Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e0a42d8f46 | ||
|
|
6c6787ec1f | ||
|
|
d419f430a9 | ||
|
|
1a5661a995 | ||
|
|
8a5767dc70 | ||
|
|
935ea84c7c | ||
|
|
1cade844fb | ||
|
|
dfca17a599 | ||
|
|
5ed691136d | ||
|
|
cdda832081 | ||
|
|
5374fb5f74 | ||
|
|
16a8dca6f7 | ||
|
|
b00fc18275 | ||
|
|
0c6ff731f6 | ||
|
|
77835010df | ||
|
|
33416852fc | ||
|
|
3a4612420c | ||
|
|
6a55f1457d | ||
|
|
76d83c2bae | ||
|
|
afd8b35423 | ||
|
|
e7c89675b6 | ||
|
|
10c6c18857 | ||
|
|
3e002199d5 | ||
|
|
7dde02d396 | ||
|
|
31871ee3e6 | ||
|
|
ff9a7534ed | ||
|
|
9869be5970 | ||
|
|
1fa4467cd1 | ||
|
|
3e75ccea65 | ||
|
|
be9f50f96b | ||
|
|
7c217cb41b | ||
|
|
5fc1c3bc27 | ||
|
|
d707c5abac | ||
|
|
eeea46cb69 | ||
|
|
669cce7011 | ||
|
|
ee8b57eb13 | ||
|
|
c927925a05 | ||
|
|
d914a7843d | ||
|
|
c04591e24a | ||
|
|
a6fbbe6ad2 | ||
|
|
4c00c60006 | ||
|
|
56b1958d37 | ||
|
|
6b2f9e094c | ||
|
|
a781b4aef3 | ||
|
|
8be4476f56 | ||
|
|
59d0b3c19c | ||
|
|
f4f8c57a74 | ||
|
|
d5619707bc | ||
|
|
9e7465319b | ||
|
|
f1f2150c67 | ||
|
|
3de722d3df | ||
|
|
7119b4f612 | ||
|
|
efaefbbd0e | ||
|
|
b12bf551ec | ||
|
|
65a419e9cd | ||
|
|
3f32ecd3e6 | ||
|
|
b5d218d446 | ||
|
|
f2e7dbc5ed | ||
|
|
c38de4c94b | ||
|
|
7d8a660642 | ||
|
|
5875e8b86b | ||
|
|
68a5b9c25a | ||
|
|
2dff49914b | ||
|
|
51518e45e4 | ||
|
|
7883ff65dc | ||
|
|
a2608754bd | ||
|
|
758bb67b7b | ||
|
|
0037f72cce | ||
|
|
df940f8168 | ||
|
|
614b040960 | ||
|
|
dccb50d8a3 | ||
|
|
5331aa8be5 | ||
|
|
79f915988b | ||
|
|
3cfe8b6b84 | ||
|
|
31ef78e916 | ||
|
|
a612e69d3e | ||
|
|
29e55de1fa | ||
|
|
c4db6e7751 | ||
|
|
47a3790c57 | ||
|
|
2894c269ea | ||
|
|
c00c73465a | ||
|
|
3e0e8be6da | ||
|
|
92a052fa7a | ||
|
|
4ebdd8ba30 | ||
|
|
4d5c597665 | ||
|
|
7e65a297bf | ||
|
|
ddcc82d89b | ||
|
|
ad99ea7673 | ||
|
|
b3fa6dc127 | ||
|
|
e6780f3b4b | ||
|
|
bededeaf01 | ||
|
|
73b868a444 | ||
|
|
eb249a2aee | ||
|
|
813fdef0c7 | ||
|
|
f8561e9398 | ||
|
|
52590509d5 | ||
|
|
604cef808e | ||
|
|
82574fd4a8 | ||
|
|
c3db9b454e | ||
|
|
bf19cd8bf5 | ||
|
|
b2c0e1af29 | ||
|
|
60d37b853b | ||
|
|
919b75a138 | ||
|
|
01fab8136e | ||
|
|
5054e24631 | ||
|
|
deff7d2079 | ||
|
|
5e6b4fa668 | ||
|
|
ef1be317e1 | ||
|
|
137d78ff73 | ||
|
|
0ddcda4b0c | ||
|
|
bf27af3925 | ||
|
|
607e15424d | ||
|
|
7c490448ec | ||
|
|
d775d2255f | ||
|
|
b94771de92 | ||
|
|
b29e16a198 | ||
|
|
0e06b4f9ce | ||
|
|
f2ab751e5f | ||
|
|
3432497efe | ||
|
|
60bb03049e | ||
|
|
a7541256cb | ||
|
|
e26fb62f5d | ||
|
|
887833089b | ||
|
|
1438f8d557 | ||
|
|
25e359facd | ||
|
|
b98d45615c | ||
|
|
7e8eff5395 | ||
|
|
f4718a71a2 | ||
|
|
46ea2d03b5 | ||
|
|
1eee11e433 | ||
|
|
a71192a63b | ||
|
|
633ff46596 | ||
|
|
8a1f350d67 | ||
|
|
ef364e1430 | ||
|
|
f6a6a5622d | ||
|
|
63d6f7c43f | ||
|
|
6e101c4647 | ||
|
|
fa792efacb | ||
|
|
66f6a75a10 | ||
|
|
de2502fad5 | ||
|
|
54171e1903 | ||
|
|
44172c1d1f | ||
|
|
41945c62f8 | ||
|
|
37d0dcb48f | ||
|
|
002e43e5fb | ||
|
|
9510aa9cf1 | ||
|
|
6a3c2b1002 | ||
|
|
f69b66dced | ||
|
|
cb1fadba4c | ||
|
|
5da91ab73e | ||
|
|
d5b541724f | ||
|
|
9758007f91 | ||
|
|
9d5f8e137f | ||
|
|
f1da95f055 | ||
|
|
9602f3c7a7 | ||
|
|
d357f5a0a4 | ||
|
|
a9eab8d86a | ||
|
|
9191199ef4 | ||
|
|
2556753530 | ||
|
|
57983a6dbc | ||
|
|
327e7ba7ba | ||
|
|
67415cf8d3 | ||
|
|
aa88ff68a1 | ||
|
|
07a0245f85 | ||
|
|
d3de613a8c | ||
|
|
bb1f69e86c | ||
|
|
dc4c2a79d9 | ||
|
|
38451a7d3d | ||
|
|
87d11d5c78 | ||
|
|
c1bbce1114 | ||
|
|
61576d3e87 | ||
|
|
c9100d2e38 | ||
|
|
7714153faf | ||
|
|
654fd7ba68 | ||
|
|
ea9f618de8 | ||
|
|
eea5a2477b | ||
|
|
8cc101b617 | ||
|
|
316d3542a9 | ||
|
|
c2da219473 | ||
|
|
6874e767c2 | ||
|
|
5a91d37365 | ||
|
|
f9c972d866 | ||
|
|
ada8f28aae | ||
|
|
11afc52b84 | ||
|
|
d9c3f0e66c | ||
|
|
49da5c33df | ||
|
|
29250f264a | ||
|
|
df00641290 | ||
|
|
a05a1403f5 | ||
|
|
c5817594d0 | ||
|
|
68a9e45337 | ||
|
|
b8da0f0890 | ||
|
|
62ff45b31f | ||
|
|
918ad48675 | ||
|
|
e5128bf02e | ||
|
|
0a0d6e7228 | ||
|
|
69180914f8 | ||
|
|
5552fda906 | ||
|
|
13759821fe | ||
|
|
2e7843da56 | ||
|
|
33ee904f60 | ||
|
|
3e8bedb1e9 | ||
|
|
4f3ad37bf4 | ||
|
|
af92ea064e | ||
|
|
dab5abb89a | ||
|
|
8893b112fa | ||
|
|
d65fa99e3c | ||
|
|
29381da2ce | ||
|
|
d96f47f93d | ||
|
|
830994b637 | ||
|
|
0d586e2101 | ||
|
|
5e6549a22c | ||
|
|
ab204cfa59 | ||
|
|
3ca77a38fb | ||
|
|
67051c74a8 | ||
|
|
2a0bf12e65 | ||
|
|
dfa16adf31 | ||
|
|
96b30e0df6 | ||
|
|
ef99a886cc | ||
|
|
20eb993757 | ||
|
|
3474be175d | ||
|
|
532bf6f0f4 | ||
|
|
c4c1e50f68 | ||
|
|
7754e12194 | ||
|
|
287d68790f | ||
|
|
7d396b1749 | ||
|
|
d666e3467f | ||
|
|
d4c158cfa4 | ||
|
|
f1af936c7d | ||
|
|
72d52b594c | ||
|
|
5622b38c17 | ||
|
|
cef3a48ff1 | ||
|
|
c6b58bb16b | ||
|
|
14ffe72574 | ||
|
|
02baf1589f | ||
|
|
9a1067862a | ||
|
|
07f848e1c7 | ||
|
|
80846ac637 | ||
|
|
62c0803cf5 | ||
|
|
08df872863 | ||
|
|
ca30e27b27 | ||
|
|
56615a5e9e | ||
|
|
9c44d234ed | ||
|
|
e03e01d410 | ||
|
|
940e701fa4 | ||
|
|
031f8b4ef9 | ||
|
|
ed6b7f3326 | ||
|
|
0ded1df66d | ||
|
|
f4dfbacf03 | ||
|
|
3fd8740c92 | ||
|
|
68dc0bd4ec | ||
|
|
cc96048dfa | ||
|
|
6697327265 | ||
|
|
a301d3e1f0 | ||
|
|
2c0e05bbcc | ||
|
|
92c1052cf5 | ||
|
|
c4763a64d8 | ||
|
|
82648dcbfc | ||
|
|
d0eadcb12e | ||
|
|
f38baea729 | ||
|
|
6048a8a1c5 | ||
|
|
b84a6114f4 | ||
|
|
b3ea5f19a8 | ||
|
|
b52a1f4da4 | ||
|
|
470d65d92a | ||
|
|
2aff3cd491 | ||
|
|
84669cb47f |
@@ -1,2 +1,3 @@
|
||||
.gitattributes export-ignore
|
||||
.gitignore export-ignore
|
||||
*.php whitespace=blank-at-eol,blank-at-eof,space-before-tab,cr-at-eol
|
||||
|
||||
+11
@@ -13,6 +13,17 @@ cheditor5.*/
|
||||
log/
|
||||
g5_tree/
|
||||
.vscode/
|
||||
.claude/
|
||||
.cursor/
|
||||
.windsurf/
|
||||
.idea/
|
||||
.playwright-mcp
|
||||
.mcp.json
|
||||
.agents
|
||||
.DS_Store
|
||||
*.swp
|
||||
*.swo
|
||||
CLAUDE.local.md
|
||||
naver*.html
|
||||
initests01/
|
||||
SIRsoft000/
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
# Gnuboard5 Security Policy
|
||||
|
||||
Please ask [https://sir.kr/security/.](https://sir.kr/co_qa)
|
||||
@@ -3,6 +3,10 @@ define('G5_IS_ADMIN', true);
|
||||
require_once '../common.php';
|
||||
require_once G5_ADMIN_PATH . '/admin.lib.php';
|
||||
|
||||
if (function_exists('g5_check_data_htaccess')) {
|
||||
g5_check_data_htaccess();
|
||||
}
|
||||
|
||||
if (isset($token)) {
|
||||
$token = @htmlspecialchars(strip_tags($token), ENT_QUOTES);
|
||||
}
|
||||
|
||||
+1
-1
@@ -42,7 +42,7 @@ function print_menu2($key, $no = '')
|
||||
continue;
|
||||
}
|
||||
|
||||
if ($is_admin != 'super' && (!array_key_exists($menu[$key][$i][0], $auth) || !strstr($auth[$menu[$key][$i][0]], 'r'))) {
|
||||
if ($is_admin != 'super' && (!array_key_exists($menu[$key][$i][0], $auth) || strpos($auth[$menu[$key][$i][0]], 'r') === false)) {
|
||||
continue;
|
||||
}
|
||||
|
||||
|
||||
+109
-5
@@ -1,11 +1,115 @@
|
||||
function check_all(f)
|
||||
{
|
||||
var chk = document.getElementsByName("chk[]");
|
||||
/** 공통 UI 모듈 */
|
||||
window.CommonUI = {
|
||||
bindTabs(tabSelector, contentSelector, options = {}) {
|
||||
const tabs = document.querySelectorAll(tabSelector);
|
||||
const contents = document.querySelectorAll(contentSelector);
|
||||
|
||||
for (i=0; i<chk.length; i++)
|
||||
chk[i].checked = f.chkall.checked;
|
||||
tabs.forEach(tab => {
|
||||
tab.addEventListener('click', () => {
|
||||
const tabName = tab.dataset.tab;
|
||||
const target = document.getElementById(`tab-${tabName}`);
|
||||
|
||||
tabs.forEach(t => t.classList.remove('active'));
|
||||
tab.classList.add('active');
|
||||
|
||||
contents.forEach(c => c.classList.add('is-hidden'));
|
||||
|
||||
if (target) target.classList.remove('is-hidden');
|
||||
|
||||
options.onChange?.(tabName, target);
|
||||
});
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
function setHtml(el, markup) {
|
||||
if (!el) return;
|
||||
if (markup == null || markup === '') {
|
||||
el.textContent = '';
|
||||
return;
|
||||
}
|
||||
const range = document.createRange();
|
||||
range.selectNodeContents(el);
|
||||
el.replaceChildren(range.createContextualFragment(markup));
|
||||
}
|
||||
|
||||
/** 팝업 관리 모듈 */
|
||||
window.PopupManager = {
|
||||
open(id, options = {}) {
|
||||
const el = document.getElementById(id);
|
||||
if (el) {
|
||||
el.classList.remove('is-hidden');
|
||||
this.bindOutsideClickClose(id);
|
||||
|
||||
if (!options.disableOutsideClose) {
|
||||
this.bindOutsideClickClose(id);
|
||||
} else {
|
||||
this.unbindOutsideClickClose(id);
|
||||
}
|
||||
}
|
||||
},
|
||||
|
||||
close(id) {
|
||||
const el = document.getElementById(id);
|
||||
if (el) el.classList.add('is-hidden');
|
||||
},
|
||||
|
||||
toggle(id) {
|
||||
const el = document.getElementById(id);
|
||||
if (el) el.classList.toggle('is-hidden');
|
||||
},
|
||||
|
||||
bindOutsideClickClose(id) {
|
||||
const el = document.getElementById(id);
|
||||
if (!el) return;
|
||||
el.onclick = () => this.close(id);
|
||||
},
|
||||
|
||||
unbindOutsideClickClose(id) {
|
||||
const el = document.getElementById(id);
|
||||
if (!el) return;
|
||||
el.onclick = null;
|
||||
},
|
||||
|
||||
/**
|
||||
* 팝업 콘텐츠 렌더링 (타이틀, 바디, 푸터 구성)
|
||||
* @param {string} title - 팝업 제목
|
||||
* @param {string} body - 팝업 본문 HTML
|
||||
* @param {string} [footer] - 푸터 HTML
|
||||
* @param {object} [options] - 팝업 열기 옵션
|
||||
*/
|
||||
render(title, body, footer = '', options = {}) {
|
||||
const titleEl = document.getElementById('popupTitle');
|
||||
const bodyEl = document.getElementById('popupBody');
|
||||
const footerEl = document.getElementById('popupFooter');
|
||||
|
||||
if (titleEl) titleEl.textContent = title;
|
||||
if (bodyEl) setHtml(bodyEl, body);
|
||||
if (footerEl) setHtml(footerEl, footer);
|
||||
|
||||
this.open('popupOverlay', options);
|
||||
}
|
||||
};
|
||||
|
||||
/** 형식 체크 */
|
||||
function check_all(target) {
|
||||
const chkboxes = document.getElementsByName("chk[]");
|
||||
let chkall;
|
||||
|
||||
if (target && target.tagName === "FORM") {
|
||||
chkall = target.querySelector('input[name="chkall"]');
|
||||
} else if (target && target.type === "checkbox") {
|
||||
chkall = target;
|
||||
}
|
||||
|
||||
if (!chkall) return;
|
||||
|
||||
for (const checkbox of chkboxes) {
|
||||
checkbox.checked = chkall.checked;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
function btn_check(f, act)
|
||||
{
|
||||
if (act == "update") // 선택수정
|
||||
|
||||
+117
-4
@@ -281,7 +281,7 @@ function auth_check($auth, $attr, $return = false)
|
||||
|
||||
$attr = strtolower($attr);
|
||||
|
||||
if (!strstr($auth, $attr)) {
|
||||
if (strpos($auth, $attr) === false) {
|
||||
if ($attr == 'r') {
|
||||
$msg = '읽을 권한이 없습니다.';
|
||||
if ($return) {
|
||||
@@ -389,7 +389,7 @@ function order_select($fld, $sel = '')
|
||||
// 불법접근을 막도록 토큰을 생성하면서 토큰값을 리턴
|
||||
function get_admin_token()
|
||||
{
|
||||
$token = md5(uniqid(rand(), true));
|
||||
$token = get_random_token_string(16);
|
||||
set_session('ss_admin_token', $token);
|
||||
|
||||
return $token;
|
||||
@@ -554,9 +554,18 @@ function admin_check_xss_params($params)
|
||||
|
||||
if (is_array($value)) {
|
||||
admin_check_xss_params($value);
|
||||
} else if ((preg_match('/<\s?[^\>]*\/?\s?>/i', $value) && (preg_match('/script.*?\/script/ius', $value) || preg_match('/(onload|onerror)=.*/ius', $value))) || preg_match('/^(?=.*token\()(?=.*xmlhttprequest\()(?=.*send\().*$/im', $value) || (preg_match('/(onload|onerror|focus)=.*/ius', $value) && preg_match('/(eval|expression|exec|prompt)(\s*)\((.*)\)/ius', $value))) {
|
||||
} else if (
|
||||
(preg_match('/<\s?[^\>]*\/?\s?>/i', $value) && (preg_match('/script.*?\/script/ius', $value) || preg_match('/on[a-z]+=*/ius', $value))) || preg_match('/^(?=.*token\()(?=.*xmlhttprequest\()(?=.*send\().*$/im', $value) ||
|
||||
(preg_match('/(on[a-z]+|focus)=.*/ius', $value) && preg_match('/(eval|atob|fetch|expression|exec|prompt)(\s*)\((.*)\)/ius', $value))) {
|
||||
alert('요청 쿼리에 잘못된 스크립트문장이 있습니다.\\nXSS 공격일수도 있습니다.', G5_URL);
|
||||
die();
|
||||
} else if (preg_match('/atob\s*\(\s*[\'"]?([a-zA-Z0-9+\/=]+)[\'"]?\s*\)/ius', $value, $matches)) {
|
||||
$decoded = base64_decode($matches[1], true);
|
||||
if ($decoded && preg_match('/(eval|fetch|script|alert|settimeout|setinterval)/ius', $decoded)) {
|
||||
// error_log("Base64 XSS 시도 감지: key=$key, decoded=$decoded, IP=" . $_SERVER['REMOTE_ADDR']);
|
||||
alert('Base64로 인코딩된 위험한 스크립트가 발견되었습니다.', G5_URL);
|
||||
die();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -601,6 +610,110 @@ function admin_menu_find_by($call, $search_key)
|
||||
return '';
|
||||
}
|
||||
|
||||
function admin_menu_local_path($url)
|
||||
{
|
||||
$url = (string) $url;
|
||||
|
||||
if (!$url) {
|
||||
return '';
|
||||
}
|
||||
|
||||
$url = preg_replace('/[?#].*$/', '', $url);
|
||||
|
||||
$maps = array(
|
||||
G5_ADMIN_URL => G5_ADMIN_PATH,
|
||||
);
|
||||
|
||||
if (defined('G5_SMS5_ADMIN_URL') && defined('G5_SMS5_ADMIN_PATH')) {
|
||||
$maps[G5_SMS5_ADMIN_URL] = G5_SMS5_ADMIN_PATH;
|
||||
}
|
||||
|
||||
foreach ($maps as $base_url => $base_path) {
|
||||
if (strpos($url, $base_url) !== 0) {
|
||||
continue;
|
||||
}
|
||||
|
||||
$path = $base_path.substr($url, strlen($base_url));
|
||||
|
||||
if (substr($path, -1) === '/') {
|
||||
$path .= 'index.php';
|
||||
}
|
||||
|
||||
return $path;
|
||||
}
|
||||
|
||||
return '';
|
||||
}
|
||||
|
||||
function admin_menu_is_super_only($menu_item)
|
||||
{
|
||||
static $cache = array();
|
||||
|
||||
$sub_menu = isset($menu_item[0]) ? (string) $menu_item[0] : '';
|
||||
if (!$sub_menu) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if (isset($cache[$sub_menu])) {
|
||||
return $cache[$sub_menu];
|
||||
}
|
||||
|
||||
// 향후 메뉴 정의에서 명시적으로 최고관리자 전용 표시가 필요할 때 사용한다.
|
||||
if (isset($menu_item[4]) && $menu_item[4] === 'super') {
|
||||
return $cache[$sub_menu] = true;
|
||||
}
|
||||
|
||||
$path = admin_menu_local_path(isset($menu_item[2]) ? $menu_item[2] : '');
|
||||
if (!$path || !is_readable($path)) {
|
||||
return $cache[$sub_menu] = false;
|
||||
}
|
||||
|
||||
$content = file_get_contents($path, false, null, 0, 12000);
|
||||
if ($content === false) {
|
||||
return $cache[$sub_menu] = false;
|
||||
}
|
||||
|
||||
$pattern = '/if\s*\([^\)]*\$is_admin\s*(?:!==|!=)\s*[\'"]super[\'"][^\)]*\)\s*\{?[\s\S]{0,250}(?:alert|alert_close|die)\s*\([^\;]*(?:최고관리자만|최고관리자로)/u';
|
||||
|
||||
return $cache[$sub_menu] = (bool) preg_match($pattern, $content);
|
||||
}
|
||||
|
||||
function admin_get_assignable_auth_menu()
|
||||
{
|
||||
global $menu;
|
||||
|
||||
$assignable_auth_menu = array();
|
||||
|
||||
if (!isset($menu) || !is_array($menu)) {
|
||||
return $assignable_auth_menu;
|
||||
}
|
||||
|
||||
foreach ($menu as $menu_group) {
|
||||
if (!is_array($menu_group)) {
|
||||
continue;
|
||||
}
|
||||
|
||||
for ($i=1; $i<count($menu_group); $i++) {
|
||||
if (!isset($menu_group[$i]) || !is_array($menu_group[$i])) {
|
||||
continue;
|
||||
}
|
||||
|
||||
$sub_menu = isset($menu_group[$i][0]) ? $menu_group[$i][0] : '';
|
||||
if (!$sub_menu || $sub_menu === '-' || substr($sub_menu, -3) === '000') {
|
||||
continue;
|
||||
}
|
||||
|
||||
if (admin_menu_is_super_only($menu_group[$i])) {
|
||||
continue;
|
||||
}
|
||||
|
||||
$assignable_auth_menu[$sub_menu] = isset($menu_group[$i][1]) ? $menu_group[$i][1] : '';
|
||||
}
|
||||
}
|
||||
|
||||
return $assignable_auth_menu;
|
||||
}
|
||||
|
||||
// 접근 권한 검사
|
||||
if (!$member['mb_id']) {
|
||||
alert('로그인 하십시오.', G5_BBS_URL . '/login.php?url=' . urlencode(correct_goto_url(G5_ADMIN_URL)));
|
||||
@@ -689,4 +802,4 @@ if (run_replace('safe_admin_add_script_boolean', false) === false) {
|
||||
$config['cf_analytics'] = '';
|
||||
$config['cf_add_script'] = '';
|
||||
$config['cf_add_meta'] = '';
|
||||
}
|
||||
}
|
||||
|
||||
@@ -11,6 +11,7 @@ $menu['menu100'] = array(
|
||||
array('100900', '캐시파일 일괄삭제', G5_ADMIN_URL . '/cache_file_delete.php', 'cf_cache', 1),
|
||||
array('100910', '캡챠파일 일괄삭제', G5_ADMIN_URL . '/captcha_file_delete.php', 'cf_captcha', 1),
|
||||
array('100920', '썸네일파일 일괄삭제', G5_ADMIN_URL . '/thumbnail_file_delete.php', 'cf_thumbnail', 1),
|
||||
array('100930', '회원관리파일 일괄삭제', G5_ADMIN_URL . '/member_list_file_delete.php', 'cf_memberlist', 1),
|
||||
array('100500', 'phpinfo()', G5_ADMIN_URL . '/phpinfo.php', 'cf_phpinfo')
|
||||
);
|
||||
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
$menu['menu200'] = array(
|
||||
array('200000', '회원관리', G5_ADMIN_URL . '/member_list.php', 'member'),
|
||||
array('200100', '회원관리', G5_ADMIN_URL . '/member_list.php', 'mb_list'),
|
||||
array('200400', '회원관리파일', G5_ADMIN_URL . '/member_list_exel.php', 'mb_list'),
|
||||
array('200300', '회원메일발송', G5_ADMIN_URL . '/mail_list.php', 'mb_mail'),
|
||||
array('200800', '접속자집계', G5_ADMIN_URL . '/visit_list.php', 'mb_visit', 1),
|
||||
array('200810', '접속자검색', G5_ADMIN_URL . '/visit_search.php', 'mb_search', 1),
|
||||
|
||||
+19
-3
@@ -14,16 +14,32 @@ $print_version = ($is_admin == 'super') ? 'Version ' . G5_GNUBOARD_VER : '';
|
||||
<strong>자바스크립트를 사용하지 않음</strong>으로 설정하신 경우는 수정이나 삭제시 별도의 경고창이 나오지 않으므로 이점 주의하시기 바랍니다.
|
||||
</p>
|
||||
</noscript>
|
||||
|
||||
</div>
|
||||
<footer id="ft">
|
||||
<p>
|
||||
Copyright © <?php echo $_SERVER['HTTP_HOST']; ?>. All rights reserved. <?php echo $print_version; ?><br>
|
||||
Copyright © <?php echo htmlspecialchars($_SERVER['HTTP_HOST']); ?>. All rights reserved. <?php echo $print_version; ?><br>
|
||||
<button type="button" class="scroll_top"><span class="top_img"></span><span class="top_txt">TOP</span></button>
|
||||
</p>
|
||||
</footer>
|
||||
</div>
|
||||
|
||||
<!-- 공통 레이어 팝업 컨테이너 -->
|
||||
<div id="adminPopupContainer">
|
||||
<div id="popupOverlay" class="popup-overlay is-hidden" onclick="PopupManager.close('popupOverlay')">
|
||||
<div class="popup-content" onclick="event.stopPropagation()">
|
||||
<div class="popup-header">
|
||||
<strong id="popupTitle" class="popup-title"></strong>
|
||||
<button type="button" class="popup-close-btn" onclick="PopupManager.close('popupOverlay')">
|
||||
<i class="fa fa-close"></i><span class="sound_only">팝업 닫기</span>
|
||||
</button>
|
||||
</div>
|
||||
<div class="popup-body" id="popupBody">
|
||||
<!-- 동적으로 내용 주입 -->
|
||||
</div>
|
||||
<div class="popup-footer" id="popupFooter">
|
||||
<!-- 버튼 등 동적으로 -->
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<script>
|
||||
|
||||
+10
-5
@@ -23,6 +23,9 @@ if (!$sst) {
|
||||
$sst = "a.mb_id, au_menu";
|
||||
$sod = "";
|
||||
}
|
||||
$allowed_sst = array('a.mb_id', 'mb_nick', 'au_menu', 'au_auth', 'a.mb_id, au_menu');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'a.mb_id, au_menu';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by $sst $sod ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
@@ -51,6 +54,8 @@ $listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall btn_ov02
|
||||
$g5['title'] = "관리권한설정";
|
||||
require_once './admin.head.php';
|
||||
|
||||
$assignable_auth_menu = admin_get_assignable_auth_menu();
|
||||
|
||||
$colspan = 5;
|
||||
?>
|
||||
|
||||
@@ -102,8 +107,8 @@ $colspan = 5;
|
||||
$is_continue = true;
|
||||
}
|
||||
|
||||
// 메뉴번호가 바뀌는 경우에 현재 없는 저장된 메뉴는 삭제함
|
||||
if (!isset($auth_menu[$row['au_menu']])) {
|
||||
// 메뉴번호가 바뀌거나 권한 부여 대상이 아닌 메뉴는 삭제함
|
||||
if (!isset($assignable_auth_menu[$row['au_menu']])) {
|
||||
sql_query(" delete from {$g5['auth_table']} where au_menu = '{$row['au_menu']}' ");
|
||||
$is_continue = true;
|
||||
}
|
||||
@@ -127,7 +132,7 @@ $colspan = 5;
|
||||
<td class="td_auth_mbnick"><?php echo $mb_nick ?></td>
|
||||
<td class="td_menu">
|
||||
<?php echo $row['au_menu'] ?>
|
||||
<?php echo $auth_menu[$row['au_menu']] ?>
|
||||
<?php echo $assignable_auth_menu[$row['au_menu']] ?>
|
||||
</td>
|
||||
<td class="td_auth"><?php echo $row['au_auth'] ?></td>
|
||||
</tr>
|
||||
@@ -151,7 +156,7 @@ $colspan = 5;
|
||||
//if (isset($stx))
|
||||
// echo '<script>document.fsearch.sfl.value = "'.$sfl.'";</script>'."\n";
|
||||
|
||||
if (strstr($sfl, 'mb_id')) {
|
||||
if (strpos($sfl, 'mb_id') !== false) {
|
||||
$mb_id = $stx;
|
||||
} else {
|
||||
$mb_id = '';
|
||||
@@ -202,7 +207,7 @@ echo $pagelist;
|
||||
<select id="au_menu" name="au_menu" required class="required">
|
||||
<option value=''>선택하세요</option>
|
||||
<?php
|
||||
foreach ($auth_menu as $key => $value) {
|
||||
foreach ($assignable_auth_menu as $key => $value) {
|
||||
if (!(substr($key, -3) == '000' || $key == '-' || !$key)) {
|
||||
echo '<option value="' . $key . '">' . $key . ' ' . $value . '</option>';
|
||||
}
|
||||
|
||||
+6
-1
@@ -13,12 +13,17 @@ if ($is_admin != 'super') {
|
||||
}
|
||||
|
||||
$mb = get_member($mb_id);
|
||||
if (!$mb['mb_id']) {
|
||||
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
|
||||
alert('존재하는 회원아이디가 아닙니다.');
|
||||
}
|
||||
|
||||
check_admin_token();
|
||||
|
||||
$assignable_auth_menu = admin_get_assignable_auth_menu();
|
||||
if (!$au_menu || !isset($assignable_auth_menu[$au_menu])) {
|
||||
alert('해당 메뉴는 관리권한을 부여할 수 없습니다.');
|
||||
}
|
||||
|
||||
require_once G5_CAPTCHA_PATH . '/captcha.lib.php';
|
||||
|
||||
if (!chk_captcha()) {
|
||||
|
||||
@@ -12,7 +12,7 @@ $bo_table = isset($_POST['bo_table']) ? substr(preg_replace('/[^a-z0-9_]/i
|
||||
$target_table = isset($_POST['target_table']) ? trim($_POST['target_table']) : '';
|
||||
$target_subject = isset($_POST['target_subject']) ? trim($_POST['target_subject']) : '';
|
||||
|
||||
$target_subject = strip_tags(clean_xss_attributes($target_subject));
|
||||
$target_subject = addslashes(strip_tags(clean_xss_attributes(stripslashes($target_subject))));
|
||||
|
||||
$file_copy = array();
|
||||
|
||||
|
||||
+10
-6
@@ -1439,7 +1439,7 @@ function frm_check_file(){
|
||||
|
||||
return false;
|
||||
} else {
|
||||
jQuery("#admin_captcha_box").hide();
|
||||
// jQuery("#admin_captcha_box").hide();
|
||||
}
|
||||
|
||||
return true;
|
||||
@@ -1447,12 +1447,12 @@ function frm_check_file(){
|
||||
|
||||
jQuery(function($){
|
||||
if( window.self !== window.top ){ // frame 또는 iframe을 사용할 경우 체크
|
||||
$("#bo_include_head, #bo_include_tail").on("change paste keyup", function(e) {
|
||||
frm_check_file();
|
||||
});
|
||||
|
||||
use_captcha_check();
|
||||
}
|
||||
|
||||
$("#bo_include_head, #bo_include_tail").on("change paste keyup", function(e) {
|
||||
frm_check_file();
|
||||
});
|
||||
});
|
||||
|
||||
function fboardform_submit(f)
|
||||
@@ -1487,10 +1487,14 @@ function fboardform_submit(f)
|
||||
return false;
|
||||
}
|
||||
|
||||
if (frm_check_file() == false) {
|
||||
jQuery(window).scrollTop($('#bo_include_tail').offset().top - 30);
|
||||
}
|
||||
|
||||
if( captcha_chk ) {
|
||||
<?php echo isset($captcha_js) ? $captcha_js : ''; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
|
||||
}
|
||||
|
||||
|
||||
return true;
|
||||
}
|
||||
</script>
|
||||
|
||||
+37
-10
@@ -12,8 +12,8 @@ check_admin_token();
|
||||
|
||||
$gr_id = isset($_POST['gr_id']) ? preg_replace('/[^a-z0-9_]/i', '', (string)$_POST['gr_id']) : '';
|
||||
$bo_admin = isset($_POST['bo_admin']) ? preg_replace('/[^a-z0-9_\, \|\#]/i', '', $_POST['bo_admin']) : '';
|
||||
$bo_subject = isset($_POST['bo_subject']) ? strip_tags(clean_xss_attributes($_POST['bo_subject'])) : '';
|
||||
$bo_mobile_subject = isset($_POST['bo_mobile_subject']) ? strip_tags(clean_xss_attributes($_POST['bo_mobile_subject'])) : '';
|
||||
$bo_subject = isset($_POST['bo_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bo_subject'])))) : '';
|
||||
$bo_mobile_subject = isset($_POST['bo_mobile_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bo_mobile_subject'])))) : '';
|
||||
|
||||
if (!$gr_id) {
|
||||
alert('그룹 ID는 반드시 선택하세요.');
|
||||
@@ -36,10 +36,27 @@ if ($w == '' && in_array($bo_table, get_bo_table_banned_word())) {
|
||||
$bo_include_head = isset($_POST['bo_include_head']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['bo_include_head'], 0, 255)) : '';
|
||||
$bo_include_tail = isset($_POST['bo_include_tail']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['bo_include_tail'], 0, 255)) : '';
|
||||
|
||||
// 관리자가 자동등록방지를 사용해야 할 경우
|
||||
if ($board && (isset($board['bo_include_head']) && $board['bo_include_head'] !== $bo_include_head || $board['bo_include_tail'] !== $bo_include_tail) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
|
||||
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
|
||||
$check_captcha = false;
|
||||
|
||||
// 관리자가 자동등록방지 CAPTCHA를 사용해야 할 경우
|
||||
// 최고 관리자인 경우에만 수정가능
|
||||
if ($is_admin === 'super') {
|
||||
if ($w === 'u') {
|
||||
if (isset($board['bo_include_head'], $board['bo_include_tail']) &&
|
||||
($board['bo_include_head'] !== $bo_include_head || $board['bo_include_tail'] !== $bo_include_tail)) {
|
||||
$check_captcha = true;
|
||||
}
|
||||
} elseif ($w === '') {
|
||||
if ($bo_include_head !== '_head.php' || $bo_include_tail !== '_tail.php') {
|
||||
$check_captcha = true;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 실제 CAPTCHA 검증
|
||||
if ($check_captcha) {
|
||||
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
|
||||
|
||||
if (!chk_captcha()) {
|
||||
alert('자동등록방지 숫자가 틀렸습니다.');
|
||||
}
|
||||
@@ -122,7 +139,7 @@ $bo_hot = isset($_POST['bo_hot']) ? (int) $_POST['bo_hot'] : 0;
|
||||
$bo_image_width = isset($_POST['bo_image_width']) ? (int) $_POST['bo_image_width'] : 0;
|
||||
$bo_use_search = isset($_POST['bo_use_search']) ? (int) $_POST['bo_use_search'] : 0;
|
||||
$bo_use_cert = isset($_POST['bo_use_cert']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['bo_use_cert']) : '';
|
||||
$bo_device = isset($_POST['bo_device']) ? clean_xss_tags($_POST['bo_device'], 1, 1) : '';
|
||||
$bo_device = isset($_POST['bo_device']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_device']), 1, 1)) : '';
|
||||
$bo_list_level = isset($_POST['bo_list_level']) ? (int) $_POST['bo_list_level'] : 0;
|
||||
$bo_read_level = isset($_POST['bo_read_level']) ? (int) $_POST['bo_read_level'] : 0;
|
||||
$bo_write_level = isset($_POST['bo_write_level']) ? (int) $_POST['bo_write_level'] : 0;
|
||||
@@ -138,9 +155,9 @@ $bo_read_point = isset($_POST['bo_read_point']) ? (int) $_POST['bo_read_point']
|
||||
$bo_write_point = isset($_POST['bo_write_point']) ? (int) $_POST['bo_write_point'] : 0;
|
||||
$bo_comment_point = isset($_POST['bo_comment_point']) ? (int) $_POST['bo_comment_point'] : 0;
|
||||
$bo_download_point = isset($_POST['bo_download_point']) ? (int) $_POST['bo_download_point'] : 0;
|
||||
$bo_select_editor = isset($_POST['bo_select_editor']) ? clean_xss_tags($_POST['bo_select_editor'], 1, 1) : '';
|
||||
$bo_skin = isset($_POST['bo_skin']) ? clean_xss_tags($_POST['bo_skin'], 1, 1) : '';
|
||||
$bo_mobile_skin = isset($_POST['bo_mobile_skin']) ? clean_xss_tags($_POST['bo_mobile_skin'], 1, 1) : '';
|
||||
$bo_select_editor = isset($_POST['bo_select_editor']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_select_editor']), 1, 1)) : '';
|
||||
$bo_skin = isset($_POST['bo_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_skin']), 1, 1)) : '';
|
||||
$bo_mobile_skin = isset($_POST['bo_mobile_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_mobile_skin']), 1, 1)) : '';
|
||||
$bo_content_head = isset($_POST['bo_content_head']) ? $_POST['bo_content_head'] : '';
|
||||
$bo_content_tail = isset($_POST['bo_content_tail']) ? $_POST['bo_content_tail'] : '';
|
||||
$bo_mobile_content_head = isset($_POST['bo_mobile_content_head']) ? $_POST['bo_mobile_content_head'] : '';
|
||||
@@ -159,7 +176,17 @@ $bo_write_min = isset($_POST['bo_write_min']) ? (int) $_POST['bo_write_min'] : 0
|
||||
$bo_write_max = isset($_POST['bo_write_max']) ? (int) $_POST['bo_write_max'] : 0;
|
||||
$bo_comment_min = isset($_POST['bo_comment_min']) ? (int) $_POST['bo_comment_min'] : 0;
|
||||
$bo_comment_max = isset($_POST['bo_comment_max']) ? (int) $_POST['bo_comment_max'] : 0;
|
||||
$bo_sort_field = isset($_POST['bo_sort_field']) ? clean_xss_tags($_POST['bo_sort_field'], 1, 1) : '';
|
||||
$bo_sort_field = isset($_POST['bo_sort_field']) ? trim(stripslashes($_POST['bo_sort_field'])) : '';
|
||||
$bo_allowed_sort_field = array('');
|
||||
if (function_exists('get_board_sort_fields')) {
|
||||
foreach (get_board_sort_fields(isset($board) ? $board : array()) as $bo_sort_v) {
|
||||
$bo_allowed_sort_field[] = $bo_sort_v[0];
|
||||
}
|
||||
}
|
||||
if (!in_array($bo_sort_field, $bo_allowed_sort_field, true)) {
|
||||
$bo_sort_field = '';
|
||||
}
|
||||
$bo_sort_field = addslashes($bo_sort_field);
|
||||
|
||||
if (strpbrk($bo_skin.$bo_mobile_skin, "?%*:|\"<>") !== false) {
|
||||
alert('스킨 디렉토리명 오류!');
|
||||
|
||||
@@ -32,6 +32,9 @@ if (!$sst) {
|
||||
$sst = "a.gr_id, a.bo_table";
|
||||
$sod = "asc";
|
||||
}
|
||||
$allowed_sst = array('a.gr_id', 'bo_table', 'bo_skin', 'bo_mobile_skin', 'bo_subject', 'bo_use_sns', 'bo_use_search', 'bo_order', 'a.gr_id, a.bo_table');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'a.gr_id, a.bo_table';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by $sst $sod ";
|
||||
|
||||
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
|
||||
|
||||
@@ -46,7 +46,7 @@ if ($act_button === "선택수정") {
|
||||
}
|
||||
}
|
||||
|
||||
$p_bo_subject = is_array($_POST['bo_subject']) ? strip_tags(clean_xss_attributes($_POST['bo_subject'][$k])) : '';
|
||||
$p_bo_subject = is_array($_POST['bo_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bo_subject'][$k])))) : '';
|
||||
|
||||
$sql = " update {$g5['board_table']}
|
||||
set gr_id = '" . sql_real_escape_string($post_gr_id) . "',
|
||||
|
||||
@@ -39,7 +39,7 @@ for ($i = 1; $i <= 10; $i++) {
|
||||
|
||||
