once('./admin.tail.php');
+14 -24
View File
@@ -15,45 +15,35 @@ include_once('./admin.head.php');
<div class="service_wrap">
<div class="sevice_1 svc_card">
<h3>신용카드 전자결제 서비스<br><span>(계좌이체, 가상계좌 결제 포함)</span></h3>
<p>이곳을 통하여 가입하시면 신용카드 결제를 국내 최저 수수료인 3.2%에 이용 할 수 있습니다. 영카트를 사용하지 않아도 이 수수료를 적용 받을 수 있습니다. 아래 가입을 희망하시는 회사의 로고를 클릭하시면 가입페이지로 이동합니다.</p>
<ul>
<li><a href="http://sir.kr/main/service/p_pg.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_01.jpg" alt="KCP 신용카드 전자결제 신청하기"></a></li>
<li ><a href="http://sir.kr/main/service/lg_pg.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_02.jpg?v2" alt="토스페이먼츠 전자결제 신청하기"></a></li>
<li class="last"><a href="http://sir.kr/main/service/inicis_pg.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_06.jpg" alt="KG 이니시스 전자결제 신청하기"></a></li>
<li><a href="https://sir.kr/services/pg/kcp" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_01.jpg" alt="NHN KCP 신용카드 전자결제 신청하기"></a></li>
<li><a href="https://sir.kr/services/pg/toss" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_02.jpg?v2" alt="토스페이먼츠 전자결제 신청하기"></a></li>
<li><a href="https://sir.kr/services/pg/inicis" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_06.jpg" alt="KG 이니시스 전자결제 신청하기"></a></li>
<li class="last"><a href="https://sir.kr/services/pg/nice" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_07.jpg" alt="나이스페이먼츠 전자결제 신청하기"></a></li>
</ul>
</div>
<div class="sevice_1 svc_phone">
<h3>휴대폰 본인확인 서비스</h3>
<p>정보통신망법 23조 2항(주민등록번호의 사용제한)에 따라 기존 주민등록번호 기반의 인증서비스 이용이 불가합니다. 주민등록번호 대체수단으로 최소한의 정보(생년월일, 휴대폰번호, 성별)를 입력받아 본인임을 확인하는 인증수단 입니다</p>
<h3>본인확인 서비스</h3>
<ul>
<li><a href="http://sir.kr/main/service/p_cert.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_01.jpg" alt="KCP 휴대폰 본인확인 신청하기"></a></li>
<li><a href="http://sir.kr/main/service/lg_cert.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_02.jpg?v2" alt="유플러스 휴대폰 본인확인 신청하기"></a></li>
<li class="last"><a href="http://sir.kr/main/service/b_cert.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_03.jpg" alt="오케이네임 휴대폰대체인증 신청하기"></a></li>
<li><a href="https://sir.kr/services/auth/kcp" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_01.jpg" alt="NHN KCP 휴대폰 본인확인 신청하기"></a></li>
<li><a href="https://sir.kr/services/auth/inicis" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_06.jpg" alt="KG이니시스 본인확인 신청하기"></a></li>
</ul>
</div>
<div class="sevice_1 svc_ipin">
<h3>아이핀 본인확인 서비스</h3>
<p>정부가 주관하는 주민등록번호 대체 수단으로 본인의 개인정보를 아이핀 사이트에 한번만 발급해 놓고, 이후부터는 아이디와 패스워드 만으로 본인임을 확인하는 인증수단 입니다. </p>
<h4><a href="http://sir.kr/main/service/b_ipin.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_04.jpg" alt="오케이네임 아이핀 본인확인 신청하기"></a></h4>
</div>
<div class="service_2">
<div class="svc_ri svc_sms">
<div class="svc_a">
<h3>SMS 문자 서비스</h3>
<p>주문이나 배송시에 상점운영자 또는 고객에게 휴대폰으로 단문메세지 (최대 한글 40자, 영문 80자)를 발송합니다.</p>
</div>
<div class="svc_btn2"><a href="http://icodekorea.com/res/join_company_fix_a.php?sellid=sir2" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_05.jpg" alt="아이코드 SMS 서비스 신청하기"></a></div>
<div class="svc_a">
<h3>SMS 문자 서비스</h3>
<p>주문이나 배송시에 상점운영자 또는 고객에게 휴대폰으로 단문메세지 (최대 한글 40자, 영문 80자)를 발송합니다.</p>
</div>
<div class="svc_btn2"><a href="https://sir.kr/services/message/icode" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_05.jpg" alt="아이코드 SMS 서비스 신청하기"></a></div>
</div>
</div>
</div>
<?php
include_once('./admin.tail.php');
include_once('./admin.tail.php');
+1 -1
View File
@@ -31,7 +31,7 @@ include_once("./admin.head.php");
echo $list_tag_st;
while($file=readdir($dir)) {
if (!strstr($file,'sess_')) continue;
if (strpos($file,'sess_') === false) continue;
if (strpos($file,'sess_')!=0) continue;
$session_file = G5_DATA_PATH.'/session/'.$file;

Some files were not shown because too many files have changed in this diff Show More