foreach ($check_keys as $key => $value) {
|
||||
if ($key === 'gr_subject') {
|
||||
$posts[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
|
||||
$posts[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
|
||||
} else {
|
||||
$posts[$key] = isset($_POST[$key]) ? $_POST[$key] : '';
|
||||
}
|
||||
|
||||
@@ -34,6 +34,9 @@ if ($stx) {
|
||||
$sql_search .= " ) ";
|
||||
}
|
||||
|
||||
$allowed_sst = array('gr_id', 'gr_subject', 'gr_admin', 'gr_order');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = '';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
if ($sst) {
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
} else {
|
||||
|
||||
@@ -21,7 +21,7 @@ if (!$chk_count) {
|
||||
for ($i = 0; $i < $chk_count; $i++) {
|
||||
$k = isset($post_chk[$i]) ? (int) $post_chk[$i] : 0;
|
||||
$gr_id = preg_replace('/[^a-z0-9_]/i', '', $post_group_id[$k]);
|
||||
$gr_subject = isset($_POST['gr_subject'][$k]) ? strip_tags(clean_xss_attributes($_POST['gr_subject'][$k])) : '';
|
||||
$gr_subject = isset($_POST['gr_subject'][$k]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['gr_subject'][$k])))) : '';
|
||||
$gr_admin = isset($_POST['gr_admin'][$k]) ? strip_tags(clean_xss_attributes($_POST['gr_admin'][$k])) : '';
|
||||
$gr_device = isset($_POST['gr_device'][$k]) ? clean_xss_tags($_POST['gr_device'][$k], 1, 1, 10) : '';
|
||||
$gr_use_access = isset($_POST['gr_use_access'][$k]) ? (int) $_POST['gr_use_access'][$k] : 0;
|
||||
@@ -36,7 +36,7 @@ for ($i = 0; $i < $chk_count; $i++) {
|
||||
gr_order = '" . $gr_order . "'
|
||||
where gr_id = '{$gr_id}' ";
|
||||
if ($is_admin != 'super') {
|
||||
$sql .= " and gr_admin = '{$gr_admin}' ";
|
||||
$sql .= " and gr_admin = '" . sql_real_escape_string($gr_admin) . "' ";
|
||||
}
|
||||
sql_query($sql);
|
||||
} elseif ($act_button == '선택삭제') {
|
||||
|
||||
@@ -28,6 +28,9 @@ if (!$sst) {
|
||||
$sst = "gm_datetime";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('gm_datetime', 'b.mb_id', 'b.mb_name', 'b.mb_nick', 'b.mb_today_login', 'a.gm_datetime');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'gm_datetime';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
|
||||
@@ -21,7 +21,7 @@ if (!is_file(G5_DATA_PATH . '/cache/browscap_cache.php')) {
|
||||
}
|
||||
|
||||
require_once G5_PLUGIN_PATH . '/browscap/Browscap.php';
|
||||
$browscap = new phpbrowscap\Browscap(G5_DATA_PATH . '/cache');
|
||||
$browscap = new Browscap(G5_DATA_PATH . '/cache');
|
||||
$browscap->doAutoUpdate = false;
|
||||
$browscap->cacheFilename = 'browscap_cache.php';
|
||||
|
||||
|
||||
@@ -17,7 +17,7 @@ if ($is_admin != 'super') {
|
||||
|
||||
require_once G5_PLUGIN_PATH . '/browscap/Browscap.php';
|
||||
|
||||
$browscap = new phpbrowscap\Browscap(G5_DATA_PATH . '/cache');
|
||||
$browscap = new Browscap(G5_DATA_PATH . '/cache');
|
||||
$browscap->updateMethod = 'cURL';
|
||||
$browscap->cacheFilename = 'browscap_cache.php';
|
||||
$browscap->updateCache();
|
||||
|
||||
+163
-10
@@ -411,9 +411,41 @@ if (!isset($config['cf_cert_kg_mid'])) {
|
||||
}
|
||||
if (!isset($config['cf_cert_use_seed'])) {
|
||||
$sql = "ALTER TABLE `{$g5['config_table']}`
|
||||
ADD COLUMN `cf_cert_use_seed` TINYINT(4) NOT NULL DEFAULT '0' AFTER `cf_cert_kg_mid`; ";
|
||||
ADD COLUMN `cf_cert_use_seed` TINYINT(4) NOT NULL DEFAULT '1' AFTER `cf_cert_kg_mid`; ";
|
||||
sql_query($sql, false);
|
||||
}
|
||||
if (!isset($config['cf_cert_kcp_enckey'])) {
|
||||
$sql = "ALTER TABLE `{$g5['config_table']}`
|
||||
ADD COLUMN `cf_cert_kcp_enckey` VARCHAR(100) NOT NULL DEFAULT '' AFTER `cf_cert_kcp_cd`; ";
|
||||
sql_query($sql, false);
|
||||
|
||||
$config['cf_cert_kcp_enckey'] = '';
|
||||
}
|
||||
|
||||
// 광고성 정보 수신 동의 사용 필드 추가
|
||||
if (!isset($config['cf_use_promotion'])) {
|
||||
sql_query(
|
||||
" ALTER TABLE `{$g5['config_table']}`
|
||||
ADD `cf_use_promotion` tinyint(1) NOT NULL DEFAULT '0' AFTER `cf_privacy` ",
|
||||
true
|
||||
);
|
||||
}
|
||||
|
||||
// 광고성 정보 수신 동의 여부 필드 추가 + 메일 / SMS 수신 일자 추가
|
||||
if (!isset($member['mb_marketing_agree'])) {
|
||||
sql_query(
|
||||
" ALTER TABLE `{$g5['member_table']}`
|
||||
ADD `mb_marketing_agree` tinyint(1) NOT NULL DEFAULT '0' AFTER `mb_scrap_cnt`,
|
||||
ADD `mb_marketing_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_marketing_agree`,
|
||||
ADD `mb_thirdparty_agree` tinyint(1) NOT NULL DEFAULT '0' AFTER `mb_marketing_date`,
|
||||
ADD `mb_thirdparty_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_thirdparty_agree`,
|
||||
ADD `mb_agree_log` TEXT NOT NULL AFTER `mb_thirdparty_date`,
|
||||
ADD `mb_mailling_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_mailling`,
|
||||
ADD `mb_sms_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_sms` ",
|
||||
true
|
||||
);
|
||||
}
|
||||
|
||||
if (!$config['cf_faq_skin']) {
|
||||
$config['cf_faq_skin'] = "basic";
|
||||
}
|
||||
@@ -955,6 +987,17 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
|
||||
<th scope="row"><label for="cf_privacy">개인정보처리방침</label></th>
|
||||
<td colspan="3"><textarea id="cf_privacy" name="cf_privacy" rows="10"><?php echo html_purifier($config['cf_privacy']); ?></textarea></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th scope="row"><label for="cf_use_promotion">회원가입 약관 동의에<br>광고성 정보 수신 동의 표시 여부</label></th>
|
||||
<td colspan="3">
|
||||
<?php echo help('<b>광고성 정보 수신 · 마케팅 목적의 개인정보 수집 및 이용 · 개인정보 제 3자 제공</b> 여부를 설정합니다. <b>SMS 또는 카카오톡</b> 사용 시 <b>개인정보 제3자 제공</b>이 활성화됩니다.'); ?>
|
||||
<?php echo help('동의한 회원에게 <b>카카오톡(친구톡)·문자</b>로 광고성 메시지를 발송할 수 있습니다.'); ?>
|
||||
<?php echo help('<b>휴대전화번호</b> 사용을 위해서는 <b>기본환경설정 > 회원가입 > 휴대전화번호 입력</b>을 <b>[보이기]</b> 또는 <b>[필수입력]</b>으로 설정해야 하며, 미설정 시 수집이 불가합니다.'); ?>
|
||||
<?php echo help('* 「정보통신망이용촉진및정보보호등에관한법률」에 따라 <b>광고성 정보 수신 동의</b>를 매 2년마다 반드시 확인해야 합니다.'); ?>
|
||||
<input type="checkbox" name="cf_use_promotion" value="1" id="cf_use_promotion" <?php echo $config['cf_use_promotion'] ? 'checked' : ''; ?>>
|
||||
<label for="cf_use_promotion">사용</label>
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
@@ -1025,7 +1068,24 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
|
||||
<?php echo option_selected("", $config['cf_cert_hp'], "사용안함"); ?>
|
||||
<?php echo option_selected("kcb", $config['cf_cert_hp'], "코리아크레딧뷰로(KCB) 휴대폰 본인확인"); ?>
|
||||
<?php echo option_selected("kcp", $config['cf_cert_hp'], "NHN KCP 휴대폰 본인확인"); ?>
|
||||
<?php echo option_selected("kcp_v2", $config['cf_cert_hp'], "NHN KCP 휴대폰 본인확인(api_v2)"); ?>
|
||||
</select>
|
||||
<div id="cf_cert_hp_kcp_v2_notice" style="display:<?php echo ($config['cf_cert_hp'] == 'kcp_v2') ? 'block' : 'none'; ?>; margin-top:8px; padding:10px 12px; background:#fff8e1; border:1px solid #ffd54f; border-radius:4px; color:#5d4037; line-height:1.5;">
|
||||
<strong>NHN KCP 휴대폰 본인확인(api_v2)</strong> 사용 시,<br>
|
||||
NHN KCP 상점관리자 > 부가서비스 > 휴대폰본인확인 > 연동방식 설정 에서 <strong>신규 연동방식(V2) 사용여부를 ‘사용’</strong> 으로 변경해야 정상 동작합니다.<br>
|
||||
PHP 7.0 이상 환경에서만 동작하며, PHP 7.0 미만에서는 사용할 수 없습니다.
|
||||
</div>
|
||||
<script>
|
||||
jQuery(function($){
|
||||
function toggle_kcp_v2_notice() {
|
||||
var is_kcp_v2 = $('#cf_cert_hp').val() === 'kcp_v2';
|
||||
$('#cf_cert_hp_kcp_v2_notice').toggle(is_kcp_v2);
|
||||
}
|
||||
|
||||
$('#cf_cert_hp').on('change', toggle_kcp_v2_notice);
|
||||
toggle_kcp_v2_notice();
|
||||
});
|
||||
</script>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
@@ -1061,9 +1121,22 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
|
||||
<tr>
|
||||
<th scope="row" class="cf_cert_service"><label for="cf_cert_kcp_cd">NHN KCP 사이트코드</label></th>
|
||||
<td class="cf_cert_service">
|
||||
<?php
|
||||
$cf_cert_kcp_cd = get_sanitize_input($config['cf_cert_kcp_cd']);
|
||||
if (preg_match('/^SM([A-Z0-9]{3})$/i', $cf_cert_kcp_cd, $matches)) {
|
||||
$cf_cert_kcp_cd = $matches[1];
|
||||
}
|
||||
?>
|
||||
<?php echo help('SM으로 시작하는 5자리 사이트 코드중 뒤의 3자리만 입력해 주십시오.<br>서비스에 가입되어 있지 않다면, 본인확인 서비스 신청페이지에서 서비스 신청 후 사이트코드를 발급 받으실 수 있습니다.') ?>
|
||||
<span class="sitecode">SM</span>
|
||||
<input type="text" name="cf_cert_kcp_cd" value="<?php echo get_sanitize_input($config['cf_cert_kcp_cd']); ?>" id="cf_cert_kcp_cd" class="frm_input" size="3"> <a href="http://sir.kr/main/service/p_cert.php" target="_blank" class="btn_frmline">NHN KCP 휴대폰 본인확인 서비스 신청페이지</a>
|
||||
<span class="sitecode" id="cf_cert_kcp_cd_prefix">SM</span>
|
||||
<input type="text" name="cf_cert_kcp_cd" value="<?php echo $cf_cert_kcp_cd; ?>" id="cf_cert_kcp_cd" class="frm_input" size="3" maxlength="3"> <a href="http://sir.kr/main/service/p_cert.php" target="_blank" class="btn_frmline">NHN KCP 휴대폰 본인확인 서비스 신청페이지</a>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th scope="row" class="cf_cert_service"><label for="cf_cert_kcp_enckey">NHN KCP 가맹점 인증키</label></th>
|
||||
<td class="cf_cert_service">
|
||||
<?php echo help('NHN KCP 상점관리자 > 기술관리센터 > 인증센터 > 가맹점 인증키관리 에서 인증키를 발급받아 입력해 주십시오.<br>NHN KCP 휴대폰 본인확인(api_v2)도 이 인증키 값을 사용합니다.') ?>
|
||||
<input type="text" name="cf_cert_kcp_enckey" value="<?php echo get_sanitize_input($config['cf_cert_kcp_enckey']); ?>" id="cf_cert_kcp_enckey" class="frm_input" maxlength="100" size="70"> <a href="https://partner.kcp.co.kr" target="_blank" class="btn_frmline">NHN KCP 상점관리자</a>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
@@ -1123,6 +1196,7 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
|
||||
<input type="checkbox" name="cf_formmail_is_member" value="1" id="cf_formmail_is_member" <?php echo $config['cf_formmail_is_member'] ? 'checked' : ''; ?>> 회원만 사용
|
||||
</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
</section>
|
||||
@@ -1511,7 +1585,6 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
|
||||
</div>
|
||||
</section>
|
||||
|
||||
|
||||
<section id="anc_cf_extra">
|
||||
<h2 class="h2_frm">여분필드 기본 설정</h2>
|
||||
<?php echo $pg_anchor ?>
|
||||
@@ -1542,7 +1615,17 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
|
||||
</table>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
|
||||
<div id="config_captcha_wrap" style="display:none">
|
||||
<h2>캡챠입력</h2>
|
||||
<?php
|
||||
require_once G5_CAPTCHA_PATH . '/captcha.lib.php';
|
||||
$captcha_html = captcha_html();
|
||||
$captcha_js = chk_captcha_js();
|
||||
echo $captcha_html;
|
||||
?>
|
||||
</div>
|
||||
|
||||
<div class="btn_fixed_top btn_confirm">
|
||||
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
|
||||
</div>
|
||||
@@ -1614,10 +1697,61 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
|
||||
});
|
||||
});
|
||||
|
||||
// 각 요소의 초기값 저장
|
||||
var initialValues = {
|
||||
cf_admin: $('#cf_admin').val(),
|
||||
cf_analytics: $('#cf_analytics').val(),
|
||||
cf_add_meta: $('#cf_add_meta').val(),
|
||||
cf_add_script: $('#cf_add_script').val()
|
||||
};
|
||||
|
||||
function check_config_captcha_open() {
|
||||
var isChanged = false;
|
||||
|
||||
// 현재 값이 있는 경우에만 변경 여부 체크
|
||||
if ($('#cf_admin').val()) {
|
||||
isChanged = isChanged || $('#cf_admin').val() !== initialValues.cf_admin;
|
||||
}
|
||||
if ($('#cf_analytics').val()) {
|
||||
isChanged = isChanged || $('#cf_analytics').val() !== initialValues.cf_analytics;
|
||||
}
|
||||
if ($('#cf_add_meta').val()) {
|
||||
isChanged = isChanged || $('#cf_add_meta').val() !== initialValues.cf_add_meta;
|
||||
}
|
||||
if ($('#cf_add_script').val()) {
|
||||
isChanged = isChanged || $('#cf_add_script').val() !== initialValues.cf_add_script;
|
||||
}
|
||||
|
||||
var $wrap = $("#config_captcha_wrap"),
|
||||
tooptipid = "mp_captcha_tooltip",
|
||||
$p_text = $("<p>", {id:tooptipid, style:"font-size:0.95em;letter-spacing:-0.1em"}).html("중요정보를 수정할 경우 캡챠를 입력해야 합니다."),
|
||||
$children = $wrap.children(':first'),
|
||||
is_invisible_recaptcha = $("#captcha").hasClass("invisible_recaptcha");
|
||||
|
||||
if(isChanged){
|
||||
$wrap.show();
|
||||
if(! is_invisible_recaptcha) {
|
||||
$wrap.css("margin-top","1em");
|
||||
if(! $("#"+tooptipid).length){ $children.after($p_text) }
|
||||
}
|
||||
} else {
|
||||
$wrap.hide();
|
||||
if($("#"+tooptipid).length && ! is_invisible_recaptcha){ $children.next("#"+tooptipid).remove(); }
|
||||
}
|
||||
|
||||
return isChanged;
|
||||
}
|
||||
|
||||
function fconfigform_submit(f) {
|
||||
var current_user_ip = "<?php echo $_SERVER['REMOTE_ADDR']; ?>";
|
||||
var cf_intercept_ip_val = f.cf_intercept_ip.value;
|
||||
|
||||
|
||||
if (check_config_captcha_open()){
|
||||
jQuery("html, body").scrollTop(jQuery("#config_captcha_wrap").offset().top);
|
||||
|
||||
<?php echo $captcha_js; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
|
||||
}
|
||||
|
||||
if (cf_intercept_ip_val && current_user_ip) {
|
||||
var cf_intercept_ips = cf_intercept_ip_val.split("\n");
|
||||
|
||||
@@ -1638,6 +1772,22 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
|
||||
f.action = "./config_form_update.php";
|
||||
return true;
|
||||
}
|
||||
|
||||
jQuery(function($){
|
||||
$("#captcha_key").prop('required', false).removeAttr("required").removeClass("required");
|
||||
|
||||
// 최고관리자 변경시
|
||||
$(document).on('change', '#cf_admin', check_config_captcha_open);
|
||||
|
||||
// 방문자분석 스크립트 변경시
|
||||
$(document).on('input', '#cf_analytics', check_config_captcha_open);
|
||||
|
||||
// 추가 메타태그 변경시
|
||||
$(document).on('input', '#cf_add_meta', check_config_captcha_open);
|
||||
|
||||
// 추가 script, css 변경시
|
||||
$(document).on('input', '#cf_add_script', check_config_captcha_open);
|
||||
});
|
||||
</script>
|
||||
|
||||
<?php
|
||||
@@ -1669,16 +1819,19 @@ if ($config['cf_cert_use']) {
|
||||
|
||||
// kcp일 때
|
||||
if ($config['cf_cert_hp'] == 'kcp') {
|
||||
|
||||
$bin_path = ((int)$config['cf_cert_use'] === 2 && !$config['cf_cert_kcp_enckey']) ? 'bin_old' : 'bin';
|
||||
|
||||
if (strtoupper(substr(PHP_OS, 0, 3)) !== 'WIN') {
|
||||
if (PHP_INT_MAX == 2147483647) { // 32-bit
|
||||
$exe = G5_KCPCERT_PATH . '/bin/ct_cli';
|
||||
$exe = G5_KCPCERT_PATH . '/'.$bin_path.'/ct_cli';
|
||||
} else {
|
||||
$exe = G5_KCPCERT_PATH . '/bin/ct_cli_x64';
|
||||
$exe = G5_KCPCERT_PATH . '/'.$bin_path.'/ct_cli_x64';
|
||||
}
|
||||
} else {
|
||||
$exe = G5_KCPCERT_PATH . '/bin/ct_cli_exe.exe';
|
||||
$exe = G5_KCPCERT_PATH . '/'.$bin_path.'/ct_cli_exe.exe';
|
||||
}
|
||||
|
||||
|
||||
echo module_exec_check($exe, 'ct_cli');
|
||||
}
|
||||
|
||||
|
||||
+48
-12
@@ -10,9 +10,11 @@ if ($is_admin != 'super') {
|
||||
alert('최고관리자만 접근 가능합니다.');
|
||||
}
|
||||
|
||||
$cf_title = isset($_POST['cf_title']) ? strip_tags(clean_xss_attributes($_POST['cf_title'])) : '';
|
||||
$cf_admin = isset($_POST['cf_admin']) ? clean_xss_tags($_POST['cf_admin'], 1, 1) : '';
|
||||
$posts = array();
|
||||
$sql = " select * from {$g5['config_table']} limit 1";
|
||||
$ori_config = sql_fetch($sql);
|
||||
|
||||
$cf_title = isset($_POST['cf_title']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['cf_title'])))) : '';
|
||||
$cf_admin = isset($_POST['cf_admin']) ? safe_replace_regex($_POST['cf_admin']) : '';
|
||||
|
||||
$mb = get_member($cf_admin);
|
||||
|
||||
@@ -24,15 +26,15 @@ check_admin_token();
|
||||
|
||||
$cf_social_servicelist = !empty($_POST['cf_social_servicelist']) ? implode(',', $_POST['cf_social_servicelist']) : '';
|
||||
|
||||
$check_keys = array('cf_cert_kcb_cd', 'cf_cert_kcp_cd', 'cf_editor', 'cf_recaptcha_site_key', 'cf_recaptcha_secret_key', 'cf_naver_clientid', 'cf_naver_secret', 'cf_facebook_appid', 'cf_facebook_secret', 'cf_twitter_key', 'cf_twitter_secret', 'cf_google_clientid', 'cf_google_secret', 'cf_googl_shorturl_apikey', 'cf_kakao_rest_key', 'cf_kakao_client_secret', 'cf_kakao_js_apikey', 'cf_payco_clientid', 'cf_payco_secret', 'cf_cert_kg_cd', 'cf_cert_kg_mid');
|
||||
$check_keys = array('cf_cert_kcb_cd', 'cf_cert_kcp_cd', 'cf_cert_kcp_enckey', 'cf_editor', 'cf_recaptcha_site_key', 'cf_recaptcha_secret_key', 'cf_naver_clientid', 'cf_naver_secret', 'cf_facebook_appid', 'cf_facebook_secret', 'cf_twitter_key', 'cf_twitter_secret', 'cf_google_clientid', 'cf_google_secret', 'cf_googl_shorturl_apikey', 'cf_kakao_rest_key', 'cf_kakao_client_secret', 'cf_kakao_js_apikey', 'cf_payco_clientid', 'cf_payco_secret', 'cf_cert_kg_cd', 'cf_cert_kg_mid');
|
||||
|
||||
foreach ($check_keys as $key) {
|
||||
if (isset($_POST[$key]) && $_POST[$key]) {
|
||||
$posts[$key] = $_POST[$key] = preg_replace('/[^a-z0-9_\-\.]/i', '', $_POST[$key]);
|
||||
$_POST[$key] = preg_replace('/[^a-z0-9_\-\.]/i', '', $_POST[$key]);
|
||||
}
|
||||
}
|
||||
|
||||
$posts['cf_icode_server_port'] = $_POST['cf_icode_server_port'] = isset($_POST['cf_icode_server_port']) ? preg_replace('/[^0-9]/', '', $_POST['cf_icode_server_port']) : '7295';
|
||||
$_POST['cf_icode_server_port'] = isset($_POST['cf_icode_server_port']) ? preg_replace('/[^0-9]/', '', $_POST['cf_icode_server_port']) : '7295';
|
||||
|
||||
if (isset($_POST['cf_intercept_ip']) && $_POST['cf_intercept_ip']) {
|
||||
$pattern = explode("\n", trim($_POST['cf_intercept_ip']));
|
||||
@@ -139,6 +141,7 @@ $check_keys = array(
|
||||
'cf_visit' => 'char',
|
||||
'cf_stipulation' => 'text',
|
||||
'cf_privacy' => 'text',
|
||||
'cf_use_promotion' => 'int',
|
||||
'cf_open_modify' => 'int',
|
||||
'cf_memo_send_point' => 'int',
|
||||
'cf_mobile_new_skin' => 'char',
|
||||
@@ -165,12 +168,12 @@ for ($i = 1; $i <= 10; $i++) {
|
||||
|
||||
foreach ($check_keys as $k => $v) {
|
||||
if ($v === 'int') {
|
||||
$posts[$key] = $_POST[$k] = isset($_POST[$k]) ? (int) $_POST[$k] : 0;
|
||||
$_POST[$k] = isset($_POST[$k]) ? (int) $_POST[$k] : 0;
|
||||
} else {
|
||||
if (in_array($k, array('cf_analytics', 'cf_add_meta', 'cf_add_script', 'cf_stipulation', 'cf_privacy'))) {
|
||||
$posts[$key] = $_POST[$k] = isset($_POST[$k]) ? $_POST[$k] : '';
|
||||
$_POST[$k] = isset($_POST[$k]) ? $_POST[$k] : '';
|
||||
} else {
|
||||
$posts[$key] = $_POST[$k] = isset($_POST[$k]) ? strip_tags(clean_xss_attributes($_POST[$k])) : '';
|
||||
$_POST[$k] = isset($_POST[$k]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$k])))) : '';
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -181,9 +184,36 @@ if ($_POST['cf_cert_use'] && !$_POST['cf_cert_ipin'] && !$_POST['cf_cert_hp'] &&
|
||||
}
|
||||
|
||||
if (!$_POST['cf_cert_use']) {
|
||||
$posts[$key] = $_POST['cf_cert_ipin'] = '';
|
||||
$posts[$key] = $_POST['cf_cert_hp'] = '';
|
||||
$posts[$key] = $_POST['cf_cert_simple'] = '';
|
||||
$_POST['cf_cert_ipin'] = '';
|
||||
$_POST['cf_cert_hp'] = '';
|
||||
$_POST['cf_cert_simple'] = '';
|
||||
}
|
||||
|
||||
// 관리자가 자동등록방지를 사용해야 할 경우 ( 기본환경설정에서 최고관리자, 방문자분석 스크립트, 추가 메타태그, 추가 script, css 변경시 )
|
||||
$check_captcha = 0;
|
||||
|
||||
if ($cf_admin && $ori_config['cf_admin'] !== $cf_admin) {
|
||||
$check_captcha = 1;
|
||||
}
|
||||
|
||||
if ($_POST['cf_analytics'] && $ori_config['cf_analytics'] !== stripslashes($_POST['cf_analytics'])) {
|
||||
$check_captcha = 1;
|
||||
}
|
||||
|
||||
if ($_POST['cf_add_meta'] && $ori_config['cf_add_meta'] !== stripslashes($_POST['cf_add_meta'])) {
|
||||
$check_captcha = 1;
|
||||
}
|
||||
|
||||
if ($_POST['cf_add_script'] && $ori_config['cf_add_script'] !== stripslashes($_POST['cf_add_script'])) {
|
||||
$check_captcha = 1;
|
||||
}
|
||||
|
||||
if ($check_captcha) {
|
||||
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
|
||||
|
||||
if (!chk_captcha()) {
|
||||
alert('자동등록방지 숫자가 틀렸습니다.');
|
||||
}
|
||||
}
|
||||
|
||||
$sql = " update {$g5['config_table']}
|
||||
@@ -271,6 +301,7 @@ $sql = " update {$g5['config_table']}
|
||||
cf_mobile_page_rows = '{$_POST['cf_mobile_page_rows']}',
|
||||
cf_stipulation = '{$_POST['cf_stipulation']}',
|
||||
cf_privacy = '{$_POST['cf_privacy']}',
|
||||
cf_use_promotion = '{$_POST['cf_use_promotion']}',
|
||||
cf_open_modify = '{$_POST['cf_open_modify']}',
|
||||
cf_memo_send_point = '{$_POST['cf_memo_send_point']}',
|
||||
cf_mobile_new_skin = '{$_POST['cf_mobile_new_skin']}',
|
||||
@@ -290,6 +321,7 @@ $sql = " update {$g5['config_table']}
|
||||
cf_cert_kg_mid = '" . trim($_POST['cf_cert_kg_mid']) . "',
|
||||
cf_cert_kcb_cd = '{$_POST['cf_cert_kcb_cd']}',
|
||||
cf_cert_kcp_cd = '{$_POST['cf_cert_kcp_cd']}',
|
||||
cf_cert_kcp_enckey = '{$_POST['cf_cert_kcp_enckey']}',
|
||||
cf_cert_limit = '{$_POST['cf_cert_limit']}',
|
||||
cf_cert_req = '{$_POST['cf_cert_req']}',
|
||||
cf_sms_use = '{$_POST['cf_sms_use']}',
|
||||
@@ -346,6 +378,10 @@ if (isset($_POST['cf_bbs_rewrite'])) {
|
||||
g5_delete_all_cache();
|
||||
}
|
||||
|
||||
if (function_exists('get_admin_captcha_by')) {
|
||||
get_admin_captcha_by('remove');
|
||||
}
|
||||
|
||||
run_event('admin_config_form_update');
|
||||
|
||||
update_rewrite_rules();
|
||||
|
||||
@@ -26,17 +26,28 @@ if ($w == "" || $w == "u") {
|
||||
}
|
||||
|
||||
$co_id = isset($_REQUEST['co_id']) ? preg_replace('/[^a-z0-9_]/i', '', $_REQUEST['co_id']) : '';
|
||||
$co_subject = isset($_POST['co_subject']) ? strip_tags(clean_xss_attributes($_POST['co_subject'])) : '';
|
||||
$co_subject = isset($_POST['co_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['co_subject'])))) : '';
|
||||
$co_include_head = isset($_POST['co_include_head']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_head'], 0, 255)) : '';
|
||||
$co_include_tail = isset($_POST['co_include_tail']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_tail'], 0, 255)) : '';
|
||||
|
||||
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
|
||||
if ($is_admin !== 'super') {
|
||||
if ($w == 'u') {
|
||||
$co_include_head = isset($co_row['co_include_head']) ? $co_row['co_include_head'] : '';
|
||||
$co_include_tail = isset($co_row['co_include_tail']) ? $co_row['co_include_tail'] : '';
|
||||
} else {
|
||||
$co_include_head = '';
|
||||
$co_include_tail = '';
|
||||
}
|
||||
}
|
||||
$co_tag_filter_use = isset($_POST['co_tag_filter_use']) ? (int) $_POST['co_tag_filter_use'] : 1;
|
||||
$co_himg_del = (isset($_POST['co_himg_del']) && $_POST['co_himg_del']) ? 1 : 0;
|
||||
$co_timg_del = (isset($_POST['co_timg_del']) && $_POST['co_timg_del']) ? 1 : 0;
|
||||
$co_html = isset($_POST['co_html']) ? (int) $_POST['co_html'] : 0;
|
||||
$co_content = isset($_POST['co_content']) ? $_POST['co_content'] : '';
|
||||
$co_mobile_content = isset($_POST['co_mobile_content']) ? $_POST['co_mobile_content'] : '';
|
||||
$co_skin = isset($_POST['co_skin']) ? clean_xss_tags($_POST['co_skin'], 1, 1) : '';
|
||||
$co_mobile_skin = isset($_POST['co_mobile_skin']) ? clean_xss_tags($_POST['co_mobile_skin'], 1, 1) : '';
|
||||
$co_skin = isset($_POST['co_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['co_skin']), 1, 1)) : '';
|
||||
$co_mobile_skin = isset($_POST['co_mobile_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['co_mobile_skin']), 1, 1)) : '';
|
||||
|
||||
// 관리자가 자동등록방지를 사용해야 할 경우
|
||||
if (((isset($co_row['co_include_head']) && $co_row['co_include_head'] !== $co_include_head) || (isset($co_row['co_include_tail']) && $co_row['co_include_tail'] !== $co_include_tail)) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
|
||||
|
||||
+98
-12
@@ -28,6 +28,39 @@ box-sizing: border-box;
|
||||
h2{font-size: 1.083em;font-weight: bold;margin:10px 0}
|
||||
|
||||
#wrapper {min-height:480px}
|
||||
|
||||
/* admin 공통 */
|
||||
/* 공통 - display none/block */
|
||||
.is-hidden { display: none !important; }
|
||||
.is-visible { display: block !important; }
|
||||
|
||||
/* 공통 - 뷰포트 (pc / mobile) 별 display none/block */
|
||||
.pc-only { display: none; }
|
||||
@media (min-width: 769px) { .pc-only { display: block !important; }}
|
||||
.mobile-only { display: block; }
|
||||
@media (min-width: 769px) { .mobile-only { display: none !important; }}
|
||||
|
||||
/* 공통 - 레이어 팝업 */
|
||||
.popup-overlay { position: fixed; top: 0; left: 0; width: 100%; height: 100%; background: rgba(0,0,0,0.3); backdrop-filter: blur(6px); -webkit-backdrop-filter: blur(6px); z-index: 9999; display: flex; justify-content: center; align-items: center; }
|
||||
.popup-content { background: #fff; border-radius: 10px; box-shadow: 0 8px 24px rgba(0,0,0,0.15); width: 800px; overflow: hidden; }
|
||||
.popup-header, .popup-footer { padding: 18px 20px; display: flex; align-items: center; }
|
||||
.popup-header { justify-content: space-between; border-bottom: 1px solid #e0e0e0; }
|
||||
.popup-footer { gap: 20px; border-top: 1px solid #e0e0e0;}
|
||||
.popup-close-btn { background: none; border: none; color: #888; font-size: 20px; cursor: pointer; padding: 4px; display: flex; align-items: center; justify-content: center; transition: color 0.2s ease; }
|
||||
.popup-close-btn:hover { color: #333; }
|
||||
.popup-title { font-size: 18px; font-weight: 600; }
|
||||
.popup-body { padding: 20px; max-height: 400px; overflow-y: auto; color: #333; }
|
||||
.popup-footer button { background: #3d70ff; color: white; border: 1px solid #3d70ff; padding: 8px 16px; border-radius: 6px; font-weight: 600; cursor: pointer; transition: background 0.2s ease, border-color 0.2s ease; }
|
||||
.popup-footer button:hover { background: #2b3d9f; border-color: #2b3d9f; }
|
||||
|
||||
/* 공통 - tab */
|
||||
.tab-container { display: flex; flex-direction: column; width: 100%; }
|
||||
.tab-header { position: relative; bottom: -1px; display: flex; }
|
||||
.tab-btn { padding: 10px 14px; background: none; border: none; border-bottom: 2px solid transparent; cursor: pointer; color: inherit; font: inherit; }
|
||||
.tab-btn.active { border-bottom-color: #000; font-weight: bold; }
|
||||
.tab-body { width: 100%; border-top: 1px solid #ccc; }
|
||||
.tab-content { padding: 16px 0; }
|
||||
|
||||
/* 레이아웃 */
|
||||
#hd h1 {position:absolute;font-size:0;line-height:0;overflow:hidden}
|
||||
#hd_top{position:fixed;top:0;left:0;width:100%;height:50px;background:#3f51b5;z-index:1000}
|
||||
@@ -95,9 +128,11 @@ box-shadow: 2px 0 2px rgba(150,150,150,0.1);}
|
||||
#container.container-small #container_title{padding-left:70px}
|
||||
.container_wr{padding:20px}
|
||||
|
||||
/* 화면낭독기 사용자용 */
|
||||
/* 화면낭독기 사용자용 (스크린 리더 대응) */
|
||||
/* 일반적인 .blind/.sr-only 사용시에 .sound_only 사용 권장 */
|
||||
#hd_login_msg {position:absolute;top:0;left:0;width:1px;height:1px;overflow:hidden}
|
||||
.msg_sound_only, .sound_only {display:inline-block !important;position:absolute;top:0;left:0;margin:0 !important;padding:0 !important;width:1px !important;height:1px !important;font-size:0;line-height:0;border:0 !important;overflow:hidden !important}
|
||||
.sound_only, .msg_sound_only {overflow:hidden;position:absolute;width:1px;height:1px;margin:-1px;padding:0;clip:rect(0,0,0,0)}
|
||||
|
||||
/* 본문 바로가기 */
|
||||
#to_content a {z-index:100000;position:absolute;top:0;left:0;font-size:0;line-height:0;overflow:hidden}
|
||||
#to_content a:focus, #to_content a:active {width:100%;height:70px;background:#fff;font-size:2em;font-weight:bold;text-align:center;text-decoration:none;line-height:3.1em}
|
||||
@@ -247,18 +282,14 @@ legend {position:absolute;width:0;height:0;font-size:0;line-height:0;text-indent
|
||||
.anchor a {display:inline-block;padding:5px 10px;border:1px solid #c8ced1;background:#d6dde1;text-decoration:none}
|
||||
.anchor .selected{background:#3f51b5}
|
||||
|
||||
|
||||
|
||||
|
||||
#sort_mb {width:800px}
|
||||
|
||||
#sort_sodr {width:600px}
|
||||
|
||||
|
||||
/* 하단 레이아웃 */
|
||||
#ft{background:#f3f3f3;padding:0 25px;color:#777;text-align:center}
|
||||
#ft p{line-height:50px;}
|
||||
.scroll_top{position:fixed;bottom:10px;right:10px;width:50px;height:50px;border:0;text-align:center;background:#ddd;background:rgba(0,0,0,0.1)}
|
||||
.scroll_top{position:fixed;bottom:10px;right:10px;width:50px;height:50px;border:0;text-align:center;background:#ddd;background:rgba(0,0,0,0.1);z-index:50;}
|
||||
.scroll_top span.top_img{display:inline-block;width: 0; height: 0; border-left: 5px solid transparent;border-right: 5px solid transparent;
|
||||
border-bottom: 5px solid black;}
|
||||
.scroll_top span.top_txt{display:block}
|
||||
@@ -281,9 +312,59 @@ border-bottom: 5px solid black;}
|
||||
.local_sch03 button{height:30px;padding:0 5px;border:0;background:#9eacc6;color:#fff;}
|
||||
.local_sch03 .btn_submit{height:30px;padding:0 5px;border:0;color:#fff;}
|
||||
.local_sch03 .frm_input{height:30px;border:1px solid #dcdcdc;padding:0 5px;}
|
||||
|
||||
/* 회원 관리 데이터 필터링 */
|
||||
.member_list_data { display: flex; flex-direction: column; padding: 20px; margin: 20px 0 40px; background: #f9f9f9; border: 1px solid #f2f2f2; color: #333; }
|
||||
.sch_table { display: flex; flex-direction: column; gap: 10px; font-size: 11.5px; color: #333; }
|
||||
.member_list_data .sch_row { display: flex; align-items: center; gap: 12px; min-height: 30px; }
|
||||
.label { min-width: 120px; font-weight: 500; white-space: nowrap; display: flex; align-items: center; }
|
||||
.label label {display: flex; gap: 10px;}
|
||||
.field { flex: 1; display: flex; flex-wrap: wrap; align-items: center; gap: 8px; }
|
||||
.field input[type="text"], .field input[type="number"], .field input[type="date"], .field select { height: 30px; min-width: 100px; padding: 0 10px; font-size: 11.5px; border: 1px solid #ddd; border-radius: 8px; background: #fff; transition: border-color 0.2s ease, box-shadow 0.2s ease; }
|
||||
.field input[type="text"]:focus, .field input[type="number"]:focus, .field input[type="date"]:focus, .field select:focus { border-color: #6f809a; box-shadow: 0 0 0 2px rgba(63,81,181,0.1); outline: none; }
|
||||
.field input::placeholder { color: #aaa; }
|
||||
.field input[type="checkbox"], .field input[type="radio"] { width: 14px; height: 14px; accent-color: #536177; }
|
||||
.radio_group { display: flex; gap: 15px; align-items: center; padding: 0 10px;}
|
||||
.radio_group label {display: flex; align-items: center; gap: 5px;}
|
||||
.ad_range_wrap {flex: 1; padding-left: 20px;}
|
||||
.ad_range_box {display: flex;}
|
||||
.ad_range_box .label {width: 109px;}
|
||||
.sch_notice { font-size: 11px; color: #999; }
|
||||
.sch_btn { display: flex; gap: 20px; justify-content: center; margin-top: 40px; }
|
||||
.sch_btn { display: flex; gap: 10px; }
|
||||
|
||||
.btn_reset { display: flex; align-items: center; gap: 6px; padding: 0 20px; height: 40px; background: #9eacc6; color: #fff; font-weight: 600; border: none; border-radius: 8px; cursor: pointer; transition: background 0.2s ease, transform 0.15s ease; }
|
||||
.btn_reset:hover { background: #5f6e89; }
|
||||
.sch_btn button:not(.btn_reset) { padding: 0 20px; height: 40px; border: 1px solid #ccd1d8; background-color: #fff; color: #444; font-weight: 600; border-radius: 8px; cursor: pointer; user-select: none; transition: border-color 0.2s ease, box-shadow 0.2s ease; box-shadow: 0 1px 2px rgba(0,0,0,0.03); }
|
||||
.sch_btn button:not(.btn_reset):hover { border-color: #6f809a; box-shadow: 0 2px 4px rgba(111, 128, 154, 0.15); }
|
||||
.sch_btn button:not(.btn_reset):active { box-shadow: inset 0 1px 2px rgba(0,0,0,0.1); }
|
||||
|
||||
/* 회원 관리 다운로드 진행 팝업 */
|
||||
.excel-download-progress p { color: #374151; }
|
||||
.excel-download-progress .progress-desc { padding: 40px 0 32px; text-align: center; }
|
||||
.excel-download-progress .progress-summary { margin-bottom: 6px; font-size: 16px; font-weight: 500; color: #111827; }
|
||||
.excel-download-progress .progress-message { font-size: 20px; font-weight: 600; color: #3b82f6; }
|
||||
.excel-download-progress .progress-error { color:red; }
|
||||
.progress-spinner { display: flex; flex-direction: column; align-items: center; gap: 45px; padding: 24px 0; transition: all 0.2s ease; }
|
||||
.spinner { width: 48px; height: 48px; border: 5px solid #3b82f6; border-top: 5px solid #fff; border-radius: 50%; animation: spin 0.8s linear infinite; }
|
||||
@keyframes spin { to { transform: rotate(360deg); } }
|
||||
.loading-message { text-align: center; font-size: 14px; color: #374151; }
|
||||
.excel-download-progress .progress-download-box { margin-top: 24px; background: #f9fafb; padding: 20px; border-radius: 8px; box-shadow: 0 1px 2px rgba(0,0,0,0.03); }
|
||||
.excel-download-progress .progress-download-box a { display: block; width: 100%; height: auto; text-align: center; margin-top: 8px; font-weight: 600; font-size: 14px; padding: 10px 20px; background: #fff; border: 1px solid #ccd1d8; border-radius: 8px; color: #444; cursor: pointer; transition: border-color 0.2s ease, box-shadow 0.2s ease; box-shadow: 0 1px 2px rgba(0,0,0,0.03); }
|
||||
.excel-download-progress .progress-download-box a:hover { border-color: #6f809a; box-shadow: 0 2px 4px rgba(111, 128, 154, 0.15); }
|
||||
.excel-download-progress .progress-download-box a:active { box-shadow: inset 0 1px 2px rgba(0,0,0,0.1); }
|
||||
|
||||
.field-select-form { display: grid; grid-template-columns: repeat(2, minmax(0, 1fr)); margin-top: 15px; gap: 0px 10px; padding: 10px; background-color: #f9fafb; border: 1px solid #e5e7eb; border-radius: 8px; color: #374151; }
|
||||
.field-select-form label { display: flex; align-items: center; cursor: pointer; padding: 6px 10px; border-radius: 4px; }
|
||||
.field-select-form label:hover { background-color: #f3f4f6; }
|
||||
.field-select-form input[type="checkbox"] { margin-right: 8px; transform: scale(1.2); }
|
||||
.field-separator { grid-column: 1 / -1; border-top: 1px solid #d1d5db; margin: 8px 0; }
|
||||
.selected-fields-preview { padding: 8px; background-color: #eef2f7; border: 1px solid #d1d5db; border-radius: 6px; margin: 10px 0px; color: #1f2937; display: flex; align-items: center; flex-wrap: wrap; gap: 8px; }
|
||||
.selected-fields-preview strong { padding: 4px 8px; }
|
||||
.selected-fields-preview .field-tag { background-color: #dbeafe; color: #1e40af; padding: 4px 8px; border-radius: 4px; }
|
||||
|
||||
/* 페이지 내 실행 */
|
||||
.local_cmd {min-width:960px}
|
||||
|
||||
.local_cmd01 {margin:0 0 10px;padding:0 }
|
||||
.local_cmd01 .cmd_tit {font-weight:bold}
|
||||
.local_cmd01 .btn_submit {padding:3px 5px;border:1px solid #ff3061;color:#fff;font-size:0.95em;vertical-align:middle}
|
||||
@@ -298,7 +379,7 @@ border-bottom: 5px solid black;}
|
||||
|
||||
.local_desc01 {margin:10px 0 10px ;padding:10px 20px;border:1px solid #f2f2f2;background:#f9f9f9}
|
||||
.local_desc01 strong {color:#ff3061}
|
||||
.local_desc01 a {text-decoration:underline}
|
||||
.local_desc01 a {text-decoration:underline;text-underline-offset:2px;}
|
||||
|
||||
.local_desc02 {margin:10px 0 ;min-width:960px} /* 주로 온라인 서식 관련 안내 내용에 사용 */
|
||||
.local_desc02 p {padding:0;line-height:1.8em}
|
||||
@@ -401,6 +482,7 @@ tfoot th {}
|
||||
.mb_leave_msg {color:#b6b6b6}
|
||||
.mb_intercept_msg {color:#ff0000}
|
||||
#point_mng {margin-top:50px}
|
||||
.ad_agree_log {max-height: 150px !important;}
|
||||
|
||||
/* 게시판추가/수정 */
|
||||
#anc_bo_extra .td_grpset label {width:auto}
|
||||
@@ -504,6 +586,7 @@ td.td_grpset {width:160px;border-left:1px solid #e9ecee;text-align:center}
|
||||
.td_time{text-align:center;width:130px}
|
||||
.td_center{text-align:center;}
|
||||
.td_type{width:120px}
|
||||
.td_consent{min-width:70px;max-width:200px}
|
||||
|
||||
.td_mng_s{width:60px}
|
||||
.td_mng_m{width:100px}
|
||||
@@ -624,6 +707,7 @@ a.lg_btn{display:inline-block;margin:5px 0 0;padding:5px 10px;background:#ED008C
|
||||
a.kg_btn{display:inline-block;margin:5px 0 0;padding:5px 10px;background:#4A2C7C;color:#fff;font-weight:normal;text-decoration:none}
|
||||
a.kakao_btn{display:inline-block;margin:5px 0 0;padding:5px 10px;background:#FDDC2F;color:#3B1E1E;font-weight:normal;text-decoration:none}
|
||||
a.naver_btn {display:inline-block;margin:5px 0 0;padding:5px 10px;background:#00C73C;color:#fff;font-weight:normal;text-decoration:none}
|
||||
a.nicepay_btn{display:inline-block;margin:5px 0 0;padding:5px 10px;background:#0057bf;color:#fff;font-weight:normal;text-decoration:none}
|
||||
|
||||
.scf_cardtest {margin:5px 0 0}
|
||||
.scf_cardtest_btn {margin-left:5px;vertical-align:middle}
|
||||
@@ -655,17 +739,19 @@ a.naver_btn {display:inline-block;margin:5px 0 0;padding:5px 10px;background:#00
|
||||
|
||||
ul.de_pg_tab{margin:0;padding:0;zoom:1}
|
||||
ul.de_pg_tab:after{display:block;visibility:hidden;clear:both;content:"";}
|
||||
ul.de_pg_tab li{position:relative;display:inline-block;float:left;text-align:center;margin:0;padding:0;width:120px}
|
||||
ul.de_pg_tab li a{margin:0 2px;display:block;overflow:hidden;text-overflow:ellipsis;white-space:nowrap;line-height:2.5;background-color:#f7f7f7;color:#74777b;font-weight:bold;font-size:1.2em;text-decoration:none}
|
||||
ul.de_pg_tab li{position:relative;display:inline-block;float:left;text-align:center;margin:0;padding:0;min-width:130px}
|
||||
ul.de_pg_tab li a{margin:0 2px;display:block;overflow:hidden;text-overflow:ellipsis;white-space:nowrap;line-height:2.5;background-color:#f7f7f7;color:#74777b;font-weight:bold;font-size:1.2em;text-decoration:none; padding:0px 10px;}
|
||||
ul.de_pg_tab li a:hover{text-decoration:none}
|
||||
ul.de_pg_tab li.tab-current a{background:#2CC185;color:#fff}
|
||||
|
||||
.pg_info_fld{position:relative}
|
||||
.kcp_info_fld th{background-color:#F6FCFF}
|
||||
.lg_info_fld th{background-color:#FFF4FA}
|
||||
.lg_info_fld_v2 th{background-color:#ffe8f5}
|
||||
.inicis_info_fld th{background-color:#F6F1FF}
|
||||
.kakao_info_fld th{background-color:#FFFCED}
|
||||
.naver_info_fld th{background-color:#F3FFF3}
|
||||
.nicepay_info_fld th{background-color:#d1e6ff}
|
||||
|
||||
/* 주문내역 */
|
||||
#sodr_list td {text-align:center}
|
||||
@@ -1131,4 +1217,4 @@ input[type="text"]{max-width:200px}
|
||||
@media only screen and (max-device-width : 480px) and (orientation : portrait){
|
||||
/* Styles */
|
||||
input[type="text"]{max-width:200px}
|
||||
}
|
||||
}
|
||||
@@ -269,6 +269,111 @@ while ($row = sql_fetch_array($result)){
|
||||
}
|
||||
}
|
||||
|
||||
// SMS5 테이블 G5_TABLE_PREFIX 적용
|
||||
if($g5['sms5_prefix'] != 'sms5_' && sql_num_rows(sql_query("show tables like 'sms5_config'")))
|
||||
{
|
||||
$tables = array('config','write','history','book','book_group','form','form_group');
|
||||
|
||||
foreach($tables as $name){
|
||||
$old_table = 'sms5_' . $name;
|
||||
$new_table = $g5['sms5_prefix'] . $name;
|
||||
|
||||
// 기존 테이블이 있고, G5_TABLE_PREFIX 적용 테이블이 없을 경우 → 테이블명 변경
|
||||
if(sql_num_rows(sql_query("SHOW TABLES LIKE '{$old_table}' "))){
|
||||
if(!sql_num_rows(sql_query("SHOW TABLES LIKE '{$new_table}' "))){
|
||||
sql_query("RENAME TABLE {$old_table} TO {$new_table}", false);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
$is_check = true;
|
||||
}
|
||||
|
||||
// 광고성 정보 수신 동의 사용 필드 추가
|
||||
if (!isset($config['cf_use_promotion'])) {
|
||||
sql_query(
|
||||
" ALTER TABLE `{$g5['config_table']}`
|
||||
ADD `cf_use_promotion` tinyint(1) NOT NULL DEFAULT '0' AFTER `cf_privacy` ",
|
||||
true
|
||||
);
|
||||
|
||||
$is_check = true;
|
||||
}
|
||||
|
||||
// 광고성 정보 수신 동의 여부 필드 추가 + 메일 / SMS 수신 일자 추가
|
||||
if (!isset($member['mb_marketing_agree'])) {
|
||||
sql_query(
|
||||
" ALTER TABLE `{$g5['member_table']}`
|
||||
ADD `mb_marketing_agree` tinyint(1) NOT NULL DEFAULT '0' AFTER `mb_scrap_cnt`,
|
||||
ADD `mb_marketing_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_marketing_agree`,
|
||||
ADD `mb_thirdparty_agree` tinyint(1) NOT NULL DEFAULT '0' AFTER `mb_marketing_date`,
|
||||
ADD `mb_thirdparty_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_thirdparty_agree`,
|
||||
ADD `mb_agree_log` TEXT NOT NULL AFTER `mb_thirdparty_date`,
|
||||
ADD `mb_mailling_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_mailling`,
|
||||
ADD `mb_sms_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_sms` ",
|
||||
true
|
||||
);
|
||||
|
||||
$is_check = true;
|
||||
}
|
||||
|
||||
// 쿠폰 로그 테이블에 UNIQUE 인덱스 추가 (쿠폰 이중사용 방지)
|
||||
if (defined('G5_USE_SHOP') && G5_USE_SHOP) {
|
||||
$result = sql_query("SHOW INDEX FROM `{$g5['g5_shop_coupon_log_table']}` WHERE Key_name = 'idx_coupon_use'", false);
|
||||
if (!$result || !sql_num_rows($result)) {
|
||||
// 기존에 동일 쿠폰이 중복 사용된 데이터가 있으면 UNIQUE 인덱스 생성 실패하므로 중복 데이터 정리
|
||||
$dup_sql = " SELECT cp_id, mb_id, MIN(cl_id) as keep_id
|
||||
FROM `{$g5['g5_shop_coupon_log_table']}`
|
||||
GROUP BY cp_id, mb_id
|
||||
HAVING COUNT(*) > 1 ";
|
||||
|
||||
$dup_result = sql_query($dup_sql, false);
|
||||
if ($dup_result && sql_num_rows($dup_result)) {
|
||||
while ($dup_row = sql_fetch_array($dup_result)) {
|
||||
|
||||
echo $dup_row['cp_id']." 의 동일 쿠폰이 중복 사용된 데이터가 있으므로 인덱스 생성이 불가합니다. <br>";
|
||||
|
||||
$sql = " DELETE FROM `{$g5['g5_shop_coupon_log_table']}`
|
||||
WHERE cp_id = '{$dup_row['cp_id']}'
|
||||
AND mb_id = '{$dup_row['mb_id']}'
|
||||
AND cl_id != '{$dup_row['keep_id']}' ";
|
||||
if ($is_admin === 'super') {
|
||||
echo "데이터베이스에서 검토후에 이 쿼리문을 실행해 주세요.<br>$sql<br>";
|
||||
}
|
||||
// sql_query($sql);
|
||||
}
|
||||
}
|
||||
|
||||
// MyISAM + utf8mb4 환경에서 키 길이 초과 방지: cp_id varchar(100), mb_id varchar(100)으로 조정
|
||||
sql_query("ALTER TABLE `{$g5['g5_shop_coupon_log_table']}` MODIFY `cp_id` varchar(100) NOT NULL DEFAULT '', MODIFY `mb_id` varchar(100) NOT NULL DEFAULT ''", false);
|
||||
sql_query("ALTER TABLE `{$g5['g5_shop_coupon_log_table']}` ADD UNIQUE KEY `idx_coupon_use` (`cp_id`, `mb_id`)", false);
|
||||
$is_check = true;
|
||||
}
|
||||
}
|
||||
|
||||
// 자동 로그인 토큰 테이블 생성 (KVE-2026-0610: 추측 가능한 자동 로그인 쿠키 위조 방지)
|
||||
// 다중 디바이스 지원을 위해 회원당 여러 토큰을 별도 테이블로 관리
|
||||
if (!isset($g5['member_auto_login_table'])) {
|
||||
$g5['member_auto_login_table'] = G5_TABLE_PREFIX.'member_auto_login';
|
||||
}
|
||||
if (!sql_query(" DESC `{$g5['member_auto_login_table']}` ", false)) {
|
||||
sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['member_auto_login_table']}` (
|
||||
`al_id` int(11) NOT NULL auto_increment,
|
||||
`mb_id` varchar(20) NOT NULL default '',
|
||||
`al_token` varchar(64) NOT NULL default '',
|
||||
`al_user_agent` varchar(255) NOT NULL default '',
|
||||
`al_ip` varchar(45) NOT NULL default '',
|
||||
`al_created` datetime DEFAULT NULL,
|
||||
`al_last_used` datetime DEFAULT NULL,
|
||||
`al_expire` datetime DEFAULT NULL,
|
||||
PRIMARY KEY (`al_id`),
|
||||
UNIQUE KEY `al_token` (`al_token`),
|
||||
KEY `mb_id` (`mb_id`),
|
||||
KEY `al_expire` (`al_expire`)
|
||||
) ENGINE=MyISAM DEFAULT CHARSET=utf8 ", true);
|
||||
$is_check = true;
|
||||
}
|
||||
|
||||
$is_check = run_replace('admin_dbupgrade', $is_check);
|
||||
|
||||
$db_upgrade_msg = $is_check ? 'DB 업그레이드가 완료되었습니다.' : '더 이상 업그레이드 할 내용이 없습니다.<br>현재 DB 업그레이드가 완료된 상태입니다.';
|
||||
|
||||
@@ -20,7 +20,7 @@ check_admin_token();
|
||||
$fm_id = isset($_REQUEST['fm_id']) ? (int) $_REQUEST['fm_id'] : 0;
|
||||
$fm_himg_del = isset($_POST['fm_himg_del']) ? (int) $_POST['fm_himg_del'] : 0;
|
||||
$fm_timg_del = isset($_POST['fm_timg_del']) ? (int) $_POST['fm_timg_del'] : 0;
|
||||
$fm_subject = isset($_POST['fm_subject']) ? strip_tags(clean_xss_attributes($_POST['fm_subject'])) : '';
|
||||
$fm_subject = isset($_POST['fm_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['fm_subject'])))) : '';
|
||||
$fm_head_html = isset($_POST['fm_head_html']) ? $_POST['fm_head_html'] : '';
|
||||
$fm_tail_html = isset($_POST['fm_tail_html']) ? $_POST['fm_tail_html'] : '';
|
||||
$fm_mobile_head_html = isset($_POST['fm_mobile_head_html']) ? $_POST['fm_mobile_head_html'] : '';
|
||||
|
||||
+13
-4
@@ -35,6 +35,10 @@ if (!auth_check_menu($auth, '200100', 'r', true)) {
|
||||
$sod = "desc";
|
||||
}
|
||||
|
||||
$allowed_sst = array('mb_datetime');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'mb_datetime';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
|
||||
@@ -284,14 +288,19 @@ if (!auth_check_menu($auth, '200200', 'r', true)) {
|
||||
</thead>
|
||||
<tbody>
|
||||
<?php
|
||||
$row2['mb_id'] = '';
|
||||
$row2 = array('mb_id'=>'');
|
||||
for ($i = 0; $row = sql_fetch_array($result); $i++) {
|
||||
if ($row2['mb_id'] != $row['mb_id']) {
|
||||
if (empty($row2) || $row2['mb_id'] != $row['mb_id']) {
|
||||
$sql2 = " SELECT mb_id, mb_name, mb_nick, mb_email, mb_homepage, mb_point from {$g5['member_table']} where mb_id = '{$row['mb_id']}' ";
|
||||
$row2 = sql_fetch($sql2);
|
||||
}
|
||||
|
||||
$mb_nick = get_sideview($row['mb_id'], $row2['mb_nick'], $row2['mb_email'], $row2['mb_homepage']);
|
||||
$mb_nick = get_sideview(
|
||||
$row['mb_id'],
|
||||
isset($row2['mb_nick']) ? $row2['mb_nick'] : '',
|
||||
isset($row2['mb_email']) ? $row2['mb_email'] : '',
|
||||
isset($row2['mb_homepage']) ? $row2['mb_homepage'] : ''
|
||||
);
|
||||
|
||||
$link1 = $link2 = "";
|
||||
if (!preg_match("/^\@/", $row['po_rel_table']) && $row['po_rel_table']) {
|
||||
@@ -302,7 +311,7 @@ if (!auth_check_menu($auth, '200200', 'r', true)) {
|
||||
|
||||
<tr>
|
||||
<td class="td_mbid"><a href="./point_list.php?sfl=mb_id&stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
|
||||
<td class="td_mbname"><?php echo get_text($row2['mb_name']); ?></td>
|
||||
<td class="td_mbname"><?php echo isset($row2['mb_name']) ? get_text($row2['mb_name']) : ''; ?></td>
|
||||
<td class="td_name sv_use">
|
||||
<div><?php echo $mb_nick ?></div>
|
||||
</td>
|
||||
|
||||
@@ -80,7 +80,7 @@ require_once './admin.head.php';
|
||||
<tr>
|
||||
<th scope="row"><label for="mb_email">E-mail</label></th>
|
||||
<td>
|
||||
<?php echo help("메일 주소에 단어 포함 (예 : @" . preg_replace('#^(www[^\.]*\.){1}#', '', $_SERVER['HTTP_HOST']) . ")") ?>
|
||||
<?php echo help("메일 주소에 단어 포함 (예 : @" . htmlspecialchars(preg_replace('#^(www[^\.]*\.){1}#', '', $_SERVER['HTTP_HOST'])) . ")") ?>
|
||||
<input type="text" name="mb_email" value="<?php echo get_sanitize_input($mb_email); ?>" id="mb_email" class="frm_input" size="50">
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
@@ -12,10 +12,10 @@ $sql_common = " from {$g5['member_table']} ";
|
||||
$sql_where = " where (1) ";
|
||||
|
||||
$mb_id1 = isset($_POST['mb_id1']) ? (int) $_POST['mb_id1'] : 1;
|
||||
$mb_id1_from = isset($_POST['mb_id1_from']) ? clean_xss_tags($_POST['mb_id1_from'], 1, 1, 30) : '';
|
||||
$mb_id1_to = isset($_POST['mb_id1_to']) ? clean_xss_tags($_POST['mb_id1_to'], 1, 1, 30) : '';
|
||||
$mb_email = isset($_POST['mb_email']) ? clean_xss_tags($_POST['mb_email'], 1, 1, 100) : '';
|
||||
$mb_mailling = isset($_POST['mb_mailling']) ? clean_xss_tags($_POST['mb_mailling'], 1, 1, 100) : '';
|
||||
$mb_id1_from = isset($_POST['mb_id1_from']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_id1_from']), 1, 1, 30)) : '';
|
||||
$mb_id1_to = isset($_POST['mb_id1_to']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_id1_to']), 1, 1, 30)) : '';
|
||||
$mb_email = isset($_POST['mb_email']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_email']), 1, 1, 100)) : '';
|
||||
$mb_mailling = isset($_POST['mb_mailling']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_mailling']), 1, 1, 100)) : '';
|
||||
$mb_level_from = isset($_POST['mb_level_from'])? (int) $_POST['mb_level_from'] : 1;
|
||||
$mb_level_to = isset($_POST['mb_level_to']) ? (int) $_POST['mb_level_to'] : 10;
|
||||
|
||||
|
||||
+1
-1
@@ -11,7 +11,7 @@ auth_check_menu($auth, $sub_menu, 'w');
|
||||
check_admin_token();
|
||||
|
||||
$ma_id = isset($_POST['ma_id']) ? (int) $_POST['ma_id'] : 0;
|
||||
$ma_subject = isset($_POST['ma_subject']) ? strip_tags(clean_xss_attributes($_POST['ma_subject'])) : '';
|
||||
$ma_subject = isset($_POST['ma_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['ma_subject'])))) : '';
|
||||
$ma_content = isset($_POST['ma_content']) ? $_POST['ma_content'] : '';
|
||||
|
||||
if ($w == '') {
|
||||
|
||||
+65
-8
@@ -52,8 +52,11 @@ if ($w == '') {
|
||||
$sound_only = '<strong class="sound_only">필수</strong>';
|
||||
|
||||
$mb['mb_mailling'] = 1;
|
||||
$mb['mb_sms'] = 1;
|
||||
$mb['mb_open'] = 1;
|
||||
$mb['mb_level'] = $config['cf_register_level'];
|
||||
$mb['mb_marketing_agree'] = 0;
|
||||
$mb['mb_thirdparty_agree'] = 0;
|
||||
$html_title = '추가';
|
||||
} elseif ($w == 'u') {
|
||||
$mb = get_member($mb_id);
|
||||
@@ -139,6 +142,14 @@ $mb_sms_no = !$mb['mb_sms'] ? 'checked="checked"' : '';
|
||||
$mb_open_yes = $mb['mb_open'] ? 'checked="checked"' : '';
|
||||
$mb_open_no = !$mb['mb_open'] ? 'checked="checked"' : '';
|
||||
|
||||
// 마케팅 목적의 개인정보 수집 및 이용
|
||||
$mb_marketing_agree_yes = $mb['mb_marketing_agree'] ? 'checked="checked"' : '';
|
||||
$mb_marketing_agree_no = !$mb['mb_marketing_agree'] ? 'checked="checked"' : '';
|
||||
|
||||
// 개인정보 제3자 제공 동의
|
||||
$mb_thirdparty_agree_yes = $mb['mb_thirdparty_agree'] ? 'checked="checked"' : '';
|
||||
$mb_thirdparty_agree_no = !$mb['mb_thirdparty_agree'] ? 'checked="checked"' : '';
|
||||
|
||||
if (isset($mb['mb_certify'])) {
|
||||
// 날짜시간형이라면 drop 시킴
|
||||
if (preg_match("/-/", $mb['mb_certify'])) {
|
||||
@@ -205,7 +216,7 @@ if (isset($mb_id) && $mb_id) {
|
||||
if ($mb['mb_intercept_date']) {
|
||||
$g5['title'] = "차단된 ";
|
||||
} else {
|
||||
$g5['title'] .= "";
|
||||
$g5['title'] = "";
|
||||
}
|
||||
$g5['title'] .= '회원 ' . $html_title;
|
||||
require_once './admin.head.php';
|
||||
@@ -264,7 +275,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<th scope="row"><label for="mb_level">회원 권한</label></th>
|
||||
<td><?php echo get_member_level_select('mb_level', 1, $member['mb_level'], $mb['mb_level']) ?></td>
|
||||
<th scope="row">포인트</th>
|
||||
<td><a href="./point_list.php?sfl=mb_id&stx=<?php echo $mb['mb_id'] ?>" target="_blank"><?php echo number_format($mb['mb_point']) ?></a> 점</td>
|
||||
<td><a href="./point_list.php?sfl=mb_id&stx=<?php echo $mb['mb_id'] ?>" target="_blank"><?php echo number_format(isset($mb['mb_point']) ? $mb['mb_point'] : 0) ?></a> 점</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th scope="row"><label for="mb_email">E-mail<strong class="sound_only">필수</strong></label></th>
|
||||
@@ -327,7 +338,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<?php echo help('이미지 크기는 <strong>넓이 ' . $config['cf_member_icon_width'] . '픽셀 높이 ' . $config['cf_member_icon_height'] . '픽셀</strong>로 해주세요.') ?>
|
||||
<input type="file" name="mb_icon" id="mb_icon">
|
||||
<?php
|
||||
$mb_dir = substr($mb['mb_id'], 0, 2);
|
||||
$mb_dir = substr(isset($mb['mb_id']) ? $mb['mb_id'] : '', 0, 2);
|
||||
$icon_file = G5_DATA_PATH . '/member/' . $mb_dir . '/' . get_mb_icon_name($mb['mb_id']) . '.gif';
|
||||
if (file_exists($icon_file)) {
|
||||
$icon_url = str_replace(G5_DATA_PATH, G5_DATA_URL, $icon_file);
|
||||
@@ -344,7 +355,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<?php echo help('이미지 크기는 <strong>넓이 ' . $config['cf_member_img_width'] . '픽셀 높이 ' . $config['cf_member_img_height'] . '픽셀</strong>로 해주세요.') ?>
|
||||
<input type="file" name="mb_img" id="mb_img">
|
||||
<?php
|
||||
$mb_dir = substr($mb['mb_id'], 0, 2);
|
||||
$mb_dir = substr(isset($mb['mb_id']) ? $mb['mb_id'] : '', 0, 2);
|
||||
$icon_file = G5_DATA_PATH . '/member_image/' . $mb_dir . '/' . get_mb_icon_name($mb['mb_id']) . '.gif';
|
||||
if (file_exists($icon_file)) {
|
||||
echo get_member_profile_img($mb['mb_id']);
|
||||
@@ -354,21 +365,64 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th scope="row">메일 수신</th>
|
||||
<th scope="row">광고성 이메일 수신</th>
|
||||
<td>
|
||||
<input type="radio" name="mb_mailling" value="1" id="mb_mailling_yes" <?php echo $mb_mailling_yes; ?>>
|
||||
<label for="mb_mailling_yes">예</label>
|
||||
<input type="radio" name="mb_mailling" value="0" id="mb_mailling_no" <?php echo $mb_mailling_no; ?>>
|
||||
<label for="mb_mailling_no">아니오</label>
|
||||
|
||||
<?php if($w == "u" && $mb['mb_mailling_date'] != "0000-00-00 00:00:00"){
|
||||
echo $mb['mb_mailling'] == 1 ? "<br>(동의 일자: ".$mb['mb_mailling_date'].")" : '';
|
||||
} ?>
|
||||
</td>
|
||||
<th scope="row"><label for="mb_sms_yes">SMS 수신</label></th>
|
||||
<th scope="row"><label for="mb_sms_yes">광고성 SMS/카카오톡 수신</label></th>
|
||||
<td>
|
||||
<input type="radio" name="mb_sms" value="1" id="mb_sms_yes" <?php echo $mb_sms_yes; ?>>
|
||||
<label for="mb_sms_yes">예</label>
|
||||
<input type="radio" name="mb_sms" value="0" id="mb_sms_no" <?php echo $mb_sms_no; ?>>
|
||||
<label for="mb_sms_no">아니오</label>
|
||||
<?php if($w == "u" && $mb['mb_sms_date'] != "0000-00-00 00:00:00"){
|
||||
echo $mb['mb_sms'] == 1 ? "<br>(동의 일자: ".$mb['mb_sms_date'].")" : '';
|
||||
} ?>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th scope="row">마케팅 목적의<br>개인정보 수집 및 이용</th>
|
||||
<td>
|
||||
<input type="radio" name="mb_marketing_agree" value="1" id="mb_marketing_agree_yes" <?php echo $mb_marketing_agree_yes; ?>>
|
||||
<label for="mb_marketing_agree_yes">예</label>
|
||||
<input type="radio" name="mb_marketing_agree" value="0" id="mb_marketing_agree_no" <?php echo $mb_marketing_agree_no; ?>>
|
||||
<label for="mb_marketing_agree_no">아니오</label>
|
||||
|
||||
<?php if($w == "u" && $mb['mb_marketing_date'] != "0000-00-00 00:00:00"){
|
||||
echo $mb['mb_marketing_agree'] == 1 ? "<br>(동의 일자: ".$mb['mb_marketing_date'].")" : '';
|
||||
} ?>
|
||||
</td>
|
||||
<th scope="row"><label for="mb_sms_yes">개인정보 제3자 제공</label></th>
|
||||
<td>
|
||||
<input type="radio" name="mb_thirdparty_agree" value="1" id="mb_thirdparty_agree_yes" <?php echo $mb_thirdparty_agree_yes; ?>>
|
||||
<label for="mb_thirdparty_agree_yes">예</label>
|
||||
<input type="radio" name="mb_thirdparty_agree" value="0" id="mb_thirdparty_agree_no" <?php echo $mb_thirdparty_agree_no; ?>>
|
||||
<label for="mb_thirdparty_agree_no">아니오</label>
|
||||
|
||||
<?php if($w == "u" && $mb['mb_thirdparty_date'] != "0000-00-00 00:00:00"){
|
||||
echo $mb['mb_thirdparty_agree'] == 1 ? "<br>(동의 일자: ".$mb['mb_thirdparty_date'].")" : '';
|
||||
} ?>
|
||||
</td>
|
||||
</tr>
|
||||
<?php if($w == "u"){?>
|
||||
<tr>
|
||||
<th scope="row">약관동의 변경내역</th>
|
||||
<td colspan="3">
|
||||
<section id="sodr_request_log_wrap" class="ad_agree_log">
|
||||
<div>
|
||||
<?php echo conv_content($mb['mb_agree_log'], 0); ?>
|
||||
</div>
|
||||
</section>
|
||||
</td>
|
||||
</tr>
|
||||
<?php } ?>
|
||||
<tr>
|
||||
<th scope="row">정보 공개</th>
|
||||
<td colspan="3">
|
||||
@@ -376,6 +430,9 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<label for="mb_open_yes">예</label>
|
||||
<input type="radio" name="mb_open" value="0" id="mb_open_no" <?php echo $mb_open_no; ?>>
|
||||
<label for="mb_open_no">아니오</label>
|
||||
<?php if($w == "u" && $mb['mb_open_date'] != "0000-00-00 00:00:00"){
|
||||
echo $mb['mb_open'] == 1 ? "<br>(동의 일자: ".$mb['mb_open_date'].")" : '';
|
||||
} ?>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
@@ -455,7 +512,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<?php if ($config['cf_use_recommend']) { // 추천인 사용 ?>
|
||||
<tr>
|
||||
<th scope="row">추천인</th>
|
||||
<td colspan="3"><?php echo ($mb['mb_recommend'] ? get_text($mb['mb_recommend']) : '없음'); // 081022 : CSRF 보안 결함으로 인한 코드 수정 ?></td>
|
||||
<td colspan="3"><?php echo ((isset($mb['mb_recommend']) && $mb['mb_recommend']) ? get_text($mb['mb_recommend']) : '없음'); // 081022 : CSRF 보안 결함으로 인한 코드 수정 ?></td>
|
||||
</tr>
|
||||
<?php } ?>
|
||||
|
||||
@@ -502,7 +559,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<span class="provider_name"><?php echo $provider_name; //서비스이름 ?> ( <?php echo $account['displayname']; ?> )</span>
|
||||
<span class="account_hidden" style="display:none"><?php echo $account['mb_id']; ?></span>
|
||||
</div>
|
||||
<div class="btn_info"><a href="<?php echo G5_SOCIAL_LOGIN_URL . '/unlink.php?mp_no=' . $account['mp_no'] ?>" class="social_unlink" data-provider="<?php echo $account['mp_no']; ?>">연동해제</a> <span class="sound_only"><?php echo substr($account['mp_register_day'], 2, 14); ?></span></div>
|
||||
<div class="btn_info"><a href="<?php echo G5_SOCIAL_LOGIN_URL . '/unlink.php?mp_no=' . $account['mp_no'] ?>" class="social_unlink" data-provider="<?php echo $account['mp_no']; ?>">연동해제</a> <span class="sound_only"><?php echo substr(isset($account['mp_register_day']) ? $account['mp_register_day'] : '', 2, 14); ?></span></div>
|
||||
</div>
|
||||
<?php } //end foreach ?>
|
||||
</li>
|
||||
|
||||
@@ -18,8 +18,12 @@ $mb_certify_case = isset($_POST['mb_certify_case']) ? preg_replace('/[^0-9a-z_]/
|
||||
$mb_certify = isset($_POST['mb_certify']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_certify']) : '';
|
||||
$mb_zip = isset($_POST['mb_zip']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_zip']) : '';
|
||||
|
||||
// 광고성 정보 수신
|
||||
$mb_marketing_agree = isset($_POST['mb_marketing_agree']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_marketing_agree']), 1, 1)) : '0';
|
||||
$mb_thirdparty_agree = isset($_POST['mb_thirdparty_agree']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_thirdparty_agree']), 1, 1)) : '0';
|
||||
|
||||
// 관리자가 자동등록방지를 사용해야 할 경우 ( 회원의 비밀번호 변경시 캡챠를 체크한다 )
|
||||
if ($mb_password && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
|
||||
if ($mb_password) {
|
||||
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
|
||||
|
||||
if (!chk_captcha()) {
|
||||
@@ -80,14 +84,12 @@ for ($i = 1; $i <= 10; $i++) {
|
||||
|
||||
foreach ($check_keys as $key) {
|
||||
if( in_array($key, array('mb_signature', 'mb_profile')) ){
|
||||
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1, 0, 0) : '';
|
||||
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1, 0, 0)) : '';
|
||||
} else {
|
||||
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
|
||||
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
|
||||
}
|
||||
}
|
||||
|
||||
$mb_memo = isset($_POST['mb_memo']) ? $_POST['mb_memo'] : '';
|
||||
|
||||
$sql_common = " mb_name = '{$posts['mb_name']}',
|
||||
mb_nick = '{$mb_nick}',
|
||||
mb_email = '{$mb_email}',
|
||||
@@ -109,8 +111,11 @@ $sql_common = " mb_name = '{$posts['mb_name']}',
|
||||
mb_mailling = '{$posts['mb_mailling']}',
|
||||
mb_sms = '{$posts['mb_sms']}',
|
||||
mb_open = '{$posts['mb_open']}',
|
||||
mb_open_date = '".G5_TIME_YMDHIS."',
|
||||
mb_profile = '{$posts['mb_profile']}',
|
||||
mb_level = '{$posts['mb_level']}',
|
||||
mb_marketing_agree = '{$mb_marketing_agree}',
|
||||
mb_thirdparty_agree = '{$mb_thirdparty_agree}',
|
||||
mb_1 = '{$posts['mb_1']}',
|
||||
mb_2 = '{$posts['mb_2']}',
|
||||
mb_3 = '{$posts['mb_3']}',
|
||||
@@ -122,6 +127,11 @@ $sql_common = " mb_name = '{$posts['mb_name']}',
|
||||
mb_9 = '{$posts['mb_9']}',
|
||||
mb_10 = '{$posts['mb_10']}' ";
|
||||
|
||||
// 부여하려는 mb_level 상한 검증 (자기보다 높은 권한 부여 차단)
|
||||
if ($is_admin !== 'super' && (int) $posts['mb_level'] >= (int) $member['mb_level']) {
|
||||
alert('자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.');
|
||||
}
|
||||
|
||||
if ($w == '') {
|
||||
$mb = get_member($mb_id);
|
||||
if (isset($mb['mb_id']) && $mb['mb_id']) {
|
||||
@@ -142,6 +152,36 @@ if ($w == '') {
|
||||
alert('이미 존재하는 이메일입니다.\\nID : ' . $row['mb_id'] . '\\n이름 : ' . $row['mb_name'] . '\\n닉네임 : ' . $row['mb_nick'] . '\\n메일 : ' . $row['mb_email']);
|
||||
}
|
||||
|
||||
$agree_items = array();
|
||||
// 마케팅 목적의 개인정보 수집 및 이용
|
||||
if ($mb_marketing_agree == 1) {
|
||||
$sql_common .= " , mb_marketing_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "마케팅 목적의 개인정보 수집 및 이용(동의)";
|
||||
}
|
||||
|
||||
// 광고성 이메일 수신
|
||||
if ($mb_mailling == 1) {
|
||||
$sql_common .= " , mb_mailling_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "광고성 이메일 수신(동의)";
|
||||
}
|
||||
|
||||
// 광고성 SMS/카카오톡 수신
|
||||
if ($mb_sms == 1) {
|
||||
$sql_common .= " , mb_sms_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "광고성 SMS/카카오톡 수신(동의)";
|
||||
}
|
||||
|
||||
// 개인정보 제3자 제공
|
||||
if ($mb_thirdparty_agree == 1) {
|
||||
$sql_common .= " , mb_thirdparty_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "개인정보 제3자 제공(동의)";
|
||||
}
|
||||
|
||||
// 동의 로그 추가
|
||||
if (!empty($agree_items)) {
|
||||
$agree_log = "[".G5_TIME_YMDHIS.", 관리자 회원추가] " . implode(' | ', $agree_items) . "\n";
|
||||
$sql_common .= " , mb_agree_log = CONCAT('{$agree_log}', IFNULL(mb_agree_log, ''))";
|
||||
}
|
||||
sql_query(" insert into {$g5['member_table']} set mb_id = '{$mb_id}', mb_password = '" . get_encrypt_string($mb_password) . "', mb_datetime = '" . G5_TIME_YMDHIS . "', mb_ip = '{$_SERVER['REMOTE_ADDR']}', mb_email_certify = '" . G5_TIME_YMDHIS . "', {$sql_common} ");
|
||||
} elseif ($w == 'u') {
|
||||
$mb = get_member($mb_id);
|
||||
@@ -193,10 +233,54 @@ if ($w == '') {
|
||||
$sql_certify = "";
|
||||
}
|
||||
|
||||
// 현재 데이터 조회
|
||||
$row = sql_fetch("select * from {$g5['member_table']} where mb_id = '{$mb_id}' ");
|
||||
$agree_items = array();
|
||||
|
||||
// 마케팅 목적의 개인정보 수집 및 이용
|
||||
$sql_marketing_date = "";
|
||||
if ($row['mb_marketing_agree'] !== $mb_marketing_agree) {
|
||||
$sql_marketing_date .= " , mb_marketing_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "마케팅 목적의 개인정보 수집 및 이용(" . ($mb_marketing_agree == 1 ? "동의" : "철회") . ")";
|
||||
}
|
||||
|
||||
// 광고성 이메일 수신
|
||||
$sql_mailling_date = "";
|
||||
if ($row['mb_mailling'] !== $mb_mailling) {
|
||||
$sql_mailling_date .= " , mb_mailling_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "광고성 이메일 수신(" . ($mb_mailling == 1 ? "동의" : "철회") . ")";
|
||||
}
|
||||
|
||||
// 광고성 SMS/카카오톡 수신
|
||||
$sql_sms_date = "";
|
||||
if ($row['mb_sms'] !== $mb_sms) {
|
||||
$sql_sms_date .= " , mb_sms_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "광고성 SMS/카카오톡 수신(" . ($mb_sms == 1 ? "동의" : "철회") . ")";
|
||||
}
|
||||
|
||||
// 개인정보 제3자 제공
|
||||
$sql_thirdparty_date = "";
|
||||
if ($row['mb_thirdparty_agree'] !== $mb_thirdparty_agree) {
|
||||
$sql_thirdparty_date .= " , mb_thirdparty_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "개인정보 제3자 제공(" . ($mb_thirdparty_agree == 1 ? "동의" : "철회") . ")";
|
||||
}
|
||||
|
||||
// 동의 로그 추가
|
||||
$sql_agree_log = "";
|
||||
if (!empty($agree_items)) {
|
||||
$agree_log = "[".G5_TIME_YMDHIS.", 관리자 회원수정] " . implode(' | ', $agree_items) . "\n";
|
||||
$sql_agree_log .= " , mb_agree_log = CONCAT('{$agree_log}', IFNULL(mb_agree_log, ''))";
|
||||
}
|
||||
|
||||
$sql = " update {$g5['member_table']}
|
||||
set {$sql_common}
|
||||
{$sql_password}
|
||||
{$sql_certify}
|
||||
{$sql_mailling_date}
|
||||
{$sql_sms_date}
|
||||
{$sql_marketing_date}
|
||||
{$sql_thirdparty_date}
|
||||
{$sql_agree_log}
|
||||
where mb_id = '{$mb_id}' ";
|
||||
sql_query($sql);
|
||||
} else {
|
||||
|
||||
+22
-11
@@ -6,6 +6,12 @@ auth_check_menu($auth, $sub_menu, 'r');
|
||||
|
||||
$sql_common = " from {$g5['member_table']} ";
|
||||
|
||||
// $sfl 화이트리스트 검증 (KVE-2026-0340)
|
||||
$allowed_sfl = array('mb_id', 'mb_nick', 'mb_name', 'mb_level', 'mb_email', 'mb_tel', 'mb_hp', 'mb_point', 'mb_datetime', 'mb_ip', 'mb_recommend');
|
||||
if (!in_array($sfl, $allowed_sfl)) {
|
||||
$sfl = 'mb_id';
|
||||
}
|
||||
|
||||
$sql_search = " where (1) ";
|
||||
if ($stx) {
|
||||
$sql_search .= " and ( ";
|
||||
@@ -36,6 +42,10 @@ if (!$sst) {
|
||||
$sod = "desc";
|
||||
}
|
||||
|
||||
$allowed_sst = array('mb_datetime', 'mb_id', 'mb_name', 'mb_nick', 'mb_level', 'mb_point', 'mb_today_login', 'mb_open', 'mb_mailling', 'mb_sms', 'mb_adult', 'mb_certify', 'mb_email_certify', 'mb_intercept_date', 'mb_leave_date');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'mb_datetime';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
|
||||
@@ -127,7 +137,7 @@ $colspan = 16;
|
||||
<th scope="col" rowspan="2" id="mb_list_cert"><?php echo subject_sort_link('mb_certify', '', 'desc') ?>본인확인</a></th>
|
||||
<th scope="col" id="mb_list_mailc"><?php echo subject_sort_link('mb_email_certify', '', 'desc') ?>메일인증</a></th>
|
||||
<th scope="col" id="mb_list_open"><?php echo subject_sort_link('mb_open', '', 'desc') ?>정보공개</a></th>
|
||||
<th scope="col" id="mb_list_mailr"><?php echo subject_sort_link('mb_mailling', '', 'desc') ?>메일수신</a></th>
|
||||
<th scope="col" id="mb_list_mailr"><?php echo subject_sort_link('mb_mailling', '', 'desc') ?>광고성이메일</a></th>
|
||||
<th scope="col" id="mb_list_auth">상태</th>
|
||||
<th scope="col" id="mb_list_mobile">휴대폰</th>
|
||||
<th scope="col" id="mb_list_lastcall"><?php echo subject_sort_link('mb_today_login', '', 'desc') ?>최종접속</a></th>
|
||||
@@ -137,9 +147,9 @@ $colspan = 16;
|
||||
<tr>
|
||||
<th scope="col" id="mb_list_name"><?php echo subject_sort_link('mb_name') ?>이름</a></th>
|
||||
<th scope="col" id="mb_list_nick"><?php echo subject_sort_link('mb_nick') ?>닉네임</a></th>
|
||||
<th scope="col" id="mb_list_sms"><?php echo subject_sort_link('mb_sms', '', 'desc') ?>SMS수신</a></th>
|
||||
<th scope="col" id="mb_list_adultc"><?php echo subject_sort_link('mb_adult', '', 'desc') ?>성인인증</a></th>
|
||||
<th scope="col" id="mb_list_auth"><?php echo subject_sort_link('mb_intercept_date', '', 'desc') ?>접근차단</a></th>
|
||||
<th scope="col" id="mb_list_sms"><?php echo subject_sort_link('mb_sms', '', 'desc') ?>광고성SMS</a></th>
|
||||
<th scope="col" id="mb_list_deny"><?php echo subject_sort_link('mb_level', '', 'desc') ?>권한</a></th>
|
||||
<th scope="col" id="mb_list_tel">전화번호</th>
|
||||
<th scope="col" id="mb_list_join"><?php echo subject_sort_link('mb_datetime', '', 'desc') ?>가입일</a></th>
|
||||
@@ -252,14 +262,15 @@ $colspan = 16;
|
||||
<input type="radio" name="mb_certify[<?php echo $i; ?>]" value="ipin" id="mb_certify_ipin_<?php echo $i; ?>" <?php echo $row['mb_certify'] == 'ipin' ? 'checked' : ''; ?>>
|
||||
<label for="mb_certify_ipin_<?php echo $i; ?>">아이핀</label>
|
||||
</td>
|
||||
<td headers="mb_list_mailc"><?php echo preg_match('/[1-9]/', $row['mb_email_certify']) ? '<span class="txt_true">Yes</span>' : '<span class="txt_false">No</span>'; ?></td>
|
||||
<td headers="mb_list_open">
|
||||
<td headers="mb_list_mailc" class="td_consent"><?php echo preg_match('/[1-9]/', $row['mb_email_certify']) ? '<span class="txt_true">Yes</span>' : '<span class="txt_false">No</span>'; ?></td>
|
||||
<td headers="mb_list_open" class="td_consent">
|
||||
<label for="mb_open_<?php echo $i; ?>" class="sound_only">정보공개</label>
|
||||
<input type="checkbox" name="mb_open[<?php echo $i; ?>]" <?php echo $row['mb_open'] ? 'checked' : ''; ?> value="1" id="mb_open_<?php echo $i; ?>">
|
||||
</td>
|
||||
<td headers="mb_list_mailr">
|
||||
<label for="mb_mailling_<?php echo $i; ?>" class="sound_only">메일수신</label>
|
||||
<td headers="mb_list_mailr" class="td_consent">
|
||||
<label for="mb_mailling_<?php echo $i; ?>" class="sound_only">광고성이메일수신</label>
|
||||
<input type="checkbox" name="mb_mailling[<?php echo $i; ?>]" <?php echo $row['mb_mailling'] ? 'checked' : ''; ?> value="1" id="mb_mailling_<?php echo $i; ?>">
|
||||
<input type="hidden" name="mb_mailling_default[<?php echo $i; ?>]" value="<?php echo isset($row['mb_mailling']) ? $row['mb_mailling'] : '0'; ?> " id="mb_mailling_default_<?php echo $i; ?>">
|
||||
</td>
|
||||
<td headers="mb_list_auth" class="td_mbstat">
|
||||
<?php
|
||||
@@ -280,11 +291,6 @@ $colspan = 16;
|
||||
<td headers="mb_list_nick" class="td_name sv_use">
|
||||
<div><?php echo $mb_nick ?></div>
|
||||
</td>
|
||||
|
||||
<td headers="mb_list_sms">
|
||||
<label for="mb_sms_<?php echo $i; ?>" class="sound_only">SMS수신</label>
|
||||
<input type="checkbox" name="mb_sms[<?php echo $i; ?>]" <?php echo $row['mb_sms'] ? 'checked' : ''; ?> value="1" id="mb_sms_<?php echo $i; ?>">
|
||||
</td>
|
||||
<td headers="mb_list_adultc">
|
||||
<label for="mb_adult_<?php echo $i; ?>" class="sound_only">성인인증</label>
|
||||
<input type="checkbox" name="mb_adult[<?php echo $i; ?>]" <?php echo $row['mb_adult'] ? 'checked' : ''; ?> value="1" id="mb_adult_<?php echo $i; ?>">
|
||||
@@ -295,6 +301,11 @@ $colspan = 16;
|
||||
<label for="mb_intercept_date_<?php echo $i; ?>" class="sound_only">접근차단</label>
|
||||
<?php } ?>
|
||||
</td>
|
||||
<td headers="mb_list_sms">
|
||||
<label for="mb_sms_<?php echo $i; ?>" class="sound_only">광고성SMS/카카오톡수신</label>
|
||||
<input type="checkbox" name="mb_sms[<?php echo $i; ?>]" <?php echo $row['mb_sms'] ? 'checked' : ''; ?> value="1" id="mb_sms_<?php echo $i; ?>">
|
||||
<input type="hidden" name="mb_sms_default[<?php echo $i; ?>]" value="<?php echo isset($row['mb_sms']) ? $row['mb_sms'] : '0'; ?> " id="mb_sms_default_<?php echo $i; ?>">
|
||||
</td>
|
||||
<td headers="mb_list_auth" class="td_mbstat">
|
||||
<?php echo get_member_level_select("mb_level[$i]", 1, $member['mb_level'], $row['mb_level']) ?>
|
||||
</td>
|
||||
|
||||
@@ -0,0 +1,294 @@
|
||||
<?php
|
||||
/*************************************************************************
|
||||
**
|
||||
** 내보내기 관련 상수 정의
|
||||
**
|
||||
*************************************************************************/
|
||||
define('MEMBER_EXPORT_PAGE_SIZE', 10000); // 파일당 처리할 회원 수
|
||||
define('MEMBER_EXPORT_MAX_SIZE', 300000); // 최대 처리할 회원 수
|
||||
define('MEMBER_BASE_DIR', "member_list"); // 엑셀 베이스 폴더
|
||||
define('MEMBER_BASE_DATE', date('YmdHis')); // 폴더/파일명용 날짜
|
||||
define('MEMBER_EXPORT_DIR', G5_DATA_PATH . "/" . MEMBER_BASE_DIR . "/" . MEMBER_BASE_DATE); // 엑셀 파일 저장 경로
|
||||
define('MEMBER_LOG_DIR', G5_DATA_PATH . "/" . MEMBER_BASE_DIR . "/" . "log"); // 로그 파일 저장 경로
|
||||
|
||||
/*************************************************************************
|
||||
**
|
||||
** 공통 함수 정의
|
||||
**
|
||||
*************************************************************************/
|
||||
/**
|
||||
* 검색 옵션 설정
|
||||
*/
|
||||
function get_export_config($type = null)
|
||||
{
|
||||
$config = array(
|
||||
'sfl_list' => array(
|
||||
'mb_id'=>'아이디',
|
||||
'mb_name'=>'이름',
|
||||
'mb_nick'=>'닉네임',
|
||||
'mb_email'=>'이메일',
|
||||
'mb_tel'=>'전화번호',
|
||||
'mb_hp'=>'휴대폰번호',
|
||||
'mb_addr1'=>'주소'
|
||||
),
|
||||
'point_cond_map' => array(
|
||||
'gte'=>'≥',
|
||||
'lte'=>'≤',
|
||||
'eq'=>'='
|
||||
),
|
||||
'intercept_list' => array(
|
||||
'exclude'=>'차단회원 제외',
|
||||
'only'=>'차단회원만'
|
||||
),
|
||||
'ad_range_list' => array(
|
||||
'all' => '수신동의 회원 전체',
|
||||
'mailling_only' => '이메일 수신동의 회원만',
|
||||
'sms_only' => 'SMS/카카오톡 수신동의 회원만',
|
||||
'month_confirm' => date('m월').' 수신동의 확인 대상만',
|
||||
'custom_period' => '수신동의 기간 직접 입력'
|
||||
),
|
||||
);
|
||||
|
||||
return $type ? (isset($config[$type]) ? $config[$type] : array()) : $config;
|
||||
}
|
||||
|
||||
/**
|
||||
* 파라미터 수집 및 유효성 검사
|
||||
*/
|
||||
function get_member_export_params()
|
||||
{
|
||||
// 친구톡 양식 - 엑셀 양식에 포함할 항목
|
||||
$fieldArray = array_map('trim', explode(',', isset($_GET['fields']) ? $_GET['fields'] : ''));
|
||||
$vars = array();
|
||||
foreach ($fieldArray as $index => $field) {
|
||||
if(!empty($field)){
|
||||
$vars['var' . ($index + 1)] = $field;
|
||||
}
|
||||
}
|
||||
|
||||
$params = array(
|
||||
'page' => 1,
|
||||
'formatType' => (int)(isset($_GET['formatType']) ? $_GET['formatType'] : 1),
|
||||
'use_stx' => isset($_GET['use_stx']) ? $_GET['use_stx'] : 0,
|
||||
'stx_cond' => clean_xss_tags(isset($_GET['stx_cond']) ? $_GET['stx_cond'] : 'like'),
|
||||
'sfl' => clean_xss_tags(isset($_GET['sfl']) ? $_GET['sfl'] : ''),
|
||||
'stx' => clean_xss_tags(isset($_GET['stx']) ? $_GET['stx'] : ''),
|
||||
'use_level' => isset($_GET['use_level']) ? $_GET['use_level'] : 0,
|
||||
'level_start' => (int)(isset($_GET['level_start']) ? $_GET['level_start'] : 1),
|
||||
'level_end' => (int)(isset($_GET['level_end']) ? $_GET['level_end'] : 10),
|
||||
'use_date' => isset($_GET['use_date']) ? $_GET['use_date'] : 0,
|
||||
'date_start' => clean_xss_tags(isset($_GET['date_start']) ? $_GET['date_start'] : ''),
|
||||
'date_end' => clean_xss_tags(isset($_GET['date_end']) ? $_GET['date_end'] : ''),
|
||||
'use_point' => isset($_GET['use_point']) ? $_GET['use_point'] : 0,
|
||||
'point' => isset($_GET['point']) ? $_GET['point'] : '',
|
||||
'point_cond' => isset($_GET['point_cond']) ? $_GET['point_cond'] : 'gte',
|
||||
'use_hp_exist' => isset($_GET['use_hp_exist']) ? $_GET['use_hp_exist'] : 0,
|
||||
'ad_range_only' => isset($_GET['ad_range_only']) ? $_GET['ad_range_only'] : 0,
|
||||
'ad_range_type' => clean_xss_tags(isset($_GET['ad_range_type']) ? $_GET['ad_range_type'] : 'all'),
|
||||
'ad_mailling' => isset($_GET['ad_mailling']) ? $_GET['ad_mailling'] : 0,
|
||||
'ad_sms' => isset($_GET['ad_sms']) ? $_GET['ad_sms'] : 0,
|
||||
'agree_date_start' => clean_xss_tags(isset($_GET['agree_date_start']) ? $_GET['agree_date_start'] : ''),
|
||||
'agree_date_end' => clean_xss_tags(isset($_GET['agree_date_end']) ? $_GET['agree_date_end'] : ''),
|
||||
'use_intercept' => isset($_GET['use_intercept']) ? $_GET['use_intercept'] : 0,
|
||||
'intercept' => clean_xss_tags(isset($_GET['intercept']) ? $_GET['intercept'] : 'exclude'),
|
||||
'vars' => $vars,
|
||||
);
|
||||
|
||||
// 레벨 범위 검증
|
||||
if ($params['level_start'] > $params['level_end']) {
|
||||
$tmp_level = $params['level_start'];
|
||||
$params['level_start'] = $params['level_end'];
|
||||
$params['level_end'] = $tmp_level;
|
||||
}
|
||||
|
||||
// 가입기간 - 날짜 범위 검증
|
||||
if ($params['use_date'] && $params['date_start'] && $params['date_end']) {
|
||||
if ($params['date_start'] > $params['date_end']) {
|
||||
$tmp_date = $params['date_start'];
|
||||
$params['date_start'] = $params['date_end'];
|
||||
$params['date_end'] = $tmp_date;
|
||||
}
|
||||
}
|
||||
|
||||
// 수신동의기간 - 날짜 범위 검증
|
||||
if ($params['ad_range_type'] == 'custom_period' && $params['agree_date_start'] && $params['agree_date_end']) {
|
||||
if ($params['agree_date_start'] > $params['agree_date_end']) {
|
||||
$tmp_agree_date = $params['agree_date_start'];
|
||||
$params['agree_date_start'] = $params['agree_date_end'];
|
||||
$params['agree_date_end'] = $tmp_agree_date;
|
||||
}
|
||||
}
|
||||
|
||||
return $params;
|
||||
}
|
||||
|
||||
/**
|
||||
* 전체 데이터 개수 조회
|
||||
*/
|
||||
function member_export_get_total_count($params)
|
||||
{
|
||||
global $g5;
|
||||
|
||||
$where = member_export_build_where($params);
|
||||
$sql = "SELECT COUNT(*) as cnt FROM {$g5['member_table']} {$where}";
|
||||
|
||||
$result = sql_query($sql);
|
||||
if (!$result) {
|
||||
throw new Exception("데이터 조회에 실패하였습니다. 다시 시도해주세요.");
|
||||
}
|
||||
|
||||
$row = sql_fetch_array($result);
|
||||
return (int)$row['cnt'];
|
||||
}
|
||||
|
||||
/**
|
||||
* WHERE 조건절 생성
|
||||
*/
|
||||
function member_export_build_where($params)
|
||||
{
|
||||
global $config;
|
||||
$conditions = array();
|
||||
|
||||
// 기본 조건 - 탈퇴하지 않은 사용자
|
||||
$conditions[] = "mb_leave_date = ''";
|
||||
|
||||
// 검색어 조건 (sql_escape_string 사용으로 보안 강화)
|
||||
if (!empty($params['use_stx']) && $params['use_stx'] === '1') {
|
||||
$sfl_list = get_export_config('sfl_list');
|
||||
$sfl = in_array($params['sfl'], array_keys($sfl_list)) ? $params['sfl'] : '';
|
||||
$stx = sql_escape_string($params['stx']);
|
||||
|
||||
if(!empty($sfl) && !empty($stx)){
|
||||
if ($params['stx_cond'] === 'like') {
|
||||
$conditions[] = "{$sfl} LIKE '%{$stx}%'";
|
||||
} else {
|
||||
$conditions[] = "{$sfl} = '{$stx}'";
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 권한 조건
|
||||
if (!empty($params['use_level']) && $params['use_level'] === '1') {
|
||||
$level_start = max(1, (int)$params['level_start']);
|
||||
$level_end = min(10, (int)$params['level_end']);
|
||||
|
||||
$conditions[] = "(mb_level BETWEEN {$level_start} AND {$level_end})";
|
||||
}
|
||||
|
||||
// 가입기간 조건
|
||||
if (!empty($params['use_date']) && $params['use_date'] === '1') {
|
||||
$date_start = isset($params['date_start']) ? sql_escape_string(trim($params['date_start'])) : '';
|
||||
$date_end = isset($params['date_end']) ? sql_escape_string(trim($params['date_end'])) : '';
|
||||
|
||||
if ($date_start && $date_end) {
|
||||
$conditions[] = "mb_datetime BETWEEN '{$date_start} 00:00:00' AND '{$date_end} 23:59:59'";
|
||||
} elseif ($date_start) {
|
||||
$conditions[] = "mb_datetime >= '{$date_start} 00:00:00'";
|
||||
} elseif ($date_end) {
|
||||
$conditions[] = "mb_datetime <= '{$date_end} 23:59:59'";
|
||||
}
|
||||
}
|
||||
|
||||
// 포인트 조건
|
||||
if (!empty($params['use_point']) && $params['use_point'] === '1') {
|
||||
$point = $params['point'];
|
||||
$point_cond = $params['point_cond'];
|
||||
|
||||
if ($point != '') {
|
||||
$point = (int)$point; // 정수로 캐스팅
|
||||
|
||||
switch ($point_cond) {
|
||||
case 'lte':
|
||||
$conditions[] = "mb_point <= {$point}";
|
||||
break;
|
||||
case 'eq':
|
||||
$conditions[] = "mb_point = {$point}";
|
||||
break;
|
||||
default:
|
||||
$conditions[] = "mb_point >= {$point}";
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 휴대폰 번호 존재 조건
|
||||
if (!empty($params['use_hp_exist']) && $params['use_hp_exist'] === '1') {
|
||||
$conditions[] = "(mb_hp is not null and mb_hp != '')";
|
||||
}
|
||||
|
||||
// 정보수신동의 조건
|
||||
if (!empty($params['ad_range_only']) && $params['ad_range_only'] === '1') {
|
||||
$range = isset($params['ad_range_type']) ? $params['ad_range_type'] : '';
|
||||
|
||||
// 공통: 마케팅 목적 수집·이용 동의 + (필요 시) 제3자 동의
|
||||
$thirdparty_clause = $config['cf_sms_use'] !== '' ? " AND mb_thirdparty_agree = 1" : "";
|
||||
$base_marketing = "mb_marketing_agree = 1{$thirdparty_clause}";
|
||||
|
||||
if ($range === 'all') {
|
||||
// 마케팅 동의 + (이메일 OR SMS 동의)
|
||||
$conditions[] = "({$base_marketing} AND (mb_mailling = 1 OR mb_sms = 1))";
|
||||
} elseif ($range === 'mailling_only') {
|
||||
// 마케팅 동의 + 이메일 동의
|
||||
$conditions[] = "({$base_marketing} AND mb_mailling = 1)";
|
||||
} elseif ($range === 'sms_only') {
|
||||
// 마케팅 동의 + SMS/카카오톡 동의
|
||||
$conditions[] = "({$base_marketing} AND mb_sms = 1)";
|
||||
} elseif ($range === 'month_confirm' || $range === 'custom_period') {
|
||||
// 채널 필터 체크
|
||||
$useEmail = !empty($params['ad_mailling']);
|
||||
$useSms = !empty($params['ad_sms']);
|
||||
|
||||
if ($range === 'month_confirm') {
|
||||
// 23개월 전 그 달
|
||||
$start = date('Y-m-01 00:00:00', strtotime('-23 months'));
|
||||
$end = date('Y-m-t 23:59:59', strtotime('-23 months'));
|
||||
$emailDateCond = "mb_mailling_date BETWEEN '{$start}' AND '{$end}'";
|
||||
$smsDateCond = "mb_sms_date BETWEEN '{$start}' AND '{$end}'";
|
||||
|
||||
} else {
|
||||
// 수신동의기간 직접 입력 - custom_period
|
||||
$date_start = isset($params['agree_date_start']) ? sql_escape_string(trim($params['agree_date_start'])) : '';
|
||||
$date_end = isset($params['agree_date_end']) ? sql_escape_string(trim($params['agree_date_end'])) : '';
|
||||
|
||||
if ($date_start && $date_end) {
|
||||
$emailDateCond = "mb_mailling_date BETWEEN '{$date_start} 00:00:00' AND '{$date_end} 23:59:59'";
|
||||
$smsDateCond = "mb_sms_date BETWEEN '{$date_start} 00:00:00' AND '{$date_end} 23:59:59'";
|
||||
} elseif ($date_start) {
|
||||
$emailDateCond = "mb_mailling_date >= '{$date_start} 00:00:00'";
|
||||
$smsDateCond = "mb_sms_date >= '{$date_start} 00:00:00'";
|
||||
} elseif ($date_end) {
|
||||
$emailDateCond = "mb_mailling_date <= '{$date_end} 23:59:59'";
|
||||
$smsDateCond = "mb_sms_date <= '{$date_end} 23:59:59'";
|
||||
} else {
|
||||
$emailDateCond = "mb_mailling_date <> '0000-00-00 00:00:00'";
|
||||
$smsDateCond = "mb_sms_date <> '0000-00-00 00:00:00'";
|
||||
}
|
||||
}
|
||||
|
||||
if (!$useEmail && !$useSms) {
|
||||
$conditions[] = "0=1"; // 둘 다 해제 ⇒ 결과 0건
|
||||
} else {
|
||||
// 조건 조립
|
||||
$parts = array();
|
||||
if ($useEmail) $parts[] = "(mb_mailling = 1 AND {$emailDateCond})";
|
||||
if ($useSms) $parts[] = "(mb_sms = 1 AND {$smsDateCond})";
|
||||
|
||||
$conditions[] = !empty($parts) ? '(' . implode(' OR ', $parts) . ')' : '';
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 차단 회원 조건
|
||||
if (!empty($params['use_intercept']) && $params['use_intercept'] === '1') {
|
||||
switch ($params['intercept']) {
|
||||
case 'exclude':
|
||||
$conditions[] = "mb_intercept_date = ''";
|
||||
break;
|
||||
case 'only':
|
||||
$conditions[] = "mb_intercept_date != ''";
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
return empty($conditions) ? '' : 'WHERE ' . implode(' AND ', $conditions);
|
||||
}
|
||||
@@ -0,0 +1,483 @@
|
||||
<?php
|
||||
$sub_menu = "200400";
|
||||
require_once './_common.php';
|
||||
require_once './member_list_exel.lib.php'; // 회원관리파일 공통 라이브러리
|
||||
|
||||
auth_check_menu($auth, $sub_menu, 'r');
|
||||
|
||||
// 파라미터 수집 및 유효성 검사
|
||||
$params = get_member_export_params();
|
||||
|
||||
// 총건수
|
||||
$total_count = 0;
|
||||
$total_error = "";
|
||||
try {
|
||||
$total_count = member_export_get_total_count($params);
|
||||
} catch (Exception $e) {
|
||||
$total_error = $e->getMessage(); // 메서드 호출 괄호 필수
|
||||
}
|
||||
|
||||
$g5['title'] = '회원관리파일';
|
||||
require_once './admin.head.php';
|
||||
$colspan = 14;
|
||||
?>
|
||||
|
||||
<h2>회원 엑셀 생성</h2>
|
||||
|
||||
<div class="local_desc01 local_desc">
|
||||
<p><b>회원수 <?php echo number_format(MEMBER_EXPORT_PAGE_SIZE);?>건 초과 시</b> <?php echo number_format(MEMBER_EXPORT_PAGE_SIZE);?>건 단위로 분리 저장되며, <b>엑셀 생성 최대 건수는 <?php echo number_format(MEMBER_EXPORT_MAX_SIZE);?>건</b>입니다. 초과 시 조건 추가 설정 후 재시도하시기 바랍니다.</p>
|
||||
<p><b>수신동의 확인 대상은 만료일까지 1달 미만인 회원</b>을 기준으로 필터링됩니다.</p>
|
||||
|
||||
<br>
|
||||
<p>파일 생성 시 서버에 임시 생성된 파일 중 <b>오늘 날짜를 제외 한 파일은 자동 삭제</b>되며, 수동 삭제 필요 시 <a href="<?php echo G5_ADMIN_URL;?>/member_list_file_delete.php"><b>회원관리파일 일괄삭제</b></a>에서 진행하시기 바랍니다.</p>
|
||||
<p>회원 정보 수정은 <a href="<?php echo G5_ADMIN_URL;?>/member_list.php" class="link"><b>회원 관리</b></a>에서 진행하실 수 있습니다.</p>
|
||||
</div>
|
||||
|
||||
<div class="local_ov01 local_ov">
|
||||
<span class="btn_ov01">
|
||||
<span class="ov_txt">총건수 </span>
|
||||
<?php if($total_error != "") { ?>
|
||||
<span class="ov_num"> <?php echo $total_error ?></span>
|
||||
<?php } else {?>
|
||||
<span class="ov_num"> <?php echo number_format($total_count) ?>건</span>
|
||||
<?php } ?>
|
||||
</span>
|
||||
</div>
|
||||
|
||||
<!-- 회원 검색 필터링 폼 -->
|
||||
<form id="fsearch" name="fsearch" class="member_list_data" method="get">
|
||||
<input type="hidden" name="token" value="<?php echo get_token(); ?>">
|
||||
<fieldset>
|
||||
<legend class="sound_only">회원 검색 필터링</legend>
|
||||
<div class="sch_table">
|
||||
|
||||
<!-- 검색어 적용 -->
|
||||
<div class="sch_row">
|
||||
<div class="label">
|
||||
<label>
|
||||
<input type="checkbox" name="use_stx" value="1" <?php echo isset($_GET['use_stx']) ? 'checked' : ''; ?>>
|
||||
검색어 적용
|
||||
</label>
|
||||
</div>
|
||||
<div class="field">
|
||||
<select name="sfl">
|
||||
<?php
|
||||
// 검색어 옵션 : [정의] get_export_config() - adm/member_list_exel.lib.php;
|
||||
foreach (get_export_config('sfl_list') as $val => $label) {
|
||||
$selected = (isset($_GET['sfl']) && $_GET['sfl'] === $val) ? 'selected' : '';
|
||||
echo "<option value=\"$val\" $selected>$label</option>";
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
<input type="text" name="stx" value="<?php echo htmlspecialchars(isset($_GET['stx']) ? $_GET['stx'] : ''); ?>" placeholder="검색어 입력">
|
||||
<span class="radio_group">
|
||||
<label><input type="radio" name="stx_cond" value="like" <?php echo (isset($_GET['stx_cond']) ? $_GET['stx_cond'] : 'like') === 'like' ? 'checked' : ''; ?>> 포함</label>
|
||||
<label><input type="radio" name="stx_cond" value="equal" <?php echo (isset($_GET['stx_cond']) ? $_GET['stx_cond'] : '') === 'equal' ? 'checked' : ''; ?>> 일치</label>
|
||||
</span>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- 레벨 적용 -->
|
||||
<div class="sch_row">
|
||||
<div class="label">
|
||||
<label><input type="checkbox" name="use_level" value="1" <?php echo isset($_GET['use_level']) ? 'checked' : ''; ?>> 레벨 적용</label>
|
||||
</div>
|
||||
<div class="field">
|
||||
<select name="level_start">
|
||||
<?php for ($i = 1; $i <= 10; $i++): ?>
|
||||
<option value="<?php echo $i; ?>" <?php echo (isset($_GET['level_start']) && $_GET['level_start'] == $i) ? 'selected' : ''; ?>><?php echo $i; ?></option>
|
||||
<?php endfor; ?>
|
||||
</select> ~
|
||||
<select name="level_end">
|
||||
<?php for ($i = 1; $i <= 10; $i++): ?>
|
||||
<option value="<?php echo $i; ?>" <?php echo (isset($_GET['level_end']) && $_GET['level_end'] == $i) ? 'selected' : ''; ?>><?php echo $i; ?></option>
|
||||
<?php endfor; ?>
|
||||
</select>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- 가입기간 적용 -->
|
||||
<div class="sch_row">
|
||||
<div class="label">
|
||||
<label><input type="checkbox" name="use_date" value="1" <?php echo isset($_GET['use_date']) ? 'checked' : ''; ?>> 가입기간 적용</label>
|
||||
</div>
|
||||
<div class="field">
|
||||
<input type="date" name="date_start" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['date_start']) ? $_GET['date_start'] : ''); ?>"> ~
|
||||
<input type="date" name="date_end" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['date_end']) ? $_GET['date_end'] : ''); ?>">
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- 포인트 적용 -->
|
||||
<div class="sch_row">
|
||||
<div class="label">
|
||||
<label><input type="checkbox" name="use_point" value="1" <?php echo isset($_GET['use_point']) ? 'checked' : ''; ?>> 포인트 적용</label>
|
||||
</div>
|
||||
<div class="field">
|
||||
<input type="number" name="point" value="<?php echo htmlspecialchars(isset($_GET['point']) ? $_GET['point'] : ''); ?>" placeholder="포인트 입력">
|
||||
<span class="radio_group">
|
||||
<label><input type="radio" name="point_cond" value="gte" <?php echo (isset($_GET['point_cond']) ? $_GET['point_cond'] : 'gte') === 'gte' ? 'checked' : ''; ?>> 이상</label>
|
||||
<label><input type="radio" name="point_cond" value="lte" <?php echo (isset($_GET['point_cond']) ? $_GET['point_cond'] : '') === 'lte' ? 'checked' : ''; ?>> 이하</label>
|
||||
<label><input type="radio" name="point_cond" value="eq" <?php echo (isset($_GET['point_cond']) ? $_GET['point_cond'] : '') === 'eq' ? 'checked' : ''; ?>> 일치</label>
|
||||
</span>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- 차단회원 조건 -->
|
||||
<div class="sch_row">
|
||||
<div class="label">
|
||||
<label><input type="checkbox" name="use_intercept" value="1" <?php echo isset($_GET['use_intercept']) ? 'checked' : ''; ?>> 차단회원</label>
|
||||
</div>
|
||||
<div class="field">
|
||||
<select name="intercept" id="intercept">
|
||||
<?php
|
||||
// 차단회원 옵션 : [정의] get_export_config() - adm/member_list_exel.lib.php
|
||||
foreach (get_export_config('intercept_list') as $val => $label) {
|
||||
$selected = ((isset($_GET['intercept']) ? $_GET['intercept'] : '') === $val) ? 'selected' : '';
|
||||
echo "<option value=\"$val\" $selected>$label</option>";
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- 휴대폰 번호 조건 - 초기세팅(설정에 휴대폰번호가 보이기/필수입력이면 기본값 checked로 설정) -->
|
||||
<div class="sch_row">
|
||||
<div class="label">
|
||||
<label>
|
||||
<?php $use_hp_checked = isset($_GET['token']) ? (isset($_GET['use_hp_exist']) ? 'checked' : '') : (($config['cf_use_hp'] || $config['cf_req_hp']) ? 'checked' : '');?>
|
||||
<input type="checkbox" name="use_hp_exist" value="1" <?php echo $use_hp_checked; ?>> 휴대폰 번호 있는 경우만
|
||||
</label>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- 정보수신동의 조건 -->
|
||||
<div class="sch_row">
|
||||
<div class="label">
|
||||
<label><input type="checkbox" name="ad_range_only" value="1" <?php echo isset($_GET['ad_range_only']) ? 'checked' : ''; ?>> 정보수신동의에 동의한 경우만</label>
|
||||
</div>
|
||||
<!-- 안내 문구 -->
|
||||
<div class="field">
|
||||
<p class="sch_notice">「정보통신망이용촉진및정보보호등에관한법률」에 따라 <b>광고성 정보 수신동의 여부</b>를 <b>매2년</b>마다 확인해야 합니다.</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="sch_row <?php echo isset($_GET['ad_range_only']) ? '' : 'is-hidden'; ?>">
|
||||
<div class="ad_range_wrap">
|
||||
<div class="ad_range_box">
|
||||
<div class="label">
|
||||
<label for="ad_range_type">회원범위</label>
|
||||
</div>
|
||||
<div class="field">
|
||||
<select name="ad_range_type" id="ad_range_type">
|
||||
<?php
|
||||
foreach (get_export_config('ad_range_list') as $val => $label) {
|
||||
$selected = ((isset($_GET['ad_range_type']) ? $_GET['ad_range_type'] : '') === $val) ? 'selected' : '';
|
||||
echo "<option value=\"$val\" $selected>$label</option>";
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
<div class="ad_range_wrap">
|
||||
<!-- 기간 직접 입력 -->
|
||||
<div class="ad_range_box <?php echo isset($_GET['ad_range_only']) && (isset($_GET['ad_range_type']) ? $_GET['ad_range_type'] : '') == 'custom_period' ? '' : 'is-hidden'; ?>">
|
||||
<div class="field">
|
||||
<input type="date" name="agree_date_start" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['agree_date_start']) ? $_GET['agree_date_start'] : date('Y-m-d', strtotime('-1 month'))); ?>"> ~
|
||||
<input type="date" name="agree_date_end" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['agree_date_end']) ? $_GET['agree_date_end'] : date('Y-m-d')); ?>">
|
||||
<p>* 광고성 정보 수신(<b>이메일 또는 SMS/카카오톡</b>) 동의일자 기준</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- 설명 문구 -->
|
||||
<?php
|
||||
$thirdpartyLbl = (!empty($config['cf_sms_use'])) ? ' / <b>개인정보 제3자 제공</b>' : '';
|
||||
|
||||
$ad_range_text = array(
|
||||
'all' => "* <b>광고성 정보 수신(이메일 또는 SMS/카카오톡)</b> / <b>마케팅 목적의 개인정보 수집 및 이용</b>{$thirdpartyLbl}에 모두 동의한 회원을 선택합니다.",
|
||||
'mailling_only' => "* <b>광고성 이메일 수신</b> / <b>마케팅 목적의 개인정보 수집 및 이용</b>{$thirdpartyLbl}에 모두 동의한 회원을 선택합니다.",
|
||||
'sms_only' => "* <b>광고성 SMS/카카오톡 수신</b> / <b>마케팅 목적의 개인정보 수집 및 이용</b>{$thirdpartyLbl}에 모두 동의한 회원을 선택합니다.",
|
||||
'month_confirm' => "* 23개월 전(" . date('Y년 m월', strtotime('-23 month')) . ") <b>광고성 정보 수신 동의(이메일 또는 SMS/카카오톡)</b>한 회원을 선택합니다."
|
||||
);
|
||||
|
||||
if (isset($_GET['ad_range_only'], $_GET['ad_range_type']) && isset($ad_range_text[$_GET['ad_range_type']])) {
|
||||
echo '<div class="ad_range_box"><p>' . $ad_range_text[$_GET['ad_range_type']] . '</p></div>';
|
||||
}
|
||||
?>
|
||||
</div>
|
||||
<br>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- 채널 체크박스 -->
|
||||
<div class="sch_row <?php echo isset($_GET['ad_range_only']) && in_array($_GET['ad_range_type'], array('month_confirm', 'custom_period')) ? '' : 'is-hidden'; ?>">
|
||||
<div class="ad_range_wrap">
|
||||
<div class="ad_range_box">
|
||||
<div class="label">
|
||||
</div>
|
||||
<div class="field">
|
||||
<?php $ad_mailling_checked = isset($_GET['token']) ? (isset($_GET['ad_mailling']) ? 'checked' : '') : 'checked';?>
|
||||
<?php $ad_sms_checked = isset($_GET['token']) ? (isset($_GET['ad_sms']) ? 'checked' : '') : 'checked';?>
|
||||
<label><input type="checkbox" name="ad_mailling" value="1" <?php echo $ad_mailling_checked; ?>> 광고성 이메일 수신</label>
|
||||
<label><input type="checkbox" name="ad_sms" value="1" <?php echo $ad_sms_checked; ?>> 광고성 SMS/카카오톡 수신</label>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="sch_btn">
|
||||
<button type="button" id="btnExcelDownload">엑셀파일 다운로드</button>
|
||||
<button type="button" class="btn_reset" onclick="location.href='?'">초기화</button>
|
||||
</div>
|
||||
</div>
|
||||
</fieldset>
|
||||
</form>
|
||||
|
||||
<script>
|
||||
document.querySelector('input[name="ad_range_only"]').addEventListener('change', function () {
|
||||
document.querySelectorAll('.ad_range_wrap').forEach(el => {
|
||||
el.classList.toggle('is-hidden', !this.checked);
|
||||
});
|
||||
});
|
||||
|
||||
document.querySelectorAll('#fsearch input, #fsearch select').forEach(el => {
|
||||
const submit = () => document.getElementById('fsearch').submit();
|
||||
el.addEventListener(el.type === 'date' ? 'blur' : 'change', submit);
|
||||
|
||||
el.addEventListener('keydown', e => {
|
||||
if (e.key === 'Enter') {
|
||||
e.preventDefault();
|
||||
submit();
|
||||
}
|
||||
});
|
||||
});
|
||||
</script>
|
||||
|
||||
<script>
|
||||
let eventSource = null;
|
||||
|
||||
// 일반 엑셀 다운로드 버튼 클릭
|
||||
document.getElementById('btnExcelDownload').addEventListener('click', () => {
|
||||
startExcelDownload();
|
||||
});
|
||||
|
||||
// 엑셀 다운로드 실행
|
||||
// 1. 기존 SSE 종료
|
||||
function closePreviousEventSource() {
|
||||
if (eventSource) {
|
||||
eventSource.close();
|
||||
eventSource = null;
|
||||
}
|
||||
}
|
||||
|
||||
// 2. FormData QueryString 변환
|
||||
function buildDownloadParams(selectedFields = []) {
|
||||
const formData = new FormData(document.getElementById('fsearch'));
|
||||
const params = new URLSearchParams(formData);
|
||||
|
||||
params.append('mode', 'start');
|
||||
|
||||
return params.toString();
|
||||
}
|
||||
|
||||
// 3. 메인 함수
|
||||
function startExcelDownload(selectedFields = []) {
|
||||
closePreviousEventSource();
|
||||
|
||||
const query = buildDownloadParams(selectedFields);
|
||||
showDownloadPopup();
|
||||
|
||||
eventSource = new EventSource(`member_list_exel_export.php?${query}`);
|
||||
eventSource.onmessage = handleProgressUpdate();
|
||||
eventSource.onerror = handleDownloadError();
|
||||
}
|
||||
|
||||
// 다운로드 팝업 표시
|
||||
function showDownloadPopup() {
|
||||
const bodyHTML = `
|
||||
<div class="excel-download-progress">
|
||||
<div class="progress-desc">
|
||||
<p class="progress-summary">총 <strong>0</strong>개 파일로 분할됩니다</p>
|
||||
<p class="progress-message"><strong>(0 / 0)</strong> 파일 다운로드 중</p>
|
||||
<p class="progress-error"></p>
|
||||
</div>
|
||||
<div class="progress-spinner">
|
||||
<div class="spinner"></div>
|
||||
<p class="loading-message">
|
||||
엑셀 파일을 생성 중입니다. 잠시만 기다려주세요.<br>
|
||||
현재 데이터 기준으로 <strong id="estimatedTimeText"></strong> 정도 소요될 수 있습니다.<br>
|
||||
<strong>페이지를 벗어나거나 닫으면 다운로드가 중단</strong>되니, 작업 완료까지 기다려 주세요.
|
||||
</p>
|
||||
</div>
|
||||
<div class="progress-box">
|
||||
<div class="progress-download-box"></div>
|
||||
</div>
|
||||
</div>
|
||||
`;
|
||||
|
||||
PopupManager.render('엑셀 다운로드 진행 중', bodyHTML, '', { disableOutsideClose: true });
|
||||
|
||||
// 닫기 버튼 이벤트 핸들링
|
||||
const closeBtn = document.querySelector('.popup-close-btn');
|
||||
if (closeBtn) {
|
||||
closeBtn.removeAttribute('onclick');
|
||||
closeBtn.addEventListener('click', handlePopupCloseWithConfirm);
|
||||
}
|
||||
}
|
||||
|
||||
// 닫기 버튼 클릭 시 다운로드 중단 여부 확인
|
||||
function handlePopupCloseWithConfirm(e) {
|
||||
if (eventSource) {
|
||||
const confirmClose = confirm("엑셀 다운로드가 진행 중입니다.\n정말 중지하시겠습니까?");
|
||||
if (!confirmClose) {
|
||||
e.preventDefault();
|
||||
return;
|
||||
}
|
||||
eventSource.close();
|
||||
eventSource = null;
|
||||
alert("엑셀 다운로드가 중단되었습니다.");
|
||||
}
|
||||
PopupManager.close('popupOverlay');
|
||||
}
|
||||
|
||||
// 체크박스 선택 시 최대 3개 제한 및 선택된 항목 미리보기 표시
|
||||
function bindFieldSelectEvents() {
|
||||
const fieldSelectForm = document.getElementById('fieldSelectForm');
|
||||
if (!fieldSelectForm) return;
|
||||
|
||||
fieldSelectForm.addEventListener('change', function (e) {
|
||||
if (e.target.name === 'fields') {
|
||||
const selected = fieldSelectForm.querySelectorAll('input[name="fields"]:checked');
|
||||
if (selected.length > 3) {
|
||||
alert("최대 3개까지 선택 가능합니다.");
|
||||
e.target.checked = false;
|
||||
return;
|
||||
}
|
||||
|
||||
// 선택된 항목 표시
|
||||
const previewContainer = document.getElementById('selectedFieldsPreview');
|
||||
let spans = '<strong>선택된 항목:</strong>';
|
||||
selected.forEach(field => {
|
||||
const label = field.parentElement.textContent.trim();
|
||||
spans += `<span class="field-tag">${label}</span>`;
|
||||
});
|
||||
previewContainer.innerHTML = spans;
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
// 엑셀 생성 및 다운로드 실행
|
||||
function handleProgressUpdate() {
|
||||
return function(e) {
|
||||
const data = JSON.parse(e.data);
|
||||
const { status, downloadType, message, total, current, totalChunks, currentChunk, zipFile, files, filePath } = data;
|
||||
|
||||
// DOM 요소 캐싱
|
||||
const titleEl = document.getElementById('popupTitle');
|
||||
const summaryEl = document.querySelector('.progress-summary');
|
||||
const messageEl = document.querySelector('.progress-message');
|
||||
const spinnerEl = document.querySelector('.progress-spinner');
|
||||
const resultEl = document.querySelector('.loading-message');
|
||||
const downloadBoxEl = document.querySelector('.progress-download-box');
|
||||
const errorEl = document.querySelector('.progress-error');
|
||||
|
||||
if (status === "progress")
|
||||
{
|
||||
summaryEl.innerHTML = `총 <strong>${totalChunks}</strong>개 파일로 ` + (downloadType === 2 ? `분할 생성됩니다` : `다운로드됩니다`) + ` (총 ${total.toLocaleString('ko-KR')}건)`;
|
||||
messageEl.innerHTML = downloadType === 2 ? `<strong>(${currentChunk} / ${totalChunks})</strong> 파일 생성 중` : `엑셀 파일 생성 중`;
|
||||
|
||||
/* 작업 소요 시간 : 예상 시간 (1만건당 10초) */
|
||||
const sec = Math.max(5, Math.ceil(total * 0.0012 * 1.2)); // 최소 5초 보장
|
||||
const text = `예상 처리 시간은 약 ${sec >= 60 ? `${Math.floor(sec / 60)}분 ${sec % 60}초` : `${sec}초`}`;
|
||||
document.getElementById('estimatedTimeText').innerText = text;
|
||||
}
|
||||
else if (status === "zipping")
|
||||
{
|
||||
summaryEl.innerHTML = `총 <strong>${totalChunks}</strong>개 파일이 압축파일로 생성됩니다`;
|
||||
messageEl.innerHTML = `<strong>${totalChunks}</strong> 파일 압축하는 중`;
|
||||
}
|
||||
else if (status === "zippingError")
|
||||
{
|
||||
errorEl.innerHTML = message;
|
||||
}
|
||||
else if (status === "error")
|
||||
{
|
||||
summaryEl.innerHTML = `엑셀 파일 다운로드 실패`;
|
||||
resultEl.innerHTML = '';
|
||||
spinnerEl?.classList.add('is-hidden');
|
||||
|
||||
const parts = message.split(/<br\s*\/?>/i);
|
||||
messageEl.innerHTML = parts[0] || '';
|
||||
errorEl.innerHTML = parts.slice(1).join('<br>') || '';
|
||||
|
||||
// SSE 작업 닫기
|
||||
eventSource?.close();
|
||||
eventSource = null;
|
||||
}
|
||||
else if (status === "done")
|
||||
{
|
||||
// SSE 작업 닫기
|
||||
eventSource?.close();
|
||||
eventSource = null;
|
||||
|
||||
titleEl.textContent = '엑셀 파일 다운로드 완료';
|
||||
messageEl.innerHTML = `<strong>총 ${total.toLocaleString('ko-KR')}건의 데이터 다운로드가 완료되었습니다!</strong>`;
|
||||
spinnerEl?.classList.add('is-hidden');
|
||||
|
||||
let html = '<p>* 자동으로 다운로드가 되지 않았다면 아래 버튼을 클릭해주세요.</p>';
|
||||
const baseUrl = `<?php echo G5_DATA_URL; ?>/member_list/<?php echo date('Ymdhis'); ?>/`; // 공통 URL 분리
|
||||
|
||||
if (zipFile) {
|
||||
const url = `${filePath}/${zipFile}`;
|
||||
html += `<a href="${url}" class="btn btn_03" download>압축파일 다운로드</a>`;
|
||||
downloadBoxEl.innerHTML = html;
|
||||
triggerAutoDownload(url, zipFile);
|
||||
} else if (files?.length) {
|
||||
files.forEach((file, index) => {
|
||||
const url = `${filePath}/${file}`;
|
||||
html += `<a class="btn btn_03" href="${url}" download>엑셀파일 다운로드 ${index + 1}</a>`;
|
||||
});
|
||||
downloadBoxEl.innerHTML = html;
|
||||
|
||||
if (files.length === 1) {
|
||||
const url = `${filePath}/${files[0]}`;
|
||||
triggerAutoDownload(url, files[0]);
|
||||
} else {
|
||||
summaryEl.innerHTML = `총 <strong>${totalChunks}</strong>개 파일이 생성되었습니다. 아래 버튼을 눌러 다운로드 받아주세요.`;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// SSE 오류 처리
|
||||
function handleDownloadError() {
|
||||
return function(e){
|
||||
const errorMessage = e?.message || e?.data || '알 수 없는 오류가 발생했습니다.';
|
||||
|
||||
document.querySelector('.progress-summary').innerHTML = `엑셀 파일 다운로드 실패`;
|
||||
document.querySelector('.progress-message').innerHTML = `엑셀 파일 다운로드에 실패하였습니다`;
|
||||
document.querySelector('.progress-error').innerHTML = errorMessage;
|
||||
document.querySelector('.loading-message').innerHTML = '';
|
||||
document.querySelector('.progress-spinner').classList.add('is-hidden');
|
||||
|
||||
if (eventSource) {
|
||||
eventSource.close();
|
||||
eventSource = null;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 자동 다운로드 실행
|
||||
function triggerAutoDownload(url, filename) {
|
||||
const a = document.createElement('a');
|
||||
a.href = url;
|
||||
a.download = filename;
|
||||
document.body.appendChild(a);
|
||||
a.click();
|
||||
document.body.removeChild(a);
|
||||
}
|
||||
</script>
|
||||
|
||||
<?php
|
||||
require_once './admin.tail.php';
|
||||
@@ -0,0 +1,565 @@
|
||||
<?php
|
||||
$sub_menu = "200400";
|
||||
require_once './_common.php';
|
||||
require_once './member_list_exel.lib.php'; // 회원관리파일 공통 라이브러리 (상수, 검색 옵션 설정, SQL WHERE 등)
|
||||
include_once(G5_LIB_PATH.'/PHPExcel.php');
|
||||
|
||||
check_demo();
|
||||
auth_check_menu($auth, $sub_menu, 'w');
|
||||
|
||||
ini_set('memory_limit', '-1');
|
||||
session_write_close(); // 세션 종료 및 잠금 해제 (백그라운드 작업을 위해 필요)
|
||||
|
||||
// 파라미터 수집 및 유효성 검사
|
||||
$params = get_member_export_params();
|
||||
if (!$params || !is_array($params)) {
|
||||
member_export_send_progress("error", "데이터가 올바르게 전달되지 않아 작업에 실패하였습니다.");
|
||||
member_export_write_log(array(), array('success' => false, 'error' => '데이터가 올바르게 전달되지 않아 작업에 실패하였습니다.'));
|
||||
exit;
|
||||
}
|
||||
|
||||
// 기존 생성된 엑셀 파일 삭제 - LOG 및 오늘 날짜 폴더 제외
|
||||
$resultExcelDelete = member_export_delete();
|
||||
|
||||
// 서버 전송 이벤트(SSE)를 위한 헤더 설정
|
||||
member_export_set_sse_headers();
|
||||
|
||||
// 모드 확인
|
||||
$mode = isset($_GET['mode']) ? $_GET['mode'] : '';
|
||||
if ($mode !== 'start') {
|
||||
member_export_send_progress("error", "잘못된 요청 입니다.");
|
||||
member_export_write_log($params, array('success' => false, 'error' => '잘못된 요청 입니다.'));
|
||||
exit;
|
||||
}
|
||||
|
||||
/**
|
||||
* 회원 내보내기 처리 실행 (예외 처리 포함)
|
||||
*/
|
||||
try {
|
||||
main_member_export($params);
|
||||
}
|
||||
catch (Exception $e)
|
||||
{
|
||||
// 에러 로그 저장 및 SSE 에러 전송
|
||||
error_log("[Member Export Error] " . $e->getMessage());
|
||||
member_export_send_progress("error", $e->getMessage());
|
||||
member_export_write_log($params, array('success' => false, 'error' => $e->getMessage()));
|
||||
}
|
||||
|
||||
/**
|
||||
* 메인 내보내기 프로세스
|
||||
*/
|
||||
function main_member_export($params)
|
||||
{
|
||||
$total = member_export_get_total_count($params);
|
||||
|
||||
if($total > MEMBER_EXPORT_MAX_SIZE){
|
||||
throw new Exception("엑셀 다운로드 가능 범위(최대 " . number_format(MEMBER_EXPORT_MAX_SIZE) . "건)를 초과했습니다.<br>조건을 추가로 설정하신 후 다시 시도해 주세요.");
|
||||
}
|
||||
|
||||
if($total <= 0){
|
||||
throw new Exception("조회된 데이터가 없어 엑셀 파일을 생성할 수 없습니다.<br>조건을 추가로 설정하신 후 다시 시도해 주세요.");
|
||||
}
|
||||
|
||||
$fileName = 'member_'.MEMBER_BASE_DATE;
|
||||
$fileList = array();
|
||||
$zipFileName = '';
|
||||
|
||||
if ($total > MEMBER_EXPORT_PAGE_SIZE) {
|
||||
// 대용량 데이터 - 분할 처리
|
||||
$pages = (int)ceil($total / MEMBER_EXPORT_PAGE_SIZE);
|
||||
member_export_send_progress("progress", "", 2, $total, 0, $pages, 0);
|
||||
|
||||
for ($i = 1; $i <= $pages; $i++) {
|
||||
$params['page'] = $i;
|
||||
|
||||
member_export_send_progress("progress", "", 2, $total, ($pages == $i ? $total : $i * MEMBER_EXPORT_PAGE_SIZE), $pages, $i);
|
||||
try {
|
||||
$data = member_export_get_data($params);
|
||||
$fileList[] = member_export_create_excel($data, $fileName, $i);
|
||||
} catch (Exception $e) {
|
||||
throw new Exception("총 {$pages}개 중 {$i}번째 파일을 생성하지 못했습니다<br>" . $e->getMessage());
|
||||
}
|
||||
}
|
||||
|
||||
// 압축 파일 생성
|
||||
if (count($fileList) > 1) {
|
||||
member_export_send_progress("zipping", "", 2, $total, $total, $pages, $i);
|
||||
$zipResult = member_export_create_zip($fileList, $fileName); // 압축 파일 생성
|
||||
|
||||
if($zipResult['error']){
|
||||
member_export_write_log($params, array('success' => false, 'error' => $zipResult['error']));
|
||||
member_export_send_progress("zippingError", $zipResult['error']);
|
||||
}
|
||||
|
||||
if ($zipResult && $zipResult['result']) {
|
||||
member_export_delete($fileList); // 압축 후 엑셀 파일 제거
|
||||
$zipFileName = $zipResult['zipFile'];
|
||||
}
|
||||
}
|
||||
|
||||
} else {
|
||||
// 소용량 데이터 - 단일 파일
|
||||
member_export_send_progress("progress", "", 1, $total, 0);
|
||||
$data = member_export_get_data($params);
|
||||
member_export_send_progress("progress", "", 1, $total, $total/2);
|
||||
$fileList[] = member_export_create_excel($data, $fileName, 0);
|
||||
member_export_send_progress("progress", "", 1, $total, $total);
|
||||
}
|
||||
|
||||
member_export_write_log($params, array('success' => true, 'total' => $total, 'files' => $fileList, 'zip' => isset($zipFileName) ? $zipFileName : null));
|
||||
member_export_send_progress("done", "", 2, $total, $total, $pages, $pages, $fileList, $zipFileName);
|
||||
}
|
||||
|
||||
/**
|
||||
* 진행률 전송
|
||||
*/
|
||||
function member_export_send_progress($status, $message = "", $downloadType = 1, $total = 1, $current = 1, $totalChunks = 1, $currentChunk = 1, $files = array(), $zipFile = '')
|
||||
{
|
||||
// 연결 상태 확인
|
||||
if (connection_aborted()) return;
|
||||
|
||||
$data = array(
|
||||
'status' => $status,
|
||||
'message' => $message,
|
||||
'downloadType' => $downloadType,
|
||||
'total' => $total,
|
||||
'current' => $current,
|
||||
'totalChunks' => $totalChunks,
|
||||
'currentChunk' => $currentChunk,
|
||||
'files' => $files,
|
||||
'zipFile' => $zipFile,
|
||||
'filePath' => G5_DATA_URL . "/" . MEMBER_BASE_DIR . "/" . MEMBER_BASE_DATE,
|
||||
);
|
||||
|
||||
$json_options = defined('JSON_UNESCAPED_UNICODE') ? JSON_UNESCAPED_UNICODE : 0;
|
||||
echo "data: " . json_encode($data, $json_options) . "\n\n";
|
||||
|
||||
// 더 안정적인 플러시
|
||||
if (ob_get_level()) ob_end_flush();
|
||||
flush();
|
||||
}
|
||||
|
||||
/**
|
||||
* 엑셀 내보내기 설정
|
||||
*/
|
||||
function member_export_get_config()
|
||||
{
|
||||
$type = 1;
|
||||
$configs = array(
|
||||
1 => array(
|
||||
'title' => array("회원관리파일(일반)"),
|
||||
'headers' => array('아이디', '이름', '닉네임', '휴대폰번호', '전화번호', '이메일', '주소', '회원권한', '포인트', '가입일', '차단',
|
||||
'광고성 이메일 수신동의', '광고성 이메일 동의일자', '광고성 SMS/카카오톡 수신동의', '광고성 SMS/카카오톡 동의일자',
|
||||
'마케팅목적의개인정보수집및이용동의', '마케팅목적의개인정보수집및이용동의일자', '개인정보제3자제공동의', '개인정보제3자제공동의일자'),
|
||||
'fields' => array('mb_id', 'mb_name', 'mb_nick', 'mb_hp', 'mb_tel', 'mb_email', 'mb_addr1', 'mb_level', 'mb_point', 'mb_datetime', 'mb_intercept_date',
|
||||
'mb_mailling','mb_mailling_date', 'mb_sms','mb_sms_date', 'mb_marketing_agree',
|
||||
'mb_marketing_date', 'mb_thirdparty_agree', 'mb_thirdparty_date'),
|
||||
'widths' => array(20, 20, 20, 20, 20, 30, 30, 10, 15, 25, 10, 20, 25, 20, 25, 20, 25, 20, 25),
|
||||
),
|
||||
);
|
||||
|
||||
return isset($configs[$type]) ? $configs[$type] : $configs[1];
|
||||
}
|
||||
|
||||
/**
|
||||
* SSE 헤더 설정
|
||||
*/
|
||||
function member_export_set_sse_headers()
|
||||
{
|
||||
header('Content-Type: text/event-stream');
|
||||
header('Cache-Control: no-cache');
|
||||
header('Connection: keep-alive');
|
||||
header('X-Accel-Buffering: no');
|
||||
|
||||
if (ob_get_level()) ob_end_flush();
|
||||
ob_implicit_flush(true);
|
||||
}
|
||||
|
||||
/**
|
||||
* 엑셀 컬럼 문자 반환
|
||||
*/
|
||||
function member_export_column_char($i)
|
||||
{
|
||||
return chr(65 + $i);
|
||||
}
|
||||
|
||||
/**
|
||||
* 회원 데이터 조회
|
||||
*/
|
||||
function member_export_get_data($params)
|
||||
{
|
||||
global $g5;
|
||||
|
||||
$config = member_export_get_config();
|
||||
$fields = $config['fields'];
|
||||
$fields = array_unique($fields);
|
||||
|
||||
// SQL 변환 맵 (가공이 필요한 필드만 정의)
|
||||
$sqlTransformMap = array(
|
||||
'mb_datetime' => "IF(mb_datetime = '0000-00-00 00:00:00', '', mb_datetime) AS mb_datetime",
|
||||
'mb_intercept_date' => "IF(mb_intercept_date != '', '차단됨', '정상') AS mb_intercept_date",
|
||||
'mb_sms' => "IF(mb_sms = '1', '동의', '미동의') AS mb_sms",
|
||||
'mb_sms_date' => "IF(mb_sms != '1' OR mb_sms_date = '0000-00-00 00:00:00', '', mb_sms_date) AS mb_sms_date",
|
||||
'mb_mailling' => "IF(mb_mailling = '1', '동의', '미동의') AS mb_mailling",
|
||||
'mb_mailling_date' => "IF(mb_mailling != '1' OR mb_mailling_date = '0000-00-00 00:00:00', '', mb_mailling_date) AS mb_mailling_date",
|
||||
'mb_marketing_agree' => "IF(mb_marketing_agree = '1', '동의', '미동의') AS mb_marketing_agree",
|
||||
'mb_marketing_date' => "IF(mb_marketing_agree != '1' OR mb_marketing_date = '0000-00-00 00:00:00', '', mb_marketing_date) AS mb_marketing_date",
|
||||
'mb_thirdparty_agree' => "IF(mb_thirdparty_agree = '1', '동의', '미동의') AS mb_thirdparty_agree",
|
||||
'mb_thirdparty_date' => "IF(mb_thirdparty_agree != '1' OR mb_thirdparty_date = '0000-00-00 00:00:00', '', mb_thirdparty_date) AS mb_thirdparty_date",
|
||||
);
|
||||
|
||||
// SQL 필드 생성
|
||||
$sqlFields = array();
|
||||
foreach ($fields as $field) {
|
||||
$sqlFields[] = isset($sqlTransformMap[$field]) ? $sqlTransformMap[$field] : $field;
|
||||
}
|
||||
$field_list = implode(', ', $sqlFields);
|
||||
|
||||
$where = member_export_build_where($params);
|
||||
|
||||
$page = (int)(isset($params['page']) ? $params['page'] : 1);
|
||||
if ($page < 1) $page = 1;
|
||||
$offset = ($page - 1) * MEMBER_EXPORT_PAGE_SIZE;
|
||||
|
||||
$sql = "SELECT {$field_list} FROM {$g5['member_table']} {$where} ORDER BY mb_no DESC LIMIT {$offset}, " . MEMBER_EXPORT_PAGE_SIZE;
|
||||
|
||||
$result = sql_query($sql);
|
||||
if (!$result) {
|
||||
throw new Exception("데이터 조회에 실패하였습니다");
|
||||
}
|
||||
|
||||
$excelData = array($config['title'], $config['headers']);
|
||||
|
||||
while ($row = sql_fetch_array($result)) {
|
||||
$rowData = array();
|
||||
foreach ($fields as $field) {
|
||||
if (isset($row[$field])) {
|
||||
$rowData[] = function_exists('csv_safe_cell') ? csv_safe_cell($row[$field]) : $row[$field];
|
||||
} else {
|
||||
$rowData[] = '';
|
||||
}
|
||||
}
|
||||
$excelData[] = $rowData;
|
||||
}
|
||||
|
||||
return $excelData;
|
||||
}
|
||||
|
||||
/**
|
||||
* 엑셀 파일 생성
|
||||
*/
|
||||
function member_export_create_excel($data, $fileName, $index = 0)
|
||||
{
|
||||
$config = member_export_get_config();
|
||||
|
||||
if (!class_exists('PHPExcel')) {
|
||||
error_log('[Member Export Error] PHPExcel 라이브러리를 찾을 수 없습니다.');
|
||||
throw new Exception('파일 생성 중 내부 오류가 발생했습니다: PHPExcel 라이브러리를 찾을 수 없습니다.');
|
||||
}
|
||||
|
||||
// 현재 설정값 백업
|
||||
$currentCache = PHPExcel_Settings::getCacheStorageMethod();
|
||||
|
||||
// 캐싱 모드 설정 (엑셀 생성 전용)
|
||||
$cacheMethods = array(
|
||||
PHPExcel_CachedObjectStorageFactory::cache_to_discISAM,
|
||||
PHPExcel_CachedObjectStorageFactory::cache_in_memory_serialized
|
||||
);
|
||||
|
||||
foreach ($cacheMethods as $method) {
|
||||
if (PHPExcel_Settings::setCacheStorageMethod($method)) {
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
try {
|
||||
$excel = new PHPExcel();
|
||||
$sheet = $excel->setActiveSheetIndex(0);
|
||||
|
||||
// 헤더 스타일 적용
|
||||
$last_char = member_export_column_char(count($config['headers']) - 1);
|
||||
$sheet->getStyle("A2:{$last_char}2")->applyFromArray(array(
|
||||
'fill' => array(
|
||||
'type' => PHPExcel_Style_Fill::FILL_SOLID,
|
||||
'startcolor' => array('rgb' => 'D9E1F2'), // 연파랑 배경
|
||||
),
|
||||
));
|
||||
|
||||
// 셀 정렬 및 줄바꿈 설정
|
||||
$sheet->getStyle("A:{$last_char}")->getAlignment()->setVertical(PHPExcel_Style_Alignment::VERTICAL_CENTER)->setWrapText(true);
|
||||
|
||||
// 컬럼 너비 설정
|
||||
foreach ($config['widths'] as $i => $width) {
|
||||
$sheet->getColumnDimension(member_export_column_char($i))->setWidth($width);
|
||||
}
|
||||
|
||||
// 데이터 입력
|
||||
$sheet->fromArray($data, NULL, 'A1');
|
||||
|
||||
// 디렉토리 확인
|
||||
member_export_ensure_directory(MEMBER_EXPORT_DIR);
|
||||
|
||||
// 파일명 생성
|
||||
$subname = $index == 0 ? 'all' : sprintf("%02d", $index);
|
||||
$filename = $fileName . "_" . $subname . ".xlsx";
|
||||
$filePath = MEMBER_EXPORT_DIR . "/" . $filename;
|
||||
|
||||
// 파일 저장
|
||||
$writer = PHPExcel_IOFactory::createWriter($excel, 'Excel2007');
|
||||
$writer->setPreCalculateFormulas(false);
|
||||
$writer->save($filePath);
|
||||
|
||||
unset($excel, $sheet, $writer); // 생성 완료 후 메모리 해제
|
||||
}
|
||||
catch (Exception $e)
|
||||
{
|
||||
if ($currentCache) {
|
||||
PHPExcel_Settings::setCacheStorageMethod($currentCache);
|
||||
}
|
||||
throw new Exception("엑셀 파일 생성에 실패하였습니다: " . $e->getMessage());
|
||||
}
|
||||
|
||||
// 캐싱 모드 원래 상태로 복원
|
||||
if ($currentCache) {
|
||||
PHPExcel_Settings::setCacheStorageMethod($currentCache);
|
||||
}
|
||||
|
||||
return $filename;
|
||||
}
|
||||
|
||||
/**
|
||||
* 압축 파일 생성
|
||||
*/
|
||||
function member_export_create_zip($files, $zipFileName)
|
||||
{
|
||||
if (!class_exists('ZipArchive')) {
|
||||
error_log('[Member Export Error] ZipArchive 클래스를 사용할 수 없습니다.');
|
||||
return array('error' => '파일을 압축하는 중 문제가 발생했습니다. 개별 파일로 제공됩니다.<br>: ZipArchive 클래스를 사용할 수 없습니다.');
|
||||
}
|
||||
|
||||
member_export_ensure_directory(MEMBER_EXPORT_DIR);
|
||||
$destinationZipPath = rtrim(MEMBER_EXPORT_DIR, "/") . "/" . $zipFileName . ".zip";
|
||||
|
||||
$zip = new ZipArchive();
|
||||
if ($zip->open($destinationZipPath, ZipArchive::CREATE | ZipArchive::OVERWRITE) !== TRUE) {
|
||||
return array('error' => "파일을 압축하는 중 문제가 발생했습니다. 개별 파일로 제공됩니다.");
|
||||
}
|
||||
|
||||
foreach ($files as $file) {
|
||||
$filePath = MEMBER_EXPORT_DIR . "/" . $file;
|
||||
if (file_exists($filePath)) {
|
||||
$zip->addFile($filePath, basename($filePath));
|
||||
}
|
||||
}
|
||||
|
||||
$result = $zip->close();
|
||||
|
||||
return array(
|
||||
'result' => $result,
|
||||
'zipFile' => $zipFileName . ".zip",
|
||||
'zipPath' => $destinationZipPath,
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* 디렉토리 생성 및 확인
|
||||
*/
|
||||
function member_export_ensure_directory($dir)
|
||||
{
|
||||
if (!is_dir($dir)) {
|
||||
if (!@mkdir($dir, G5_DIR_PERMISSION, true)) {
|
||||
throw new Exception("디렉토리 생성 실패");
|
||||
}
|
||||
@chmod($dir, G5_DIR_PERMISSION);
|
||||
}
|
||||
|
||||
if (!is_writable($dir)) {
|
||||
throw new Exception("디렉토리 쓰기 권한 없음");
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* 파일 삭제 - 값이 있으면 해당 파일만 삭제, 없으면 디렉토리 내 모든 파일 삭제
|
||||
* - 알집 생성 완료 시 엑셀 파일 제거
|
||||
* - 작업 전 오늘 날짜 폴더 및 log 폴더를 제외한 나머지 파일 모두 제거
|
||||
*/
|
||||
function member_export_delete($fileList = array())
|
||||
{
|
||||
$cnt = 0;
|
||||
|
||||
// 파일 리스트가 있는 경우 -> 해당 파일만 삭제
|
||||
if (!empty($fileList)) {
|
||||
foreach ($fileList as $file) {
|
||||
$filePath = rtrim(MEMBER_EXPORT_DIR, DIRECTORY_SEPARATOR) . DIRECTORY_SEPARATOR . $file;
|
||||
if (file_exists($filePath) && is_file($filePath) && @unlink($filePath)) {
|
||||
$cnt++;
|
||||
}
|
||||
}
|
||||
}
|
||||
// 파일 리스트가 없는 경우 -> 디렉토리 내 모든 파일 삭제
|
||||
else {
|
||||
$files = glob(rtrim(G5_DATA_PATH . "/" . MEMBER_BASE_DIR, '/') . '/*');
|
||||
|
||||
function deleteFolder($dir) {
|
||||
foreach (glob($dir . '/{.,}*', GLOB_BRACE) as $item) {
|
||||
if (in_array(basename($item), array('.', '..'))) continue;
|
||||
is_dir($item) ? deleteFolder($item) : unlink($item);
|
||||
}
|
||||
rmdir($dir);
|
||||
}
|
||||
|
||||
foreach ($files as $file) {
|
||||
$name = basename($file);
|
||||
|
||||
// log 폴더와 오늘 날짜로 시작하는 폴더는 제외
|
||||
if ($name === 'log' || preg_match('/^' . date('Ymd') . '\d{6}$/', $name)) continue;
|
||||
|
||||
if (is_file($file) && pathinfo($file, PATHINFO_EXTENSION) !== 'log' && @unlink($file)) {
|
||||
$cnt++;
|
||||
} elseif (is_dir($file)) {
|
||||
deleteFolder($file); // 재귀 폴더 삭제 함수 사용
|
||||
$cnt++;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return $cnt;
|
||||
}
|
||||
|
||||
/**
|
||||
* 로그 작성
|
||||
*/
|
||||
function member_export_write_log($params, $result = array())
|
||||
{
|
||||
global $member;
|
||||
|
||||
$maxSize = 1024 * 1024 * 2; // 2MB
|
||||
$maxFiles = 10; // 최대 로그 파일 수 (필요시 조정)
|
||||
$username = isset($member['mb_id']) ? $member['mb_id'] : 'guest';
|
||||
$datetime = date("Y-m-d H:i:s");
|
||||
|
||||
if (!is_dir(MEMBER_LOG_DIR)) {
|
||||
@mkdir(MEMBER_LOG_DIR, G5_DIR_PERMISSION, true);
|
||||
@chmod(MEMBER_LOG_DIR, G5_DIR_PERMISSION);
|
||||
}
|
||||
|
||||
$logFiles = glob(MEMBER_LOG_DIR . "/export_log_*.log");
|
||||
if (!$logFiles) {
|
||||
$logFiles = array();
|
||||
}
|
||||
|
||||
// 최신 파일 기준 정렬 (최신 → 오래된)
|
||||
usort($logFiles, 'member_export_compare_log_mtime');
|
||||
|
||||
$latestLogFile = isset($logFiles[0]) ? $logFiles[0] : null;
|
||||
|
||||
// 용량 기준으로 새 파일 생성
|
||||
if (!$latestLogFile || filesize($latestLogFile) >= $maxSize) {
|
||||
$latestLogFile = MEMBER_LOG_DIR . "/export_log_" . date("YmdHi") . ".log";
|
||||
file_put_contents($latestLogFile, '');
|
||||
array_unshift($logFiles, $latestLogFile);
|
||||
}
|
||||
|
||||
// 최대 파일 수 초과 시 오래된 파일 제거
|
||||
if (count($logFiles) > $maxFiles) {
|
||||
$filesToDelete = array_slice($logFiles, $maxFiles);
|
||||
foreach ($filesToDelete as $file) {
|
||||
@unlink($file);
|
||||
}
|
||||
}
|
||||
|
||||
$success = isset($result['success']) && $result['success'] === true;
|
||||
$status = $success ? '성공' : '실패';
|
||||
|
||||
// 조건 정리
|
||||
$condition = array();
|
||||
|
||||
// 검색 조건
|
||||
if ($params['use_stx'] == 1 && !empty($params['stx'])) {
|
||||
$sfl_list = get_export_config('sfl_list');
|
||||
|
||||
$label = isset($sfl_list[$params['sfl']]) ? $sfl_list[$params['sfl']] : '';
|
||||
$condition[] = "검색({$params['stx_cond']}) : {$label} - {$params['stx']}";
|
||||
}
|
||||
|
||||
// 레벨 조건
|
||||
if ($params['use_level'] == 1 && ($params['level_start'] || $params['level_end'])) {
|
||||
$condition[] = "레벨: {$params['level_start']}~{$params['level_end']}";
|
||||
}
|
||||
|
||||
// 가입일 조건
|
||||
if ($params['use_date'] == 1 && ($params['date_start'] || $params['date_end'])) {
|
||||
$condition[] = "가입일: {$params['date_start']}~{$params['date_end']}";
|
||||
}
|
||||
|
||||
// 포인트 조건
|
||||
if ($params['use_point'] == 1 && $params['point'] !== '') {
|
||||
$point_cond_map = get_export_config('point_cond_map');
|
||||
$symbol = isset($point_cond_map[$params['point_cond']]) ? $point_cond_map[$params['point_cond']] : '≥';
|
||||
$condition[] = "포인트 {$symbol} {$params['point']}";
|
||||
}
|
||||
|
||||
// 휴대폰 여부
|
||||
if ($params['use_hp_exist'] == 1) {
|
||||
$condition[] = "휴대폰번호 있는 경우만";
|
||||
}
|
||||
|
||||
// 광고 수신 동의
|
||||
if ($params['ad_range_only'] == 1) {
|
||||
$ad_range_list = get_export_config('ad_range_list');
|
||||
$label = isset($ad_range_list[$params['ad_range_type']]) ? $ad_range_list[$params['ad_range_type']] : '';
|
||||
$condition[] = "수신동의: 예 ({$label})";
|
||||
|
||||
if ($params['ad_range_type'] == "custom_period" && ($params['agree_date_start'] || $params['agree_date_end'])) {
|
||||
$condition[] = "수신동의일: {$params['agree_date_start']}~{$params['agree_date_end']}";
|
||||
}
|
||||
|
||||
if (in_array($params['ad_range_type'], array("month_confirm", "custom_period"))){
|
||||
$channels = array_filter(array(
|
||||
!empty($params['ad_mailling']) && (int)$params['ad_mailling'] === 1 ? '이메일' : null,
|
||||
!empty($params['ad_sms']) && (int)$params['ad_sms'] === 1 ? 'SMS/카카오톡' : null,
|
||||
));
|
||||
|
||||
if ($channels) {
|
||||
$condition[] = '수신채널: ' . implode(', ', $channels);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 차단회원 처리
|
||||
if ($params['use_intercept'] == 1) {
|
||||
$intercept_list = get_export_config('intercept_list');
|
||||
$label = isset($intercept_list[$params['intercept']]) ? $intercept_list[$params['intercept']] : '';
|
||||
if ($label) $condition[] = $label;
|
||||
}
|
||||
|
||||
$conditionStr = !empty($condition) ? implode(', ', $condition) : '없음';
|
||||
$line1 = "[{$datetime}] [{$status}] 관리자: {$username}";
|
||||
|
||||
// 성공일 경우 추가 정보
|
||||
if ($success) {
|
||||
$total = isset($result['total']) ? $result['total'] : 0;
|
||||
$fileCount = isset($result['zip']) ? 1 : count(isset($result['files']) ? $result['files'] : array());
|
||||
$line1 .= " | 총 {$total}건 | 파일: {$fileCount}개";
|
||||
}
|
||||
|
||||
$logEntry = $line1 . PHP_EOL;
|
||||
$logEntry .= "조건: {$conditionStr}" . PHP_EOL;
|
||||
|
||||
if (!$success && !empty($result['error'])) {
|
||||
$logEntry .= "오류 메시지: {$result['error']}" . PHP_EOL;
|
||||
}
|
||||
|
||||
$logEntry .= PHP_EOL;
|
||||
|
||||
// 파일에 기록
|
||||
if (@file_put_contents($latestLogFile, $logEntry, FILE_APPEND | LOCK_EX) === false) {
|
||||
error_log("[Member Export Error] 로그 파일 기록 실패: {$latestLogFile}");
|
||||
}
|
||||
}
|
||||
|
||||
function member_export_compare_log_mtime($a, $b)
|
||||
{
|
||||
return filemtime($b) - filemtime($a);
|
||||
}
|
||||
@@ -0,0 +1,72 @@
|
||||
<?php
|
||||
$sub_menu = '100930';
|
||||
include_once('./_common.php');
|
||||
|
||||
if ($is_admin != 'super')
|
||||
alert('최고관리자만 접근 가능합니다.', G5_URL);
|
||||
|
||||
$g5['title'] = '회원관리파일 일괄삭제';
|
||||
include_once(G5_ADMIN_PATH.'/admin.head.php');
|
||||
?>
|
||||
|
||||
<div class="local_desc02 local_desc">
|
||||
<p>
|
||||
완료 메세지가 나오기 전에 프로그램의 실행을 중지하지 마십시오.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<?php
|
||||
flush();
|
||||
|
||||
if (!$dir = @opendir(G5_DATA_PATH . '/member_list')) {
|
||||
echo '<p>회원관리파일를 열지못했습니다.</p>';
|
||||
}
|
||||
|
||||
$cnt = 0;
|
||||
echo '<ul class="session_del">' . PHP_EOL;
|
||||
|
||||
$files = glob(G5_DATA_PATH . '/member_list/*');
|
||||
$cnt = 0;
|
||||
|
||||
// 폴더 및 하위 파일 재귀 삭제 함수
|
||||
function deleteFolder($folderPath) {
|
||||
$items = glob($folderPath . '/*');
|
||||
foreach ($items as $item) {
|
||||
if (is_dir($item)) {
|
||||
deleteFolder($item);
|
||||
} else {
|
||||
unlink($item);
|
||||
}
|
||||
}
|
||||
rmdir($folderPath); // 폴더 자체 삭제
|
||||
}
|
||||
|
||||
if (is_array($files)) {
|
||||
foreach ($files as $member_list_file) {
|
||||
// log 확장자가 아닌 파일/디렉토리 처리
|
||||
$ext = strtolower(pathinfo($member_list_file, PATHINFO_EXTENSION));
|
||||
$basename = basename($member_list_file);
|
||||
|
||||
if (is_file($member_list_file) && $ext !== 'log') {
|
||||
unlink($member_list_file);
|
||||
echo '<li>파일 삭제: ' . $member_list_file . '</li>' . PHP_EOL;
|
||||
$cnt++;
|
||||
} elseif (is_dir($member_list_file) && $basename !== 'log') {
|
||||
deleteFolder($member_list_file);
|
||||
echo '<li>폴더 삭제: ' . $member_list_file . '</li>' . PHP_EOL;
|
||||
$cnt++;
|
||||
}
|
||||
|
||||
flush();
|
||||
|
||||
if ($cnt % 10 == 0) {
|
||||
echo PHP_EOL;
|
||||
}
|
||||
}
|
||||
}
|
||||
echo '<li>완료됨</li></ul>' . PHP_EOL;
|
||||
echo '<div class="local_desc01 local_desc"><p><strong>회원관리파일 ' . $cnt . '건 삭제 완료됐습니다.</strong><br>프로그램의 실행을 끝마치셔도 좋습니다.</p></div>' . PHP_EOL;
|
||||
?>
|
||||
|
||||
<?php
|
||||
include_once(G5_ADMIN_PATH.'/admin.tail.php');
|
||||
@@ -27,12 +27,38 @@ if ($_POST['act_button'] == "선택수정") {
|
||||
$post_mb_sms = isset($_POST['mb_sms'][$k]) ? (int) $_POST['mb_sms'][$k] : 0;
|
||||
$post_mb_open = isset($_POST['mb_open'][$k]) ? (int) $_POST['mb_open'][$k] : 0;
|
||||
|
||||
$agree_items = array();
|
||||
// 광고성 이메일 수신동의 일자 추가
|
||||
$post_mb_mailling_default = isset($_POST['mb_mailling_default'][$k]) ? (int) $_POST['mb_mailling_default'][$k] : 0;
|
||||
$sql_mailling_date = "";
|
||||
if ($post_mb_mailling_default != $post_mb_mailling) {
|
||||
$sql_mailling_date = " , mb_mailling_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "광고성 이메일 수신(" . ($post_mb_mailling == 1 ? "동의" : "철회") . ")";
|
||||
}
|
||||
|
||||
// 광고성 SMS/카카오톡 수신동의 일자 추가
|
||||
$post_mb_sms_default = isset($_POST['mb_sms_default'][$k]) ? (int) $_POST['mb_sms_default'][$k] : 0;
|
||||
$sql_sms_date = "";
|
||||
if ($post_mb_sms_default != $post_mb_sms) {
|
||||
$sql_sms_date = " , mb_sms_date = '".G5_TIME_YMDHIS."' ";
|
||||
$agree_items[] = "광고성 SMS/카카오톡 수신(" . ($post_mb_sms == 1 ? "동의" : "철회") . ")";
|
||||
}
|
||||
|
||||
// 동의 로그 추가
|
||||
$sql_agree_log = "";
|
||||
if (!empty($agree_items)) {
|
||||
$agree_log = "[".G5_TIME_YMDHIS.", 회원관리 선택수정] " . implode(' | ', $agree_items) . "\n";
|
||||
$sql_agree_log .= " , mb_agree_log = CONCAT('{$agree_log}', IFNULL(mb_agree_log, ''))";
|
||||
}
|
||||
|
||||
$mb_datas[] = $mb = get_member($_POST['mb_id'][$k]);
|
||||
|
||||
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
|
||||
$msg .= $mb['mb_id'] . ' : 회원자료가 존재하지 않습니다.\\n';
|
||||
} elseif ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level']) {
|
||||
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 회원은 수정할 수 없습니다.\\n';
|
||||
} elseif ($is_admin != 'super' && $post_mb_level >= (int) $member['mb_level']) {
|
||||
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.\\n';
|
||||
} elseif ($member['mb_id'] == $mb['mb_id']) {
|
||||
$msg .= $mb['mb_id'] . ' : 로그인 중인 관리자는 수정 할 수 없습니다.\\n';
|
||||
} else {
|
||||
@@ -50,6 +76,9 @@ if ($_POST['act_button'] == "선택수정") {
|
||||
mb_open = '" . $post_mb_open . "',
|
||||
mb_certify = '" . sql_real_escape_string($post_mb_certify) . "',
|
||||
mb_adult = '{$mb_adult}'
|
||||
{$sql_mailling_date}
|
||||
{$sql_sms_date}
|
||||
{$sql_agree_log}
|
||||
where mb_id = '" . sql_real_escape_string($mb['mb_id']) . "' ";
|
||||
sql_query($sql);
|
||||
}
|
||||
|
||||
+13
-1
@@ -117,6 +117,15 @@ if ($new == 'new' || !$code) {
|
||||
});
|
||||
});
|
||||
|
||||
function htmlEscape(str) {
|
||||
return str
|
||||
.replace(/&/g, '&')
|
||||
.replace(/</g, '<')
|
||||
.replace(/>/g, '>')
|
||||
.replace(/"/g, '"')
|
||||
.replace(/'/g, ''');
|
||||
}
|
||||
|
||||
function add_menu_list(name, link, code) {
|
||||
var $menulist = $("#menulist", opener.document);
|
||||
var ms = new Date().getTime();
|
||||
@@ -126,7 +135,10 @@ if ($new == 'new' || !$code) {
|
||||
<?php } else { ?>
|
||||
sub_menu_class = " class=\"td_category sub_menu_class\"";
|
||||
<?php } ?>
|
||||
|
||||
|
||||
name = htmlEscape(name);
|
||||
link = htmlEscape(link);
|
||||
|
||||
var list = "<tr class=\"menu_list menu_group_<?php echo $code; ?>\">";
|
||||
list += "<td" + sub_menu_class + ">";
|
||||
list += "<label for=\"me_name_" + ms + "\" class=\"sound_only\">메뉴<strong class=\"sound_only\"> 필수</strong></label>";
|
||||
|
||||
@@ -30,7 +30,7 @@ for ($i = 0; $i < $count; $i++) {
|
||||
|
||||
$code = is_array($_POST['code']) ? strip_tags($_POST['code'][$i]) : '';
|
||||
$me_name = is_array($_POST['me_name']) ? strip_tags($_POST['me_name'][$i]) : '';
|
||||
$me_link = (preg_match('/^javascript/i', $_POST['me_link'][$i]) || preg_match('/script:/i', $_POST['me_link'][$i])) ? G5_URL : strip_tags(clean_xss_attributes($_POST['me_link'][$i]));
|
||||
$me_link = (preg_match('/^javascript/i', $_POST['me_link'][$i]) || preg_match('/script:/i', $_POST['me_link'][$i])) ? G5_URL : addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['me_link'][$i]))));
|
||||
|
||||
if (!$code || !$me_name || !$me_link) {
|
||||
continue;
|
||||
|
||||
@@ -16,7 +16,7 @@ if ($w == 'd') {
|
||||
|
||||
check_admin_token();
|
||||
|
||||
$nw_subject = isset($_POST['nw_subject']) ? strip_tags(clean_xss_attributes($_POST['nw_subject'])) : '';
|
||||
$nw_subject = isset($_POST['nw_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['nw_subject'])))) : '';
|
||||
$posts = array();
|
||||
|
||||
$check_keys = array(
|
||||
@@ -37,7 +37,7 @@ foreach ($check_keys as $key => $val) {
|
||||
if ($val === 'int') {
|
||||
$posts[$key] = isset($_POST[$key]) ? (int) $_POST[$key] : 0;
|
||||
} elseif ($val === 'str') {
|
||||
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : 0;
|
||||
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : 0;
|
||||
} else {
|
||||
$posts[$key] = isset($_POST[$key]) ? trim($_POST[$key]) : 0;
|
||||
}
|
||||
|
||||
+4
-1
@@ -25,6 +25,9 @@ if (!$sst) {
|
||||
$sst = "po_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('po_id', 'mb_id', 'po_content', 'po_point', 'po_datetime');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'po_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
@@ -66,7 +69,7 @@ if ($config['cf_point_term'] > 0) {
|
||||
$po_expire_term = $config['cf_point_term'];
|
||||
}
|
||||
|
||||
if (strstr($sfl, "mb_id")) {
|
||||
if (strpos($sfl, "mb_id") !== false) {
|
||||
$mb_id = $stx;
|
||||
} else {
|
||||
$mb_id = "";
|
||||
|
||||
@@ -43,11 +43,16 @@ foreach ($_POST as $key => $value) {
|
||||
}
|
||||
|
||||
if (in_array($key, $check_keys)) {
|
||||
$_POST[$key] = strip_tags(clean_xss_attributes($value));
|
||||
if (preg_match('/^po_cnt[1-9]$/', $key) || in_array($key, array('po_level', 'po_point', 'po_id'), true)) {
|
||||
$_POST[$key] = (int) $value;
|
||||
} else {
|
||||
$_POST[$key] = addslashes(strip_tags(clean_xss_attributes(stripslashes($value))));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
$po_id = isset($_POST['po_id']) ? $_POST['po_id'] : '';
|
||||
$po_id = isset($_POST['po_id']) ? (int) $_POST['po_id'] : 0;
|
||||
$_POST['po_use'] = isset($_POST['po_use']) ? (int) $_POST['po_use'] : 0;
|
||||
|
||||
if ($w == '') {
|
||||
$sql = " insert {$g5['poll_table']}
|
||||
|
||||
@@ -21,6 +21,9 @@ if (!$sst) {
|
||||
$sst = "po_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('po_id', 'po_subject', 'po_level', 'po_use', 'po_etc');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'po_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
|
||||
@@ -6,6 +6,8 @@ auth_check_menu($auth, $sub_menu, 'r');
|
||||
|
||||
// 체크된 자료 삭제
|
||||
if (isset($_POST['chk']) && is_array($_POST['chk'])) {
|
||||
check_admin_token();
|
||||
|
||||
for ($i = 0; $i < count($_POST['chk']); $i++) {
|
||||
$pp_id = (int) $_POST['chk'][$i];
|
||||
|
||||
@@ -36,6 +38,9 @@ if (!$sst) {
|
||||
$sst = "pp_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('pp_id', 'pp_word', 'pp_date', 'pp_ip');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'pp_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
|
||||
@@ -15,12 +15,18 @@ $qaconfig = get_qa_config();
|
||||
$check_keys = array('qa_title', 'qa_category', 'qa_skin', 'qa_mobile_skin', 'qa_use_email', 'qa_req_email', 'qa_use_hp', 'qa_req_hp', 'qa_use_sms', 'qa_send_number', 'qa_admin_hp', 'qa_admin_email', 'qa_subject_len', 'qa_mobile_subject_len', 'qa_page_rows', 'qa_mobile_page_rows', 'qa_image_width', 'qa_upload_size');
|
||||
|
||||
foreach ($check_keys as $key) {
|
||||
$$key = $_POST[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
|
||||
$$key = $_POST[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
|
||||
}
|
||||
|
||||
$qa_include_head = isset($qa_include_head) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_head, 0, 255)) : '';
|
||||
$qa_include_tail = isset($qa_include_tail) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_tail, 0, 255)) : '';
|
||||
|
||||
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
|
||||
if ($is_admin !== 'super') {
|
||||
$qa_include_head = isset($qaconfig['qa_include_head']) ? $qaconfig['qa_include_head'] : '';
|
||||
$qa_include_tail = isset($qaconfig['qa_include_tail']) ? $qaconfig['qa_include_tail'] : '';
|
||||
}
|
||||
|
||||
// 관리자가 자동등록방지를 사용해야 할 경우
|
||||
if ($board && ($qaconfig['qa_include_head'] !== $qa_include_head || $qaconfig['qa_include_tail'] !== $qa_include_tail) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
|
||||
include_once G5_CAPTCHA_PATH . '/captcha.lib.php';
|
||||
|
||||
+61
-24
@@ -9,40 +9,76 @@ if (!$config['cf_email_use'])
|
||||
|
||||
include_once(G5_LIB_PATH.'/mailer.lib.php');
|
||||
|
||||
$token = get_token();
|
||||
|
||||
$g5['title'] = '메일 테스트';
|
||||
include_once('./admin.head.php');
|
||||
|
||||
if (isset($_POST['email'])) {
|
||||
check_admin_token();
|
||||
|
||||
$_POST['email'] = strip_tags($_POST['email']);
|
||||
$email = explode(',', $_POST['email']);
|
||||
|
||||
$real_email = array();
|
||||
$sent_email = array(); // 발송 요청 성공
|
||||
$failed_email = array(); // 발송 실패 (메일 서버에서 거부/오류)
|
||||
|
||||
for ($i=0; $i<count($email); $i++){
|
||||
|
||||
if (!preg_match("/([0-9a-zA-Z_-]+)@([0-9a-zA-Z_-]+)\.([0-9a-zA-Z_-]+)/", $email[$i])) continue;
|
||||
|
||||
$real_email[] = $email[$i];
|
||||
mailer($config['cf_admin_email_name'], $config['cf_admin_email'], trim($email[$i]), '[메일검사] 제목', '<span style="font-size:9pt;">[메일검사] 내용<p>이 내용이 제대로 보인다면 보내는 메일 서버에는 이상이 없는것입니다.<p>'.G5_TIME_YMDHIS.'<p>이 메일 주소로는 회신되지 않습니다.</span>', 1);
|
||||
|
||||
$to = trim($email[$i]);
|
||||
$send_result = mailer($config['cf_admin_email_name'], $config['cf_admin_email'], $to, '[메일검사] 제목', '<span style="font-size:9pt;">[메일검사] 내용<p>이 내용이 제대로 보인다면 보내는 메일 서버에는 이상이 없는것입니다.<p>'.G5_TIME_YMDHIS.'<p>이 메일 주소로는 회신되지 않습니다.</span>', 1);
|
||||
|
||||
if ($send_result) {
|
||||
$sent_email[] = $to;
|
||||
} else {
|
||||
$failed_email[] = $to;
|
||||
}
|
||||
}
|
||||
|
||||
if( $real_email ){
|
||||
if( $sent_email || $failed_email ){
|
||||
echo '<section>';
|
||||
echo '<h2>결과메세지</h2>';
|
||||
echo '<div class="local_desc01 local_desc"><p>';
|
||||
echo '다음 '.count($real_email).'개의 메일 주소로 테스트 메일 발송이 완료되었습니다.';
|
||||
echo '</p></div>';
|
||||
echo '<ul>';
|
||||
for ($i=0;$i<count($real_email);$i++) {
|
||||
echo '<li>'.$real_email[$i].'</li>';
|
||||
echo '<h2>결과 메시지</h2>';
|
||||
|
||||
if( $sent_email ){
|
||||
echo '<div class="local_desc01 local_desc"><p>';
|
||||
echo '다음 '.count($sent_email).'개의 메일 주소로 테스트 메일 <strong>발송 요청이 성공</strong>했습니다. <strong>수신함 도착 여부는 별도 확인이 필요합니다.</strong>';
|
||||
echo '</p></div>';
|
||||
echo '<ul>';
|
||||
for ($i=0;$i<count($sent_email);$i++) {
|
||||
echo '<li>'.get_text($sent_email[$i]).'</li>';
|
||||
}
|
||||
echo '</ul>';
|
||||
echo '<div class="local_desc02 local_desc"><p>';
|
||||
echo '<strong>발송 요청 성공은 사이트가 메일 서버에 메일을 넘겼다는 의미이며, 받은편지함 도착을 보장하지는 않습니다.</strong><br>';
|
||||
echo '메일이 보이지 않는다면 아래 항목을 순서대로 확인해 주십시오.';
|
||||
echo '</p></div>';
|
||||
echo '<ol>';
|
||||
echo '<li>받은편지함뿐 아니라 <strong>스팸함, 정크메일함, 프로모션함</strong>을 확인합니다.</li>';
|
||||
echo '<li>네이버, 지메일, 회사메일 등 <strong>서로 다른 메일 주소</strong>로 다시 테스트합니다.</li>';
|
||||
echo '<li>관리자 메일 주소가 사이트 도메인과 같은지 확인합니다. 도메인이 다르면 스팸으로 분류될 가능성이 높습니다.</li>';
|
||||
echo '<li>도메인 메일을 사용한다면 <strong>SPF, DKIM, DMARC</strong> 설정을 확인합니다.</li>';
|
||||
echo '<li>계속 도착하지 않으면 서버 개발자에게 메일 발송 로그를 확인해주세요.</li>';
|
||||
echo '</ol>';
|
||||
}
|
||||
echo '</ul>';
|
||||
echo '<div class="local_desc02 local_desc"><p>';
|
||||
echo '해당 주소로 테스트 메일이 도착했는지 확인해 주십시오.<br>';
|
||||
echo '만약, 테스트 메일이 오지 않는다면 더 다양한 계정의 메일 주소로 메일을 보내 보십시오.<br>';
|
||||
echo '그래도 메일이 하나도 도착하지 않는다면 메일 서버(sendmail server)의 오류일 가능성이 높으니, 웹 서버관리자에게 문의하여 주십시오.<br>';
|
||||
echo '도메인을 소유하고 있을시 SPF, DKIM 설정이 필요할수 있습니다.<br>';
|
||||
echo '</p></div>';
|
||||
|
||||
if( $failed_email ){
|
||||
echo '<div class="local_desc01 local_desc" style="color:#d9534f"><p>';
|
||||
echo '다음 '.count($failed_email).'개의 메일 주소는 <strong>발송에 실패</strong>했습니다.';
|
||||
echo '</p></div>';
|
||||
echo '<ul>';
|
||||
for ($i=0;$i<count($failed_email);$i++) {
|
||||
echo '<li>'.get_text($failed_email[$i]).'</li>';
|
||||
}
|
||||
echo '</ul>';
|
||||
echo '<div class="local_desc02 local_desc"><p>';
|
||||
echo '발송 실패는 받는 사람의 문제가 아니라 <strong>보내는 서버(메일 발송) 설정 문제</strong>일 가능성이 높습니다.<br>';
|
||||
echo 'SMTP 정보(주소/포트/인증)가 올바른지, 서버에서 메일 발송(sendmail/mail 함수)이 허용되어 있는지 확인하시고, 웹 서버 관리자(호스팅 업체)에게 문의해 주십시오.<br>';
|
||||
echo '자세한 오류 내용은 서버의 PHP error_log 에 기록됩니다.<br>';
|
||||
echo '</p></div>';
|
||||
}
|
||||
|
||||
echo '</section>';
|
||||
}
|
||||
}
|
||||
@@ -52,15 +88,16 @@ if (isset($_POST['email'])) {
|
||||
<h2>테스트 메일 발송</h2>
|
||||
<div class="local_desc02 local_desc">
|
||||
<p>
|
||||
메일서버가 정상적으로 동작 중인지 확인할 수 있습니다.<br>
|
||||
사이트에서 메일 서버로 메일을 전달할 수 있는지 확인합니다. 이 테스트는 받은편지함 도착을 보장하지 않습니다.<br>
|
||||
아래 입력칸에 테스트 메일을 발송하실 메일 주소를 입력하시면, [메일검사] 라는 제목으로 테스트 메일을 발송합니다.<br>
|
||||
보내는 메일주소 : <?php echo get_sanitize_input($config['cf_admin_email']); ?><br>
|
||||
<?php if (function_exists('domain_mail_host') && $config['cf_admin_email'] && stripos($config['cf_admin_email'], domain_mail_host()) === false) { ?>
|
||||
<?php echo '외부메일설정이나 기타 설정을 하지 않았다면, 도메인과 다른 헤더로 여겨 스팸이나 차단될 가능성이 있습니다.<br>기본환경설정에서 관리자 메일 주소를 name'.domain_mail_host().' 과 같은 도메인 형식으로 설정할것을 권장합니다.'; ?>
|
||||
<?php echo '외부메일설정이나 기타 설정을 하지 않았다면, 도메인과 다른 헤더로 여겨 스팸이나 차단될 가능성이 있습니다.<br>외부메일설정이나 기타 설정을 하지 않았다면, 기본환경설정에서 관리자 메일 주소를 name'.domain_mail_host().' 과 같은 도메인 형식으로 설정할것을 권장합니다.'; ?>
|
||||
<?php } ?>
|
||||
</p>
|
||||
</div>
|
||||
<form name="fsendmailtest" method="post">
|
||||
<input type="hidden" name="token" value="<?php echo $token; ?>">
|
||||
<fieldset id="fsendmailtest">
|
||||
<legend>테스트메일 발송</legend>
|
||||
<label for="email">받는 메일주소<strong class="sound_only"> 필수</strong></label>
|
||||
@@ -70,11 +107,11 @@ if (isset($_POST['email'])) {
|
||||
</form>
|
||||
<div class="local_desc02 local_desc">
|
||||
<p>
|
||||
만약 [메일검사] 라는 내용으로 테스트 메일이 도착하지 않는다면 보내는 메일서버 혹은 받는 메일서버 중 문제가 발생했을 가능성이 있습니다.<br>
|
||||
따라서 보다 정확한 테스트를 원하신다면 여러 곳으로 테스트 메일을 발송하시기 바랍니다.<br>
|
||||
테스트 결과가 발송 요청 성공으로 표시되어도 수신 메일 서버의 스팸 정책에 따라 도착하지 않을 수 있습니다.<br>
|
||||
정확한 확인을 위해 여러 메일 서비스로 테스트하고, 도착하지 않으면 스팸함과 도메인 인증(SPF, DKIM, DMARC)을 확인해 주십시오.<br>
|
||||
</p>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
<?php
|
||||
include_once('./admin.tail.php');
|
||||
include_once('./admin.tail.php');
|
||||
|
||||
@@ -31,7 +31,7 @@ include_once("./admin.head.php");
|
||||
echo $list_tag_st;
|
||||
while($file=readdir($dir)) {
|
||||
|
||||
if (!strstr($file,'sess_')) continue;
|
||||
if (strpos($file,'sess_') === false) continue;
|
||||
if (strpos($file,'sess_')!=0) continue;
|
||||
|
||||
$session_file = G5_DATA_PATH.'/session/'.$file;
|
||||
|
||||
@@ -1,6 +1,45 @@
|
||||
<?php
|
||||
if (!defined('_GNUBOARD_')) exit;
|
||||
|
||||
function get_shop_skin_dirs($is_mobile=false)
|
||||
{
|
||||
global $config;
|
||||
|
||||
$skin_path = $is_mobile ? G5_MOBILE_PATH.'/'.G5_SKIN_DIR : G5_SKIN_PATH;
|
||||
$skins = get_skin_dir('shop', $skin_path);
|
||||
|
||||
if(defined('G5_THEME_PATH') && $config['cf_theme']) {
|
||||
$theme_skin_path = $is_mobile ? G5_THEME_MOBILE_PATH.'/'.G5_SKIN_DIR : G5_THEME_PATH.'/'.G5_SKIN_DIR;
|
||||
$dirs = get_skin_dir('shop', $theme_skin_path);
|
||||
if(!empty($dirs)) {
|
||||
foreach($dirs as $dir) {
|
||||
$skins[] = 'theme/'.$dir;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return $skins;
|
||||
}
|
||||
|
||||
function check_shop_skin_dir($skin_dir, $label, $is_mobile=false)
|
||||
{
|
||||
if( $skin_dir === '' ) {
|
||||
return;
|
||||
}
|
||||
|
||||
if( preg_match('#\.+(\/|\\\)#', $skin_dir) ){
|
||||
alert($label.' 폴더명에 포함될수 없는 문자가 들어있습니다.');
|
||||
}
|
||||
|
||||
if( ! is_include_path_check($skin_dir, 1) ){
|
||||
alert('오류 : 데이터폴더가 포함된 path 또는 잘못된 path 를 포함할수 없습니다.');
|
||||
}
|
||||
|
||||
if( ! in_array($skin_dir, get_shop_skin_dirs($is_mobile), true) ){
|
||||
alert($label.'을 올바르게 선택해 주십시오.');
|
||||
}
|
||||
}
|
||||
|
||||
// 상품옵션별재고 또는 상품재고에 더하기
|
||||
function add_io_stock($it_id, $ct_qty, $io_id="", $io_type=0)
|
||||
{
|
||||
@@ -125,14 +164,19 @@ function pg_setting_check($is_print=false){
|
||||
|
||||
$msg = '';
|
||||
$pg_msg = '';
|
||||
$pg_test_conf_link = G5_ADMIN_URL.'/shop_admin/configform.php#de_card_test1';
|
||||
|
||||
if( $default['de_card_test'] ){
|
||||
if( $default['de_pg_service'] === 'kcp' && $default['de_kcp_mid'] && $default['de_kcp_site_key'] ){
|
||||
$pg_msg = 'NHN KCP';
|
||||
} else if ( $default['de_pg_service'] === 'lg' && $config['cf_lg_mid'] && $config['cf_lg_mert_key'] ){
|
||||
$pg_msg = 'LG유플러스';
|
||||
} else if ( $default['de_pg_service'] === 'toss' && $config['cf_lg_mid'] && $config['cf_toss_client_key'] && $config['cf_toss_secret_key'] ){
|
||||
$msg .= '<div class="admin_pg_notice od_test_caution">(주의!) 토스페이먼츠 결제의 결제 설정이 현재 테스트결제로 되어 있습니다.<br>반드시 <a href="#lg_info_anchor">상점 API키</a>를 <u>[테스트]키</u>로 설정한 후 테스트결제를 진행해야합니다.<br>쇼핑몰 운영 시에는 실결제로 전환하여 <u>[라이브]키</u>로 설정해 주시기 바랍니다.<br>아래 링크를 클릭하여 실결제로 설정하여 운영해 주세요.<br><a href="'.$pg_test_conf_link.'" class="pg_test_conf_link">'.$pg_test_conf_link.'</a></div>';
|
||||
} else if ( $default['de_pg_service'] === 'inicis' && $default['de_inicis_mid'] && $default['de_inicis_sign_key'] ){
|
||||
$pg_msg = 'KG이니시스';
|
||||
} else if ( $default['de_pg_service'] === 'nicepay' && $default['de_nicepay_mid'] && $default['de_nicepay_key'] ){
|
||||
$pg_msg = 'NICEPAY';
|
||||
}
|
||||
}
|
||||
|
||||
@@ -145,7 +189,6 @@ function pg_setting_check($is_print=false){
|
||||
}
|
||||
|
||||
if( $pg_msg ){
|
||||
$pg_test_conf_link = G5_ADMIN_URL.'/shop_admin/configform.php#de_card_test1';
|
||||
$msg .= '<div class="admin_pg_notice od_test_caution">(주의!) '.$pg_msg.' 결제의 결제 설정이 현재 테스트결제 로 되어 있습니다.<br>테스트결제시 실제 결제가 되지 않으므로, 쇼핑몰 운영중이면 반드시 실결제로 설정하여 운영하셔야 합니다.<br>아래 링크를 클릭하여 실결제로 설정하여 운영해 주세요.<br><a href="'.$pg_test_conf_link.'" class="pg_test_conf_link">'.$pg_test_conf_link.'</a></div>';
|
||||
}
|
||||
|
||||
@@ -156,6 +199,25 @@ function pg_setting_check($is_print=false){
|
||||
}
|
||||
}
|
||||
|
||||
function is_cancel_shop_pg_order($od){
|
||||
|
||||
$is_od_pg_cancel = false;
|
||||
|
||||
if (($od['od_settle_case'] == '신용카드' || $od['od_settle_case'] == '간편결제' || $od['od_settle_case'] == 'KAKAOPAY') || ($od['od_pg'] == 'inicis' && is_inicis_order_pay($od['od_settle_case']))) {
|
||||
$is_od_pg_cancel = true;
|
||||
}
|
||||
|
||||
if ($od['od_pg'] === 'nicepay' && in_array($od['od_settle_case'], array('계좌이체', '휴대폰'))) {
|
||||
$is_od_pg_cancel = true;
|
||||
}
|
||||
|
||||
if($od['od_pg'] === 'toss' && in_array($od['od_settle_case'], array('계좌이체', '휴대폰'))) {
|
||||
$is_od_pg_cancel = true;
|
||||
}
|
||||
|
||||
return $is_od_pg_cancel;
|
||||
}
|
||||
|
||||
function check_order_inicis_tmps(){
|
||||
global $g5, $config, $default, $member;
|
||||
|
||||
@@ -218,4 +280,4 @@ function check_order_inicis_tmps(){
|
||||
|
||||
set_cookie('admin_visit_time', G5_SERVER_TIME, 3600); //1시간 간격으로 체크
|
||||
}
|
||||
} //end function check_order_inicis_tmps;
|
||||
} //end function check_order_inicis_tmps;
|
||||
|
||||
@@ -20,14 +20,14 @@ $bn_bimg = isset($_FILES['bn_bimg']['tmp_name']) ? $_FILES['bn_bimg']['tmp_
|
||||
$bn_bimg_name = isset($_FILES['bn_bimg']['name']) ? $_FILES['bn_bimg']['name'] : '';
|
||||
$bn_id = isset($_REQUEST['bn_id']) ? preg_replace('/[^0-9]/', '', $_REQUEST['bn_id']) : 0;
|
||||
$bn_bimg_del = (isset($_POST['bn_bimg_del']) && $_POST['bn_bimg_del']) ? preg_replace('/[^0-9]/', '', $_POST['bn_id']) : 0;
|
||||
$bn_url = isset($_POST['bn_url']) ? strip_tags(clean_xss_attributes($bn_url)) : '';
|
||||
$bn_alt = isset($_POST['bn_alt']) ? strip_tags(clean_xss_attributes($bn_alt)) : '';
|
||||
$bn_device = isset($_POST['bn_device']) ? clean_xss_tags($_POST['bn_device'], 1, 1) : '';
|
||||
$bn_position = isset($_POST['bn_position']) ? clean_xss_tags($_POST['bn_position'], 1, 1) : '';
|
||||
$bn_url = isset($_POST['bn_url']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bn_url'])))) : '';
|
||||
$bn_alt = isset($_POST['bn_alt']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bn_alt'])))) : '';
|
||||
$bn_device = isset($_POST['bn_device']) ? safe_replace_regex($_POST['bn_device']) : '';
|
||||
$bn_position = isset($_POST['bn_position']) ? addslashes(clean_xss_tags(stripslashes($_POST['bn_position']), 1, 1)) : '';
|
||||
$bn_border = isset($_POST['bn_border']) ? (int) $_POST['bn_border'] : 0;
|
||||
$bn_new_win = isset($_POST['bn_new_win']) ? (int) $_POST['bn_new_win'] : 0;
|
||||
$bn_begin_time = isset($_POST['bn_begin_time']) ? clean_xss_tags($_POST['bn_begin_time'], 1, 1) : '';
|
||||
$bn_end_time = isset($_POST['bn_end_time']) ? clean_xss_tags($_POST['bn_end_time'], 1, 1) : '';
|
||||
$bn_begin_time = isset($_POST['bn_begin_time']) ? safe_replace_regex($_POST['bn_begin_time'], 'time') : '';
|
||||
$bn_end_time = isset($_POST['bn_end_time']) ? safe_replace_regex($_POST['bn_end_time'], 'time') : '';
|
||||
$bn_order = isset($_POST['bn_order']) ? (int) $_POST['bn_order'] : 0;
|
||||
|
||||
if ($bn_bimg_del) @unlink(G5_DATA_PATH."/banner/$bn_id");
|
||||
@@ -99,4 +99,4 @@ if ($w == "" || $w == "u")
|
||||
goto_url("./bannerform.php?w=u&bn_id=$bn_id");
|
||||
} else {
|
||||
goto_url("./bannerlist.php");
|
||||
}
|
||||
}
|
||||
|
||||
@@ -75,7 +75,7 @@ foreach( $check_str_keys as $key=>$val ){
|
||||
if( $val === 'int' ){
|
||||
$value = isset($_POST[$key]) ? (int) $_POST[$key] : 0;
|
||||
} else {
|
||||
$value = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
|
||||
$value = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
|
||||
}
|
||||
$$key = $_POST[$key] = $value;
|
||||
}
|
||||
@@ -123,7 +123,7 @@ if ($w == "" || $w == "u")
|
||||
$sql = " select mb_id from {$g5['member_table']} where mb_id = '$ca_mb_id' ";
|
||||
$row = sql_fetch($sql);
|
||||
if (!$row['mb_id'])
|
||||
alert("\'$ca_mb_id\' 은(는) 존재하는 회원아이디가 아닙니다.");
|
||||
alert("'$ca_mb_id' 은(는) 존재하는 회원아이디가 아닙니다.");
|
||||
}
|
||||
}
|
||||
|
||||
@@ -256,4 +256,4 @@ if ($w == "" || $w == "u")
|
||||
goto_url("./categoryform.php?w=u&ca_id=$ca_id&$qstr");
|
||||
} else {
|
||||
goto_url("./categorylist.php?$qstr");
|
||||
}
|
||||
}
|
||||
|
||||
@@ -42,6 +42,9 @@ if (!$sst)
|
||||
$sst = "ca_id";
|
||||
$sod = "asc";
|
||||
}
|
||||
$allowed_sst = array('ca_id', 'ca_name', 'ca_mb_id', 'ca_use');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'ca_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = "order by $sst $sod";
|
||||
|
||||
// 출력할 레코드를 얻음
|
||||
|
||||
@@ -19,7 +19,7 @@ for ($i=0; $i<$post_ca_id_count; $i++)
|
||||
$sql = " select mb_id from {$g5['member_table']} where mb_id = '".sql_real_escape_string($str_ca_mb_id)."' ";
|
||||
$row = sql_fetch($sql);
|
||||
if (!$row['mb_id'])
|
||||
alert("\'{$str_ca_mb_id}\' 은(는) 존재하는 회원아이디가 아닙니다.", "./categorylist.php?$qstr");
|
||||
alert("'{$str_ca_mb_id}' 은(는) 존재하는 회원아이디가 아닙니다.", "./categorylist.php?$qstr");
|
||||
}
|
||||
|
||||
$check_files = array();
|
||||
@@ -51,7 +51,7 @@ for ($i=0; $i<$post_ca_id_count; $i++)
|
||||
alert('스킨파일명에 포함될수 없는 문자가 들어있습니다.');
|
||||
}
|
||||
|
||||
if( ! is_include_path_check($file) ){
|
||||
if( ! is_include_path_check($file, 1) ){
|
||||
alert('오류 : 데이터폴더가 포함된 path 또는 잘못된 path 를 포함할수 없습니다.');
|
||||
}
|
||||
|
||||
@@ -62,7 +62,7 @@ for ($i=0; $i<$post_ca_id_count; $i++)
|
||||
}
|
||||
}
|
||||
|
||||
$p_ca_name = is_array($_POST['ca_name']) ? strip_tags(clean_xss_attributes($_POST['ca_name'][$i])) : '';
|
||||
$p_ca_name = is_array($_POST['ca_name']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['ca_name'][$i])))) : '';
|
||||
|
||||
$posts = array();
|
||||
|
||||
@@ -94,4 +94,4 @@ for ($i=0; $i<$post_ca_id_count; $i++)
|
||||
|
||||
}
|
||||
|
||||
goto_url("./categorylist.php?$qstr");
|
||||
goto_url("./categorylist.php?$qstr");
|
||||
|
||||
+107
-16
@@ -207,6 +207,22 @@ if( ! isset($default['de_inicis_iniapi_key']) ){
|
||||
sql_query($sql, false);
|
||||
}
|
||||
|
||||
// NICEPAY mid, key 추가
|
||||
if (! isset($default['de_nicepay_mid'])) {
|
||||
$sql = "ALTER TABLE `{$g5['g5_shop_default_table']}`
|
||||
ADD COLUMN `de_nicepay_mid` VARCHAR(20) NOT NULL DEFAULT '' AFTER `de_inicis_cartpoint_use`,
|
||||
ADD COLUMN `de_nicepay_key` VARCHAR(150) NOT NULL DEFAULT '' AFTER `de_nicepay_mid`; ";
|
||||
sql_query($sql, false);
|
||||
}
|
||||
|
||||
// 토스페이먼츠 client, secret key 추가
|
||||
if( ! isset($config['cf_toss_client_key']) ){
|
||||
$sql = "ALTER TABLE `{$g5['config_table']}`
|
||||
ADD COLUMN `cf_toss_client_key` VARCHAR(100) NOT NULL DEFAULT '' AFTER `cf_lg_mert_key`,
|
||||
ADD COLUMN `cf_toss_secret_key` VARCHAR(100) NOT NULL DEFAULT '' AFTER `cf_toss_client_key`; ";
|
||||
sql_query($sql, false);
|
||||
}
|
||||
|
||||
if( function_exists('pg_setting_check') ){
|
||||
pg_setting_check(true);
|
||||
}
|
||||
@@ -624,15 +640,27 @@ if(!$default['de_kakaopay_cancelpwd']){
|
||||
<tr id="kcp_vbank_url" class="pg_vbank_url">
|
||||
<th scope="row">NHN KCP 가상계좌<br>입금통보 URL</th>
|
||||
<td>
|
||||
<?php echo help("NHN KCP 가상계좌 사용시 다음 주소를 <strong><a href=\"http://admin.kcp.co.kr\" target=\"_blank\">NHN KCP 관리자</a> > 상점정보관리 > 정보변경 > 공통URL 정보 > 공통URL 변경후</strong>에 넣으셔야 상점에 자동으로 입금 통보됩니다."); ?>
|
||||
<?php echo help("NHN KCP 가상계좌 사용시 다음 주소를 <strong><a href=\"https://partner.kcp.co.kr\" target=\"_blank\">NHN KCP 관리자</a> > 상점정보관리 > 정보변경 > 공통URL 정보 > 공통URL 변경후</strong>에 넣으셔야 상점에 자동으로 입금 통보됩니다."); ?>
|
||||
<?php echo G5_SHOP_URL; ?>/settle_kcp_common.php</td>
|
||||
</tr>
|
||||
<tr id="inicis_vbank_url" class="pg_vbank_url">
|
||||
<th scope="row">KG이니시스 가상계좌 입금통보 URL</th>
|
||||
<th scope="row">KG이니시스 가상계좌<br>입금통보 URL</th>
|
||||
<td>
|
||||
<?php echo help("KG이니시스 가상계좌 사용시 다음 주소를 <strong><a href=\"https://iniweb.inicis.com/\" target=\"_blank\">KG이니시스 관리자</a> > 거래내역 > 가상계좌 > 입금통보방식선택 > URL 수신 설정</strong>에 넣으셔야 상점에 자동으로 입금 통보됩니다."); ?>
|
||||
<?php echo G5_SHOP_URL; ?>/settle_inicis_common.php</td>
|
||||
</tr>
|
||||
<tr id="nicepay_vbank_url" class="pg_vbank_url">
|
||||
<th scope="row">NICEPAY 가상계좌<br>입금통보 URL</th>
|
||||
<td>
|
||||
<?php echo help("NICEPAY 가상계좌 사용시 다음 주소를 <strong><a href=\"https://npg.nicepay.co.kr/\" target=\"_blank\">NICEPAY 관리자</a> > 가맹점관리자페이지 설정 (메인화면 → 가맹점정보 클릭)</strong>에 넣으셔야 상점에 자동으로 입금 통보됩니다."); ?>
|
||||
<?php echo G5_SHOP_URL; ?>/settle_nicepay_common.php</td>
|
||||
</tr>
|
||||
<tr id="toss_vbank_url" class="pg_vbank_url">
|
||||
<th scope="row">토스페이먼츠 가상계좌<br>입금통보 URL</th>
|
||||
<td>
|
||||
<?php echo help("토스페이먼츠 가상계좌 사용시 다음 주소를 <strong><a href=\"https://app.tosspayments.com/\" target=\"_blank\">토스페이먼츠 상점관리자</a> > 개발자센터 > 웹훅 > 웹훅 등록하기에 URL</strong>에 넣으시고, <strong>구독할 이벤트를 [DEPOSIT_CALLBACK]</strong>을 선택하셔야 상점에 자동으로 입금 통보됩니다."); ?>
|
||||
<?php echo G5_SHOP_URL; ?>/settle_toss_common.php</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th scope="row"><label for="de_hp_use">휴대폰결제사용</label></th>
|
||||
<td>
|
||||
@@ -666,13 +694,14 @@ if(!$default['de_kakaopay_cancelpwd']){
|
||||
<tr>
|
||||
<th scope="row"><label for="de_easy_pay_use">PG사 간편결제 버튼 사용</label></th>
|
||||
<td>
|
||||
<?php echo help("주문서 작성 페이지에 PG사 간편결제(PAYCO, PAYNOW, KPAY) 버튼의 별도 사용 여부를 설정합니다.", 50); ?>
|
||||
<?php echo help("주문서 작성 페이지에 PG사 간편결제(PAYCO, 토스, KPAY...) 버튼의 별도 사용 여부를 설정합니다.", 50); ?>
|
||||
<select id="de_easy_pay_use" name="de_easy_pay_use">
|
||||
<option value="0" <?php echo get_selected($default['de_easy_pay_use'], 0); ?>>노출안함</option>
|
||||
<option value="1" <?php echo get_selected($default['de_easy_pay_use'], 1); ?>>노출함</option>
|
||||
</select>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<th scope="row"><label for="de_taxsave_use">현금영수증<br>발급사용</label></th>
|
||||
<td>
|
||||
@@ -686,13 +715,13 @@ if(!$default['de_kakaopay_cancelpwd']){
|
||||
<?php
|
||||
$account_checked = $vbank_checked = $transfer_checked = '';
|
||||
|
||||
if (strstr($default['de_taxsave_types'], 'account')) {
|
||||
if (strpos($default['de_taxsave_types'], 'account') !== false) {
|
||||
$account_checked = 'checked="checked"';
|
||||
}
|
||||
if (strstr($default['de_taxsave_types'], 'vbank')) {
|
||||
if (strpos($default['de_taxsave_types'], 'vbank') !== false) {
|
||||
$vbank_checked = 'checked="checked"';
|
||||
}
|
||||
if (strstr($default['de_taxsave_types'], 'transfer')) {
|
||||
if (strpos($default['de_taxsave_types'], 'transfer') !== false) {
|
||||
$transfer_checked = 'checked="checked"';
|
||||
}
|
||||
?>
|
||||
@@ -761,8 +790,10 @@ if(!$default['de_kakaopay_cancelpwd']){
|
||||
<?php echo help('쇼핑몰에서 사용할 결제대행사를 선택합니다.'); ?>
|
||||
<ul class="de_pg_tab">
|
||||
<li class="<?php if($default['de_pg_service'] == 'kcp') echo 'tab-current'; ?>"><a href="#kcp_info_anchor" data-value="kcp" title="NHN KCP 선택하기" >NHN KCP</a></li>
|
||||
<li class="<?php if($default['de_pg_service'] == 'lg') echo 'tab-current'; ?>"><a href="#lg_info_anchor" data-value="lg" title="토스페이먼츠 선택하기">토스페이먼츠</a></li>
|
||||
<li class="<?php if($default['de_pg_service'] == 'lg') echo 'tab-current'; ?>"><a href="#lg_info_anchor" data-value="lg" title="토스페이먼츠(구버전) 선택하기">토스페이먼츠(구버전)</a></li>
|
||||
<li class="<?php if($default['de_pg_service'] == 'toss') echo 'tab-current'; ?>"><a href="#lg_info_anchor" data-value="toss" title="토스페이먼츠 선택하기">토스페이먼츠</a></li>
|
||||
<li class="<?php if($default['de_pg_service'] == 'inicis') echo 'tab-current'; ?>"><a href="#inicis_info_anchor" data-value="inicis" title="KG이니시스 선택하기">KG이니시스</a></li>
|
||||
<li class="<?php if($default['de_pg_service'] == 'nicepay') echo 'tab-current'; ?>"><a href="#nicepay_info_anchor" data-value="nicepay" title="NICEPAY 선택하기">NICEPAY</a></li>
|
||||
</ul>
|
||||
</td>
|
||||
</tr>
|
||||
@@ -818,12 +849,26 @@ if(!$default['de_kakaopay_cancelpwd']){
|
||||
</td>
|
||||
</tr>
|
||||
<tr class="pg_info_fld lg_info_fld">
|
||||
<th scope="row"><label for="cf_lg_mert_key">토스페이먼츠 MERT KEY</label></th>
|
||||
<th scope="row"><label for="cf_lg_mert_key">토스페이먼츠(구버전) MERT KEY</label></th>
|
||||
<td>
|
||||
<?php echo help("토스페이먼츠 상점MertKey는 상점관리자 -> 계약정보 -> 상점정보관리에서 확인하실 수 있습니다.\n예) 95160cce09854ef44d2edb2bfb05f9f3\n<a href=\"".G5_ADMIN_URL."/config_form.php#anc_cf_cert\">기본환경설정 > 본인확인</a> 설정의 토스페이먼츠 MERT KEY와 동일합니다."); ?>
|
||||
<?php echo help("토스페이먼츠(구버전) 상점 MertKey는 상점관리자 -> 개발자센터 -> API키 -> 머트 키에서 확인하실 수 있습니다.\n예) 95160cce09854ef44d2edb2bfb05f9f3"); ?>
|
||||
<input type="text" name="cf_lg_mert_key" value="<?php echo get_sanitize_input($config['cf_lg_mert_key']); ?>" id="cf_lg_mert_key" class="frm_input " size="36" maxlength="50">
|
||||
</td>
|
||||
</tr>
|
||||
<tr class="pg_info_fld lg_info_fld_v2">
|
||||
<th scope="row"><label for="cf_toss_client_key">토스페이먼츠 API Client Key</label></th>
|
||||
<td>
|
||||
<?php echo help("토스페이먼츠 API 클라이언트 키는 상점관리자 -> 개발자센터 -> API키 -> 클라이언트 키에서 확인하실 수 있습니다. 예) live_ck_tosspayment\n실결제용 [라이브] 키와 테스트용 [테스트] 키는 서로 다르므로, <b>테스트로 결제시에는 [테스트] 키</b>로 변경하여 사용해주시기 바랍니다. 예) 테스트 키: test_ck_tosspayment"); ?>
|
||||
<input type="text" name="cf_toss_client_key" value="<?php echo get_sanitize_input($config['cf_toss_client_key']); ?>" id="cf_toss_client_key" class="frm_input " size="40" maxlength="50">
|
||||
</td>
|
||||
</tr>
|
||||
<tr class="pg_info_fld lg_info_fld_v2">
|
||||
<th scope="row"><label for="cf_toss_secret_key">토스페이먼츠 API Secret Key</label></th>
|
||||
<td>
|
||||
<?php echo help("토스페이먼츠 API 시크릿 키는 상점관리자 -> 개발자센터 -> API키 -> 시크릿 키에서 확인하실 수 있습니다. 예) live_sk_tosspayment\n실결제용 [라이브] 키와 테스트용 [테스트] 키는 서로 다르므로, <b>테스트로 결제시에는 [테스트] 키</b>로 변경하여 사용해주시기 바랍니다. 예) 테스트 키: test_sk_tosspayment"); ?>
|
||||
<input type="text" name="cf_toss_secret_key" value="<?php echo get_sanitize_input($config['cf_toss_secret_key']); ?>" id="cf_toss_secret_key" class="frm_input " size="40" maxlength="50">
|
||||
</td>
|
||||
</tr>
|
||||
<tr class="pg_info_fld inicis_info_fld" id="inicis_info_anchor">
|
||||
<th scope="row">
|
||||
<label for="de_inicis_mid">KG이니시스 상점아이디</label><br>
|
||||
@@ -918,7 +963,7 @@ if(!$default['de_kakaopay_cancelpwd']){
|
||||
</tr>
|
||||
<tr class="kakao_info_fld">
|
||||
<th scope="row">
|
||||
<label for="de_kakaopay_enckey">카카오페이 사용</label>
|
||||
<label for="de_kakaopay_enckey">KG이니시스<br>카카오페이 사용</label>
|
||||
</th>
|
||||
<td>
|
||||
<?php echo help("체크시 카카오페이 (KG 이니시스)를 사용합니다. <br >KG 이니시스의 SIRK****** 아이디를 받은 상점만 해당됩니다.", 50); ?>
|
||||
@@ -932,6 +977,38 @@ if(!$default['de_kakaopay_cancelpwd']){
|
||||
<input type="text" name="de_kakaopay_hashkey" value="<?php echo get_sanitize_input($default['de_kakaopay_hashkey']); ?>" id="de_kakaopay_hashkey" class="frm_input" size="20">
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="pg_info_fld nicepay_info_fld" id="nicepay_info_anchor">
|
||||
<th scope="row"><label for="de_nicepay_mid">NICEPAY MID</label><br><a href="http://sir.kr/main/service/nicepayments_pg.php" target="_blank" id="scf_nicepay_reg" class="nicepay_btn">NICEPAY 신청하기</a></th>
|
||||
<td>
|
||||
<span class="frm_info">NICEPAY로 부터 발급 받으신 상점MID를 SR 을 제외한 나머지 자리를 입력 합니다.<br>NICEPAY 상점관리자 > 가맹점정보 > KEY관리에서 확인 할수 있습니다.<br>만약, 상점아이디가 SR로 시작하지 않는다면 계약담당자에게 변경 요청을 해주시기 바랍니다. 예) SRpaytestm</span>
|
||||
<span class="sitecode">SR</span>
|
||||
<input type="text" name="de_nicepay_mid" value="<?php echo get_sanitize_input($default['de_nicepay_mid']); ?>" id="de_nicepay_mid" class="frm_input" size="12" maxlength="12">
|
||||
영문소문자(숫자포함 가능)
|
||||
</td>
|
||||
</tr>
|
||||
<tr class="pg_info_fld nicepay_info_fld">
|
||||
<th scope="row"><label for="de_nicepay_key">NICEPAY KEY</label></th>
|
||||
<td>
|
||||
<input type="text" name="de_nicepay_key" value="<?php echo get_sanitize_input($default['de_nicepay_key']); ?>" id="de_nicepay_key" class="frm_input" size="100" maxlength="100">
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr class="pg_info_fld nicepay_info_fld">
|
||||
<th scope="row"><label for="de_nicepay_easy_pays">NICEPAY 간편결제</label></th>
|
||||
<td>
|
||||
<?php echo help("체크시 NICEPAY 간편결제들을 활성화 합니다.\nNICEPAY > 간편결제는 테스트결제가 되지 않습니다. 실결제에만 정상작동 합니다.\n애플페이는 IOS 기기에 모바일결제만 가능합니다."); ?>
|
||||
<input type="checkbox" id="de_easy_nicepay_samsungpay" name="de_easy_pays[]" value="nicepay_samsungpay" <?php if(stripos($default['de_easy_pay_services'], 'nicepay_samsungpay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nicepay_samsungpay" disabled>삼성페이</label><br>
|
||||
<input type="checkbox" id="de_easy_nicepay_naverpay" name="de_easy_pays[]" value="nicepay_naverpay" <?php if(stripos($default['de_easy_pay_services'], 'nicepay_naverpay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nicepay_naverpay">NAVERPAY (네이버페이)</label><br>
|
||||
<input type="checkbox" id="de_easy_nicepay_kakaopay" name="de_easy_pays[]" value="nicepay_kakaopay" <?php if(stripos($default['de_easy_pay_services'], 'nicepay_kakaopay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nicepay_kakaopay">KAKAOPAY (카카오페이)</label><br>
|
||||
<input type="checkbox" id="de_easy_nicepay_applepay" name="de_easy_pays[]" value="nicepay_applepay" <?php if(stripos($default['de_easy_pay_services'], 'nicepay_applepay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nicepay_applepay">APPLEPAY (애플페이)</label><br>
|
||||
<input type="checkbox" id="de_easy_nicepay_paycopay" name="de_easy_pays[]" value="nicepay_paycopay" <?php if(stripos($default['de_easy_pay_services'], 'nicepay_paycopay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nicepay_paycopay">페이코</label><br>
|
||||
<input type="checkbox" id="de_easy_nicepay_skpay" name="de_easy_pays[]" value="nicepay_skpay" <?php if(stripos($default['de_easy_pay_services'], 'nicepay_skpay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nicepay_skpay">SK페이</label><br>
|
||||
<input type="checkbox" id="de_easy_nicepay_ssgpay" name="de_easy_pays[]" value="nicepay_ssgpay" <?php if(stripos($default['de_easy_pay_services'], 'nicepay_ssgpay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nicepay_ssgpay">SSG페이</label><br>
|
||||
<input type="checkbox" id="de_easy_nicepay_lpay" name="de_easy_pays[]" value="nicepay_lpay" <?php if(stripos($default['de_easy_pay_services'], 'nicepay_lpay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nicepay_lpay">LPAY</label>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<?php if (defined('G5_SHOP_DIRECT_NAVERPAY') && G5_SHOP_DIRECT_NAVERPAY) { ?>
|
||||
<tr class="naver_info_fld">
|
||||
<th scope="row">
|
||||
@@ -1020,8 +1097,10 @@ if(!$default['de_kakaopay_cancelpwd']){
|
||||
<a href="http://testadmin8.kcp.co.kr/" target="_blank" class="btn_frmline">테스트 관리자</a>
|
||||
</div>
|
||||
<div class="scf_cardtest lg_cardtest">
|
||||
<a href="https://pgweb.uplus.co.kr/" target="_blank" class="btn_frmline">실결제 관리자</a>
|
||||
<a href="https://pgweb.uplus.co.kr/tmert" target="_blank" class="btn_frmline">테스트 관리자</a>
|
||||
<a href="https://app.tosspayments.com/" target="_blank" class="btn_frmline">상점 관리자</a>
|
||||
</div>
|
||||
<div class="scf_cardtest toss_cardtest">
|
||||
<a href="https://app.tosspayments.com/" target="_blank" class="btn_frmline">상점 관리자</a>
|
||||
</div>
|
||||
<div class="scf_cardtest inicis_cardtest">
|
||||
<a href="https://iniweb.inicis.com/" target="_blank" class="btn_frmline">상점 관리자</a>
|
||||
@@ -1042,11 +1121,14 @@ if(!$default['de_kakaopay_cancelpwd']){
|
||||
<dt>휴대폰</dt><dd>테스트 지원되지 않음.</dd>
|
||||
</dl>
|
||||
<ul id="kcp_cardtest_tip" class="scf_cardtest_tip_adm scf_cardtest_tip_adm_hide">
|
||||
<li>테스트결제의 <a href="http://testadmin8.kcp.co.kr/assist/login.LoginAction.do" target="_blank">상점관리자</a> 로그인 정보는 NHN KCP로 문의하시기 바랍니다. (기술지원 1544-8661)</li>
|
||||
<li>테스트결제의 <a href="https://testpartner.kcp.co.kr/" target="_blank">상점관리자</a> 로그인 정보는 NHN KCP로 문의하시기 바랍니다. (기술지원 1544-8661)</li>
|
||||
<li><b>일반결제</b>의 테스트 사이트코드는 <b>T0000</b> 이며, <b>에스크로 결제</b>의 테스트 사이트코드는 <b>T0007</b> 입니다.</li>
|
||||
</ul>
|
||||
<ul id="lg_cardtest_tip" class="scf_cardtest_tip_adm scf_cardtest_tip_adm_hide">
|
||||
<li>테스트결제의 <a href="http://pgweb.dacom.net:7085/" target="_blank">상점관리자</a> 로그인 정보는 토스페이먼츠 상점아이디 첫 글자에 t를 추가해서 로그인하시기 바랍니다. 예) tsi_lguplus</li>
|
||||
<li>테스트 결제건에 대한 <a href="https://app.tosspayments.com/" target="_blank">상점관리자</a> 접근은, 상점관리자 상단 '테스트 모드'를 활성화 하여서 접근할 수 있습니다.</li>
|
||||
</ul>
|
||||
<ul id="toss_cardtest_tip" class="scf_cardtest_tip_adm scf_cardtest_tip_adm_hide">
|
||||
<li>테스트 결제건에 대한 <a href="https://app.tosspayments.com/" target="_blank">상점관리자</a> 접근은, 상점관리자 상단 '테스트 모드'를 활성화 하여서 접근할 수 있습니다.</li>
|
||||
</ul>
|
||||
<ul id="inicis_cardtest_tip" class="scf_cardtest_tip_adm scf_cardtest_tip_adm_hide">
|
||||
<li><b>일반결제</b>의 테스트 사이트 mid는 <b>INIpayTest</b> 이며, <b>에스크로 결제</b>의 테스트 사이트 mid는 <b>iniescrow0</b> 입니다.</li>
|
||||
@@ -1722,12 +1804,20 @@ function fconfig_check(f)
|
||||
}
|
||||
} else if ( f.de_pg_service.value == "lg" ) {
|
||||
if( f.cf_lg_mid.value && f.cf_lg_mert_key.value && parseInt(f.de_card_test.value) > 0 ){
|
||||
pg_msg = "토스페이먼츠";
|
||||
pg_msg = "토스페이먼츠(구버전)";
|
||||
}
|
||||
} else if ( f.de_pg_service.value == "toss" ) {
|
||||
if( f.cf_lg_mid.value && f.cf_toss_client_key.value && f.cf_toss_secret_key.value && parseInt(f.de_card_test.value) > 0 ){
|
||||
msg += "(주의!) 토스페이먼츠 결제의 결제 설정이 현재 테스트결제로 되어 있습니다.\n상점 API키를 [테스트]키로 설정한 후 테스트결제를 진행해주세요.\n쇼핑몰 운영중이면 반드시 실결제 전환 및 [라이브]키로 설정하여 운영하셔야 합니다.\n실결제로 변경하려면 결제설정 탭 -> 결제 테스트에서 실결제를 선택해 주세요.\n정말로 테스트결제로 설정하시겠습니까?";
|
||||
}
|
||||
} else if ( f.de_pg_service.value == "inicis" ) {
|
||||
if( f.de_inicis_mid.value && f.de_inicis_sign_key.value && parseInt(f.de_card_test.value) > 0 ){
|
||||
pg_msg = "KG이니시스";
|
||||
}
|
||||
} else if ( f.de_pg_service.value == "nicepay" ) {
|
||||
if( f.de_nicepay_mid.value && f.de_nicepay_key.value && parseInt(f.de_card_test.value) > 0 ){
|
||||
pg_msg = "NICEPAY";
|
||||
}
|
||||
}
|
||||
|
||||
if( pg_msg ){
|
||||
@@ -2051,4 +2141,5 @@ if($default['de_iche_use'] || $default['de_vbank_use'] || $default['de_hp_use']
|
||||
}
|
||||
}
|
||||
|
||||
include_once (G5_ADMIN_PATH.'/admin.tail.php');
|
||||
|
||||
include_once (G5_ADMIN_PATH.'/admin.tail.php');
|
||||
|
||||
@@ -64,6 +64,8 @@ foreach($check_skin_keys as $key){
|
||||
if( isset($_POST[$key]) && preg_match('#\.+(\/|\\\)#', $_POST[$key]) ){
|
||||
alert('스킨설정에 유효하지 문자가 포함되어 있습니다.');
|
||||
}
|
||||
|
||||
$$key = $_POST[$key] = sql_real_escape_string($_POST[$key]);
|
||||
}
|
||||
|
||||
// 현금영수증 발급수단
|
||||
@@ -159,6 +161,8 @@ $check_sanitize_keys = array(
|
||||
'de_kcp_site_key', //NHN KCP SITE KEY
|
||||
'cf_lg_mid', //LG유플러스 상점아이디
|
||||
'cf_lg_mert_key', //LG유플러스 MERT KEY
|
||||
'cf_toss_client_key', //토스페이먼츠 MERT KEY
|
||||
'cf_toss_secret_key', //토스페이먼츠 MERT KEY
|
||||
'de_inicis_mid', //KG이니시스 상점아이디
|
||||
'de_inicis_iniapi_key', //KG이니시스 INIAPI KEY
|
||||
'de_inicis_iniapi_iv', //KG이니시스 INIAPI IV
|
||||
@@ -167,6 +171,8 @@ $check_sanitize_keys = array(
|
||||
'de_inicis_lpay_use', //KG이니시스 Lpay 사용
|
||||
'de_inicis_kakaopay_use', //KG이니시스 카카오페이 사용
|
||||
'de_inicis_cartpoint_use', //KG이니시스 신용카드 포인트 결제
|
||||
'de_nicepay_mid', //NICEPAY 상점아이디
|
||||
'de_nicepay_key', //NICEPAY 상점키
|
||||
'de_kakaopay_mid', //카카오페이 상점MID
|
||||
'de_kakaopay_key', //카카오페이 상점키
|
||||
'de_kakaopay_enckey', //카카오페이 상점 EncKey
|
||||
@@ -241,9 +247,9 @@ $check_sanitize_keys = array(
|
||||
|
||||
foreach( $check_sanitize_keys as $key ){
|
||||
if( in_array($key, array('de_bank_account')) ){
|
||||
$$key = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1, 0, 0) : '';
|
||||
$$key = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1, 0, 0)) : '';
|
||||
} else {
|
||||
$$key = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
|
||||
$$key = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
|
||||
}
|
||||
}
|
||||
|
||||
@@ -377,6 +383,8 @@ $sql = " update {$g5['g5_shop_default_table']}
|
||||
de_inicis_lpay_use = '{$de_inicis_lpay_use}',
|
||||
de_inicis_kakaopay_use = '{$de_inicis_kakaopay_use}',
|
||||
de_inicis_cartpoint_use = '{$de_inicis_cartpoint_use}',
|
||||
de_nicepay_mid = '{$de_nicepay_mid}',
|
||||
de_nicepay_key = '{$de_nicepay_key}',
|
||||
de_card_noint_use = '{$de_card_noint_use}',
|
||||
de_card_point = '{$de_card_point}',
|
||||
de_settle_min_point = '{$de_settle_min_point}',
|
||||
@@ -461,7 +469,9 @@ $sql = " update {$g5['config_table']}
|
||||
cf_icode_server_port = '{$_POST['cf_icode_server_port']}',
|
||||
cf_icode_token_key = '{$cf_icode_token_key}',
|
||||
cf_lg_mid = '{$cf_lg_mid}',
|
||||
cf_lg_mert_key = '{$cf_lg_mert_key}' ";
|
||||
cf_lg_mert_key = '{$cf_lg_mert_key}',
|
||||
cf_toss_client_key = '{$cf_toss_client_key}',
|
||||
cf_toss_secret_key = '{$cf_toss_secret_key}' ";
|
||||
sql_query($sql);
|
||||
|
||||
run_event('shop_admin_configformupdate');
|
||||
@@ -470,4 +480,4 @@ if( $warning_msg ){
|
||||
alert($warning_msg, "./configform.php");
|
||||
} else {
|
||||
goto_url("./configform.php");
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,7 +4,7 @@ include_once('./_common.php');
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
$cp_id = isset($_REQUEST['cp_id']) ? clean_xss_tags($_REQUEST['cp_id'], 1, 1) : '';
|
||||
$cp_id = isset($_REQUEST['cp_id']) ? safe_replace_regex($_REQUEST['cp_id'], 'cp_id') : '';
|
||||
$cp = array(
|
||||
'cp_method'=>'',
|
||||
'cp_subject'=>'',
|
||||
@@ -46,13 +46,13 @@ include_once(G5_PLUGIN_PATH.'/jquery-ui/datepicker.php');
|
||||
?>
|
||||
|
||||
<form name="fcouponform" action="./couponformupdate.php" method="post" onsubmit="return form_check(this);">
|
||||
<input type="hidden" name="w" value="<?php echo $w; ?>">
|
||||
<input type="hidden" name="cp_id" value="<?php echo $cp_id; ?>">
|
||||
<input type="hidden" name="sst" value="<?php echo $sst; ?>">
|
||||
<input type="hidden" name="sod" value="<?php echo $sod; ?>">
|
||||
<input type="hidden" name="sfl" value="<?php echo $sfl; ?>">
|
||||
<input type="hidden" name="stx" value="<?php echo $stx; ?>">
|
||||
<input type="hidden" name="page" value="<?php echo $page;?>">
|
||||
<input type="hidden" name="w" value="<?php echo get_sanitize_input($w); ?>">
|
||||
<input type="hidden" name="cp_id" value="<?php echo get_sanitize_input($cp_id); ?>">
|
||||
<input type="hidden" name="sst" value="<?php echo get_sanitize_input($sst); ?>">
|
||||
<input type="hidden" name="sod" value="<?php echo get_sanitize_input($sod); ?>">
|
||||
<input type="hidden" name="sfl" value="<?php echo get_sanitize_input($sfl); ?>">
|
||||
<input type="hidden" name="stx" value="<?php echo get_sanitize_input($stx); ?>">
|
||||
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page);?>">
|
||||
|
||||
<div class="tbl_frm01 tbl_wrap">
|
||||
<table>
|
||||
@@ -292,4 +292,4 @@ function form_check(f)
|
||||
</script>
|
||||
|
||||
<?php
|
||||
include_once (G5_ADMIN_PATH.'/admin.tail.php');
|
||||
include_once (G5_ADMIN_PATH.'/admin.tail.php');
|
||||
|
||||
@@ -6,6 +6,8 @@ auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
check_admin_token();
|
||||
|
||||
$cp_id = isset($_REQUEST['cp_id']) ? safe_replace_regex($_REQUEST['cp_id'], 'cp_id') : '';
|
||||
|
||||
$_POST = array_map('trim', $_POST);
|
||||
|
||||
$check_sanitize_keys = array(
|
||||
@@ -25,7 +27,7 @@ $check_sanitize_keys = array(
|
||||
);
|
||||
|
||||
foreach( $check_sanitize_keys as $key ){
|
||||
$$key = $_POST[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
|
||||
$$key = $_POST[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
|
||||
}
|
||||
|
||||
if(!$_POST['cp_subject'])
|
||||
@@ -264,4 +266,4 @@ if ($w == '' && (isset($_POST['cp_sms_send']) || isset($_POST['cp_email_send']))
|
||||
}
|
||||
}
|
||||
|
||||
goto_url('./couponlist.php');
|
||||
goto_url('./couponlist.php');
|
||||
|
||||
@@ -6,6 +6,8 @@ auth_check_menu($auth, $sub_menu, "r");
|
||||
|
||||
$sql_common = " from {$g5['g5_shop_coupon_table']} ";
|
||||
|
||||
if ($sfl && !in_array($sfl, array('mb_id', 'cp_subject', 'cp_id'))) $sfl = '';
|
||||
|
||||
$sql_search = " where (1) ";
|
||||
if ($stx) {
|
||||
$sql_search .= " and ( ";
|
||||
@@ -24,6 +26,9 @@ if (!$sst) {
|
||||
$sst = "cp_no";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('cp_no', 'cp_id', 'cp_subject', 'mb_id', 'cp_end', 'cp_start', 'cp_method');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'cp_no';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
|
||||
@@ -6,6 +6,8 @@ auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
check_admin_token();
|
||||
|
||||
$cz_id = isset($_REQUEST['cz_id']) ? (int) $_REQUEST['cz_id'] : 0;
|
||||
|
||||
@mkdir(G5_DATA_PATH."/coupon", G5_DIR_PERMISSION);
|
||||
@chmod(G5_DATA_PATH."/coupon", G5_DIR_PERMISSION);
|
||||
|
||||
@@ -28,7 +30,7 @@ $check_sanitize_keys = array(
|
||||
);
|
||||
|
||||
foreach( $check_sanitize_keys as $key ){
|
||||
$$key = $_POST[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
|
||||
$$key = $_POST[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
|
||||
}
|
||||
|
||||
if(!$_POST['cz_subject'])
|
||||
@@ -150,4 +152,4 @@ if($_FILES['cp_img']['tmp_name']) {
|
||||
sql_query($sql);
|
||||
}
|
||||
|
||||
goto_url('./couponzonelist.php?'.$qstr);
|
||||
goto_url('./couponzonelist.php?'.$qstr);
|
||||
|
||||
@@ -15,6 +15,9 @@ if (!$sst) {
|
||||
$sst = "cz_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('cz_id');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'cz_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
|
||||
@@ -20,6 +20,8 @@ if (!$od['od_id']) {
|
||||
|
||||
// 주문정보
|
||||
$data = unserialize(base64_decode($od['dt_data']));
|
||||
$data_od_cp_id = isset($data['od_cp_id']) ? safe_replace_regex($data['od_cp_id'], 'cp_id') : '';
|
||||
$data_sc_cp_id = isset($data['sc_cp_id']) ? safe_replace_regex($data['sc_cp_id'], 'cp_id') : '';
|
||||
|
||||
$sql_common = " from {$g5['g5_shop_cart_table']} where od_id = '{$od['cart_id']}' and ct_status = '쇼핑' and ct_select = '1' ";
|
||||
|
||||
@@ -38,8 +40,8 @@ if($od['mb_id']) {
|
||||
$it_cp_cnt = (isset($data['cp_id']) && is_array($data['cp_id'])) ? count($data['cp_id']) : 0;
|
||||
$arr_it_cp_prc = array();
|
||||
for($i=0; $i<$it_cp_cnt; $i++) {
|
||||
$cid = $data['cp_id'][$i];
|
||||
$it_id = $data['it_id'][$i];
|
||||
$cid = isset($data['cp_id'][$i]) ? safe_replace_regex($data['cp_id'][$i], 'cp_id') : '';
|
||||
$it_id = isset($data['it_id'][$i]) ? safe_replace_regex($data['it_id'][$i], 'it_id') : '';
|
||||
$sql = " select cp_id, cp_method, cp_target, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
|
||||
from {$g5['g5_shop_coupon_table']}
|
||||
where cp_id = '$cid'
|
||||
@@ -98,10 +100,10 @@ if($od['mb_id']) {
|
||||
$tot_od_price -= $tot_it_cp_price;
|
||||
|
||||
// 주문쿠폰
|
||||
if(isset($data['od_cp_id']) && $data['od_cp_id']) {
|
||||
if($data_od_cp_id) {
|
||||
$sql = " select cp_id, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
|
||||
from {$g5['g5_shop_coupon_table']}
|
||||
where cp_id = '{$data['od_cp_id']}'
|
||||
where cp_id = '$data_od_cp_id'
|
||||
and mb_id IN ( '{$od['mb_id']}', '전체회원' )
|
||||
and cp_method = '2' ";
|
||||
$cp = sql_fetch($sql);
|
||||
@@ -134,10 +136,10 @@ $od_send_cost = get_sendcost($od['cart_id']);
|
||||
$tot_sc_cp_price = 0;
|
||||
if($od['mb_id'] && $od_send_cost > 0) {
|
||||
// 배송쿠폰
|
||||
if($data['sc_cp_id']) {
|
||||
if($data_sc_cp_id) {
|
||||
$sql = " select cp_id, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
|
||||
from {$g5['g5_shop_coupon_table']}
|
||||
where cp_id = '{$data['sc_cp_id']}'
|
||||
where cp_id = '$data_sc_cp_id'
|
||||
and mb_id IN ( '{$od['mb_id']}', '전체회원' )
|
||||
and cp_method = '3' ";
|
||||
$cp = sql_fetch($sql);
|
||||
@@ -571,4 +573,4 @@ function del_confirm()
|
||||
</script>
|
||||
|
||||
<?php
|
||||
include_once(G5_ADMIN_PATH.'/admin.tail.php');
|
||||
include_once(G5_ADMIN_PATH.'/admin.tail.php');
|
||||
|
||||
@@ -30,6 +30,8 @@ if($w == 'd') {
|
||||
|
||||
// 주문정보
|
||||
$data = unserialize(base64_decode($od['dt_data']));
|
||||
$data_od_cp_id = isset($data['od_cp_id']) ? safe_replace_regex($data['od_cp_id'], 'cp_id') : '';
|
||||
$data_sc_cp_id = isset($data['sc_cp_id']) ? safe_replace_regex($data['sc_cp_id'], 'cp_id') : '';
|
||||
|
||||
$sql_common = " from {$g5['g5_shop_cart_table']} where od_id = '{$od['cart_id']}' and ct_status = '쇼핑' ";
|
||||
|
||||
@@ -53,8 +55,8 @@ if($od['mb_id']) {
|
||||
$it_cp_cnt = (isset($data['cp_id']) && is_array($data['cp_id'])) ? count($data['cp_id']) : 0;
|
||||
$arr_it_cp_prc = array();
|
||||
for($i=0; $i<$it_cp_cnt; $i++) {
|
||||
$cid = $data['cp_id'][$i];
|
||||
$it_id = $data['it_id'][$i];
|
||||
$cid = isset($data['cp_id'][$i]) ? safe_replace_regex($data['cp_id'][$i], 'cp_id') : '';
|
||||
$it_id = isset($data['it_id'][$i]) ? safe_replace_regex($data['it_id'][$i], 'it_id') : '';
|
||||
$sql = " select cp_id, cp_method, cp_target, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
|
||||
from {$g5['g5_shop_coupon_table']}
|
||||
where cp_id = '$cid'
|
||||
@@ -113,10 +115,10 @@ if($od['mb_id']) {
|
||||
$tot_od_price -= $tot_it_cp_price;
|
||||
|
||||
// 주문쿠폰
|
||||
if(isset($data['od_cp_id']) && $data['od_cp_id']) {
|
||||
if($data_od_cp_id) {
|
||||
$sql = " select cp_id, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
|
||||
from {$g5['g5_shop_coupon_table']}
|
||||
where cp_id = '{$data['od_cp_id']}'
|
||||
where cp_id = '$data_od_cp_id'
|
||||
and mb_id IN ( '{$od['mb_id']}', '전체회원' )
|
||||
and cp_method = '2' ";
|
||||
$cp = sql_fetch($sql);
|
||||
@@ -149,10 +151,10 @@ $od_send_cost = get_sendcost($od['cart_id']);
|
||||
$tot_sc_cp_price = 0;
|
||||
if($od['mb_id'] && $od_send_cost > 0) {
|
||||
// 배송쿠폰
|
||||
if($data['sc_cp_id']) {
|
||||
if($data_sc_cp_id) {
|
||||
$sql = " select cp_id, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
|
||||
from {$g5['g5_shop_coupon_table']}
|
||||
where cp_id = '{$data['sc_cp_id']}'
|
||||
where cp_id = '$data_sc_cp_id'
|
||||
and mb_id IN ( '{$od['mb_id']}', '전체회원' )
|
||||
and cp_method = '3' ";
|
||||
$cp = sql_fetch($sql);
|
||||
@@ -212,38 +214,38 @@ if($data['od_settle_case'] == 'KAKAOPAY')
|
||||
$od_pg = 'KAKAOPAY';
|
||||
|
||||
$od_email = get_email_address($data['od_email']);
|
||||
$od_name = clean_xss_tags($data['od_name']);
|
||||
$od_tel = clean_xss_tags($data['od_tel']);
|
||||
$od_hp = clean_xss_tags($data['od_hp']);
|
||||
$od_name = addslashes(clean_xss_tags($data['od_name']));
|
||||
$od_tel = addslashes(clean_xss_tags($data['od_tel']));
|
||||
$od_hp = addslashes(clean_xss_tags($data['od_hp']));
|
||||
$od_zip = preg_replace('/[^0-9]/', '', $data['od_zip']);
|
||||
$od_zip1 = substr($od_zip, 0, 3);
|
||||
$od_zip2 = substr($od_zip, 3);
|
||||
$od_addr1 = clean_xss_tags($data['od_addr1']);
|
||||
$od_addr2 = clean_xss_tags($data['od_addr2']);
|
||||
$od_addr3 = clean_xss_tags($data['od_addr3']);
|
||||
$od_addr_jibeon = preg_match("/^(N|R)$/", $data['od_addr_jibeon']) ? $data['od_addr_jibeon'] : '';
|
||||
$od_b_name = clean_xss_tags($data['od_b_name']);
|
||||
$od_b_tel = clean_xss_tags($data['od_b_tel']);
|
||||
$od_b_hp = clean_xss_tags($data['od_b_hp']);
|
||||
$od_addr1 = addslashes(clean_xss_tags($data['od_addr1']));
|
||||
$od_addr2 = addslashes(clean_xss_tags($data['od_addr2']));
|
||||
$od_addr3 = addslashes(clean_xss_tags($data['od_addr3']));
|
||||
$od_addr_jibeon = preg_match("/^(N|R|J)$/", $data['od_addr_jibeon']) ? $data['od_addr_jibeon'] : '';
|
||||
$od_b_name = addslashes(clean_xss_tags($data['od_b_name']));
|
||||
$od_b_tel = addslashes(clean_xss_tags($data['od_b_tel']));
|
||||
$od_b_hp = addslashes(clean_xss_tags($data['od_b_hp']));
|
||||
$od_b_zip = preg_replace('/[^0-9]/', '', $data['od_b_zip']);
|
||||
$od_b_zip1 = substr($od_b_zip, 0, 3);
|
||||
$od_b_zip2 = substr($od_b_zip, 3);
|
||||
$od_b_addr1 = clean_xss_tags($data['od_b_addr1']);
|
||||
$od_b_addr2 = clean_xss_tags($data['od_b_addr2']);
|
||||
$od_b_addr3 = clean_xss_tags($data['od_b_addr3']);
|
||||
$od_b_addr_jibeon = preg_match("/^(N|R)$/", $data['od_b_addr_jibeon']) ? $data['od_b_addr_jibeon'] : '';
|
||||
$od_memo = clean_xss_tags($data['od_memo'], 0, 1, 0, 0);
|
||||
$od_deposit_name = clean_xss_tags($data['od_deposit_name']);
|
||||
$od_b_addr1 = addslashes(clean_xss_tags($data['od_b_addr1']));
|
||||
$od_b_addr2 = addslashes(clean_xss_tags($data['od_b_addr2']));
|
||||
$od_b_addr3 = addslashes(clean_xss_tags($data['od_b_addr3']));
|
||||
$od_b_addr_jibeon = preg_match("/^(N|R|J)$/", $data['od_b_addr_jibeon']) ? $data['od_b_addr_jibeon'] : '';
|
||||
$od_memo = addslashes(clean_xss_tags($data['od_memo'], 0, 1, 0, 0));
|
||||
$od_deposit_name = addslashes(clean_xss_tags($data['od_deposit_name']));
|
||||
$od_tax_flag = $default['de_tax_flag_use'];
|
||||
$od_receipt_price = $tot_ct_price + $od_send_cost + $od_send_cost2 - ($od_temp_point + $tot_cp_price + $tot_sc_cp_price);
|
||||
$od_receipt_point = $od_temp_point;
|
||||
$od_receipt_time = $od['dt_time'];
|
||||
$od_misu = 0;
|
||||
$od_status = '입금';
|
||||
$od_bank_account = isset($data['od_bank_account']) ? clean_xss_tags($data['od_bank_account'], 1, 1) : '';
|
||||
$od_bank_account = isset($data['od_bank_account']) ? addslashes(clean_xss_tags(stripslashes($data['od_bank_account']), 1, 1)) : '';
|
||||
$od_tno = '';
|
||||
$od_app_no = '';
|
||||
$od_hope_date = isset($data['od_hope_date']) ? clean_xss_tags($data['od_hope_date'], 1, 1) : '';
|
||||
$od_hope_date = isset($data['od_hope_date']) ? addslashes(clean_xss_tags(stripslashes($data['od_hope_date']), 1, 1)) : '';
|
||||
|
||||
// 주문서에 입력
|
||||
$sql = " insert {$g5['g5_shop_order_table']}
|
||||
@@ -321,8 +323,8 @@ if ($od['mb_id'] && $od_receipt_point)
|
||||
if($od['mb_id']) {
|
||||
$it_cp_cnt = (isset($data['cp_id']) && is_array($data['cp_id'])) ? count($data['cp_id']) : 0;
|
||||
for($i=0; $i<$it_cp_cnt; $i++) {
|
||||
$cid = $data['cp_id'][$i];
|
||||
$cp_it_id = $data['it_id'][$i];
|
||||
$cid = isset($data['cp_id'][$i]) ? safe_replace_regex($data['cp_id'][$i], 'cp_id') : '';
|
||||
$cp_it_id = isset($data['it_id'][$i]) ? safe_replace_regex($data['it_id'][$i], 'it_id') : '';
|
||||
$cp_prc = isset($arr_it_cp_prc[$cp_it_id]) ? (int) $arr_it_cp_prc[$cp_it_id] : 0;
|
||||
|
||||
if(trim($cid)) {
|
||||
@@ -346,9 +348,9 @@ if($od['mb_id']) {
|
||||
sql_query($sql);
|
||||
}
|
||||
|
||||
if(isset($data['od_cp_id']) && $data['od_cp_id']) {
|
||||
if($data_od_cp_id) {
|
||||
$sql = " insert into {$g5['g5_shop_coupon_log_table']}
|
||||
set cp_id = '{$data['od_cp_id']}',
|
||||
set cp_id = '$data_od_cp_id',
|
||||
mb_id = '{$od['mb_id']}',
|
||||
od_id = '$od_id',
|
||||
cp_price = '$tot_od_cp_price',
|
||||
@@ -356,9 +358,9 @@ if($od['mb_id']) {
|
||||
sql_query($sql);
|
||||
}
|
||||
|
||||
if(isset($data['sc_cp_id']) && $data['sc_cp_id']) {
|
||||
if($data_sc_cp_id) {
|
||||
$sql = " insert into {$g5['g5_shop_coupon_log_table']}
|
||||
set cp_id = '{$data['sc_cp_id']}',
|
||||
set cp_id = '$data_sc_cp_id',
|
||||
mb_id = '{$od['mb_id']}',
|
||||
od_id = '$od_id',
|
||||
cp_price = '$tot_sc_cp_price',
|
||||
@@ -384,10 +386,16 @@ sql_query($sql);
|
||||
$sql = " delete from {$g5['g5_shop_order_data_table']} where od_id = '$od_id' and dt_pg = '$od_pg' ";
|
||||
sql_query($sql, true);
|
||||
|
||||
$orderform_url = './orderform.php?od_id='.$od_id;
|
||||
$inorderlist_url = './inorderlist.php?'.str_replace('&', '&', $qstr);
|
||||
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
|
||||
$js_orderform_url = function_exists('get_js_safe_string') ? get_js_safe_string($orderform_url) : '"'.strtr((string)$orderform_url, $js_replace).'"';
|
||||
$js_inorderlist_url = function_exists('get_js_safe_string') ? get_js_safe_string($inorderlist_url) : '"'.strtr((string)$inorderlist_url, $js_replace).'"';
|
||||
|
||||
echo '<meta http-equiv="content-type" content="text/html; charset=utf-8">'.PHP_EOL;
|
||||
echo '<script>'.PHP_EOL;
|
||||
echo 'if(confirm("복구하신 주문 상세페이지로 이동하시겠습니까?"))'.PHP_EOL;
|
||||
echo 'document.location.href = "./orderform.php?od_id='.$od_id.'";'.PHP_EOL;
|
||||
echo 'document.location.href = '.$js_orderform_url.';'.PHP_EOL;
|
||||
echo 'else'.PHP_EOL;
|
||||
echo 'document.location.href = "./inorderlist.php?'.str_replace('&', '&', $qstr).'";'.PHP_EOL;
|
||||
echo '</script>'.PHP_EOL;
|
||||
echo 'document.location.href = '.$js_inorderlist_url.';'.PHP_EOL;
|
||||
echo '</script>'.PHP_EOL;
|
||||
|
||||
@@ -24,6 +24,9 @@ if (!$sst) {
|
||||
$sst = "od_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('od_id');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'od_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
@@ -104,6 +107,12 @@ $colspan = 10;
|
||||
case 'lg':
|
||||
$pg = 'LGU+';
|
||||
break;
|
||||
case 'toss':
|
||||
$pg = '토스페이먼츠';
|
||||
break;
|
||||
case 'nicepay':
|
||||
$pg = 'NICEPAY';
|
||||
break;
|
||||
default:
|
||||
$pg = 'KCP';
|
||||
break;
|
||||
|
||||
@@ -67,7 +67,9 @@ for ($i=0; $row=sql_fetch_array($result); $i++)
|
||||
for ($i=0; $i<$len; $i++)
|
||||
$nbsp .= " ";
|
||||
|
||||
$category_select .= "<option value=\"{$row['ca_id']}\">$nbsp{$row['ca_name']}</option>\n";
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row['ca_id']) : $row['ca_name'];
|
||||
$category_select .= "<option value=\"{$row['ca_id']}\">$nbsp{$category_path}</option>\n";
|
||||
}
|
||||
|
||||
// 모바일 1줄당 이미지수 필드 추가
|
||||
|
||||
@@ -33,7 +33,7 @@ $ev_mobile_list_row = isset($_POST['ev_mobile_list_row']) ? (int) $_POST['ev_mob
|
||||
$ev_use = isset($_POST['ev_use']) ? (int) $_POST['ev_use'] : 0;
|
||||
$ev_subject_strong = isset($_POST['ev_subject_strong']) ? (int) $_POST['ev_subject_strong'] : 0;
|
||||
|
||||
$ev_subject = isset($_POST['ev_subject']) ? clean_xss_tags($_POST['ev_subject'], 1, 1) : '';
|
||||
$ev_subject = isset($_POST['ev_subject']) ? addslashes(clean_xss_tags(stripslashes($_POST['ev_subject']), 1, 1)) : '';
|
||||
$ev_head_html = isset($_POST['ev_head_html']) ? $_POST['ev_head_html'] : '';
|
||||
$ev_tail_html = isset($_POST['ev_tail_html']) ? $_POST['ev_tail_html'] : '';
|
||||
|
||||
@@ -129,4 +129,4 @@ if ($w == "" || $w == "u")
|
||||
else
|
||||
{
|
||||
goto_url("./itemevent.php");
|
||||
}
|
||||
}
|
||||
|
||||
@@ -107,7 +107,9 @@ if($ev_id) {
|
||||
$len = strlen($row1['ca_id']) / 2 - 1;
|
||||
$nbsp = "";
|
||||
for ($i=0; $i<$len; $i++) $nbsp .= " ";
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
@@ -105,7 +105,7 @@ else if ($w == "u")
|
||||
and b.ca_mb_id = '{$member['mb_id']}' ";
|
||||
$row = sql_fetch($sql);
|
||||
if (!$row['it_id'])
|
||||
alert("\'{$member['mb_id']}\' 님께서 수정 할 권한이 없는 상품입니다.");
|
||||
alert("'{$member['mb_id']}' 님께서 수정 할 권한이 없는 상품입니다.");
|
||||
}
|
||||
|
||||
$it = get_shop_item($it_id);
|
||||
@@ -146,9 +146,11 @@ for ($i=0; $row=sql_fetch_array($result); $i++)
|
||||
$nbsp = "";
|
||||
for ($i=0; $i<$len; $i++)
|
||||
$nbsp .= " ";
|
||||
|
||||
$category_select .= "<option value=\"{$row['ca_id']}\">$nbsp{$row['ca_name']}</option>\n";
|
||||
|
||||
|
||||
// 전체 카테고리 경로 표시 (예: 남성의류 > 상의 > 셔츠)
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row['ca_id']) : $row['ca_name'];
|
||||
$category_select .= "<option value=\"{$row['ca_id']}\">$nbsp{$category_path}</option>\n";
|
||||
|
||||
$script .= "ca_use['{$row['ca_id']}'] = {$row['ca_use']};\n";
|
||||
$script .= "ca_stock_qty['{$row['ca_id']}'] = {$row['ca_stock_qty']};\n";
|
||||
//$script .= "ca_explan_html['$row[ca_id]'] = $row[ca_explan_html];\n";
|
||||
@@ -1394,7 +1396,9 @@ $(function(){
|
||||
for ($i=0; $i<$len; $i++)
|
||||
$nbsp .= " ";
|
||||
|
||||
echo "<option value=\"{$row['ca_id']}\">$nbsp{$row['ca_name']}</option>\n";
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row['ca_id']) : $row['ca_name'];
|
||||
echo "<option value=\"{$row['ca_id']}\">$nbsp{$category_path}</option>\n";
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
@@ -1897,4 +1901,4 @@ categorychange(document.fitemform);
|
||||
</script>
|
||||
|
||||
<?php
|
||||
include_once (G5_ADMIN_PATH.'/admin.tail.php');
|
||||
include_once (G5_ADMIN_PATH.'/admin.tail.php');
|
||||
|
||||
@@ -235,6 +235,14 @@ sql_query(" delete from {$g5['g5_shop_event_item_table']} where it_id = '$it_id'
|
||||
// 선택옵션
|
||||
sql_query(" delete from {$g5['g5_shop_item_option_table']} where io_type = '0' and it_id = '$it_id' "); // 기존선택옵션삭제
|
||||
|
||||
// 금지할 패턴 목록
|
||||
$forbidden_patterns = array(
|
||||
'/<\s*script/i', // <script>
|
||||
'/<\s*iframe/i', // <iframe>
|
||||
'/on\w+\s*=/i', // onclick=, onerror= 등 이벤트 핸들러
|
||||
'/javascript:/i' // javascript: 프로토콜
|
||||
);
|
||||
|
||||
$option_count = (isset($_POST['opt_id']) && is_array($_POST['opt_id'])) ? count($_POST['opt_id']) : array();
|
||||
$it_option_subject = '';
|
||||
$it_supply_subject = '';
|
||||
@@ -243,8 +251,18 @@ if($option_count) {
|
||||
// 옵션명
|
||||
$opt1_cnt = $opt2_cnt = $opt3_cnt = 0;
|
||||
for($i=0; $i<$option_count; $i++) {
|
||||
$post_opt_id = isset($_POST['opt_id'][$i]) ? preg_replace(G5_OPTION_ID_FILTER, '', strip_tags($_POST['opt_id'][$i])) : '';
|
||||
|
||||
$post_opt_id = isset($_POST['opt_id'][$i]) ? $_POST['opt_id'][$i] : '';
|
||||
|
||||
foreach ($forbidden_patterns as $pattern) {
|
||||
if (preg_match($pattern, $post_opt_id)) {
|
||||
$post_opt_id = '';
|
||||
$_POST['opt_id'][$i] = '';
|
||||
continue 2;
|
||||
}
|
||||
}
|
||||
|
||||
$post_opt_id = preg_replace(G5_OPTION_ID_FILTER, '', strip_tags($post_opt_id));
|
||||
|
||||
$opt_val = explode(chr(30), $post_opt_id);
|
||||
if(isset($opt_val[0]) && $opt_val[0])
|
||||
$opt1_cnt++;
|
||||
@@ -271,8 +289,18 @@ if($supply_count) {
|
||||
// 추가옵션명
|
||||
$arr_spl = array();
|
||||
for($i=0; $i<$supply_count; $i++) {
|
||||
$post_spl_id = isset($_POST['spl_id'][$i]) ? preg_replace(G5_OPTION_ID_FILTER, '', strip_tags($_POST['spl_id'][$i])) : '';
|
||||
|
||||
$post_spl_id = isset($_POST['spl_id'][$i]) ? $_POST['spl_id'][$i] : '';
|
||||
|
||||
foreach ($forbidden_patterns as $pattern) {
|
||||
if (preg_match($pattern, $post_spl_id)) {
|
||||
$post_spl_id = '';
|
||||
$_POST['spl_id'][$i] = '';
|
||||
continue 2;
|
||||
}
|
||||
}
|
||||
|
||||
$post_spl_id = preg_replace(G5_OPTION_ID_FILTER, '', strip_tags($post_spl_id));
|
||||
|
||||
$spl_val = explode(chr(30), $post_spl_id);
|
||||
if(!in_array($spl_val[0], $arr_spl))
|
||||
$arr_spl[] = $spl_val[0];
|
||||
@@ -291,7 +319,7 @@ for($i=0; $i<$count_ii_article; $i++) {
|
||||
}
|
||||
$it_info_value = addslashes(serialize($value_array));
|
||||
|
||||
$it_name = isset($_POST['it_name']) ? strip_tags(clean_xss_attributes(trim($_POST['it_name']))) : '';
|
||||
$it_name = isset($_POST['it_name']) ? addslashes(strip_tags(clean_xss_attributes(trim(stripslashes($_POST['it_name']))))) : '';
|
||||
|
||||
// KVE-2019-0708
|
||||
$check_sanitize_keys = array(
|
||||
@@ -328,7 +356,7 @@ $check_sanitize_keys = array(
|
||||
);
|
||||
|
||||
foreach( $check_sanitize_keys as $key ){
|
||||
$$key = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
|
||||
$$key = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
|
||||
}
|
||||
|
||||
$it_basic = preg_replace('#<script(.*?)>(.*?)<\/script>#is', '', $it_basic);
|
||||
@@ -337,6 +365,18 @@ $it_explan = isset($_POST['it_explan']) ? $_POST['it_explan'] : '';
|
||||
if ($it_name == "")
|
||||
alert("상품명을 입력해 주십시오.");
|
||||
|
||||
// 상품 스킨은 파일 경로가 아니라 스킨 디렉토리명(basic, theme/basic 등)을 저장한다.
|
||||
$it_skin = isset($_POST['it_skin']) ? trim(strip_tags(clean_xss_attributes(stripslashes($_POST['it_skin'])))) : '';
|
||||
$it_mobile_skin = isset($_POST['it_mobile_skin']) ? trim(strip_tags(clean_xss_attributes(stripslashes($_POST['it_mobile_skin'])))) : '';
|
||||
|
||||
if (function_exists('check_shop_skin_dir')) {
|
||||
check_shop_skin_dir($it_skin, 'PC용 스킨');
|
||||
check_shop_skin_dir($it_mobile_skin, '모바일용 스킨', true);
|
||||
}
|
||||
|
||||
$it_skin = addslashes($it_skin);
|
||||
$it_mobile_skin = addslashes($it_mobile_skin);
|
||||
|
||||
$sql_common = " ca_id = '$ca_id',
|
||||
ca_id2 = '$ca_id2',
|
||||
ca_id3 = '$ca_id3',
|
||||
@@ -356,7 +396,7 @@ $sql_common = " ca_id = '$ca_id',
|
||||
it_type5 = '$it_type5',
|
||||
it_basic = '$it_basic',
|
||||
it_explan = '$it_explan',
|
||||
it_explan2 = '".strip_tags(trim(clean_xss_attributes($it_explan)))."',
|
||||
it_explan2 = '".addslashes(strip_tags(trim(clean_xss_attributes(stripslashes($it_explan)))))."',
|
||||
it_mobile_explan = '$it_mobile_explan',
|
||||
it_cust_price = '$it_cust_price',
|
||||
it_price = '$it_price',
|
||||
@@ -459,7 +499,7 @@ else if ($w == "d")
|
||||
and b.ca_mb_id = '{$member['mb_id']}' ";
|
||||
$row = sql_fetch($sql);
|
||||
if (!$row['it_id'])
|
||||
alert("\'{$member['mb_id']}\' 님께서 삭제 할 권한이 없는 상품입니다.");
|
||||
alert("'{$member['mb_id']}' 님께서 삭제 할 권한이 없는 상품입니다.");
|
||||
}
|
||||
|
||||
itemdelete($it_id);
|
||||
|
||||
@@ -25,7 +25,8 @@ for ($i=0; $row=sql_fetch_array($result); $i++)
|
||||
for ($i=0; $i<$len; $i++) {
|
||||
$nbsp .= ' ';
|
||||
}
|
||||
$ca_list .= '<option value="'.$row['ca_id'].'">'.$nbsp.$row['ca_name'].'</option>'.PHP_EOL;
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row['ca_id']) : $row['ca_name'];
|
||||
$ca_list .= '<option value="'.$row['ca_id'].'">'.$nbsp.$category_path.'</option>'.PHP_EOL;
|
||||
}
|
||||
|
||||
$where = " and ";
|
||||
@@ -67,6 +68,9 @@ if (!$sst) {
|
||||
$sst = "it_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('it_id', 'it_name', 'it_order', 'it_use', 'it_soldout', 'it_hit', 'it_price', 'it_cust_price', 'it_point', 'it_stock_qty');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'it_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = "order by $sst $sod";
|
||||
|
||||
|
||||
@@ -100,7 +104,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
$len = strlen($row1['ca_id']) / 2 - 1;
|
||||
$nbsp = '';
|
||||
for ($i=0; $i<$len; $i++) $nbsp .= ' ';
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sca, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sca, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
@@ -29,17 +29,22 @@ if ($post_act_button == "선택수정") {
|
||||
$p_ca_id = (isset($_POST['ca_id']) && is_array($_POST['ca_id'])) ? strip_tags($_POST['ca_id'][$k]) : '';
|
||||
$p_ca_id2 = (isset($_POST['ca_id2']) && is_array($_POST['ca_id2'])) ? strip_tags($_POST['ca_id2'][$k]) : '';
|
||||
$p_ca_id3 = (isset($_POST['ca_id3']) && is_array($_POST['ca_id3'])) ? strip_tags($_POST['ca_id3'][$k]) : '';
|
||||
$p_it_name = (isset($_POST['it_name']) && is_array($_POST['it_name'])) ? strip_tags(clean_xss_attributes($_POST['it_name'][$k])) : '';
|
||||
$p_it_name = (isset($_POST['it_name']) && is_array($_POST['it_name'])) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['it_name'][$k])))) : '';
|
||||
$p_it_cust_price = (isset($_POST['it_cust_price']) && is_array($_POST['it_cust_price'])) ? strip_tags($_POST['it_cust_price'][$k]) : '';
|
||||
$p_it_price = (isset($_POST['it_price']) && is_array($_POST['it_price'])) ? strip_tags($_POST['it_price'][$k]) : '';
|
||||
$p_it_stock_qty = (isset($_POST['it_stock_qty']) && is_array($_POST['it_stock_qty'])) ? strip_tags($_POST['it_stock_qty'][$k]) : '';
|
||||
$p_it_skin = (isset($_POST['it_skin']) && is_array($_POST['it_skin'])) ? strip_tags($_POST['it_skin'][$k]) : '';
|
||||
$p_it_mobile_skin = (isset($_POST['it_mobile_skin']) && is_array($_POST['it_mobile_skin'])) ? strip_tags($_POST['it_mobile_skin'][$k]) : '';
|
||||
$p_it_skin = (isset($_POST['it_skin']) && is_array($_POST['it_skin'])) ? trim(strip_tags(clean_xss_attributes(stripslashes($_POST['it_skin'][$k])))) : '';
|
||||
$p_it_mobile_skin = (isset($_POST['it_mobile_skin']) && is_array($_POST['it_mobile_skin'])) ? trim(strip_tags(clean_xss_attributes(stripslashes($_POST['it_mobile_skin'][$k])))) : '';
|
||||
$p_it_use = isset($_POST['it_use'][$k]) ? clean_xss_tags($_POST['it_use'][$k], 1, 1) : 0;
|
||||
$p_it_soldout = isset($_POST['it_soldout'][$k]) ? clean_xss_tags($_POST['it_soldout'][$k], 1, 1) : 0;
|
||||
$p_it_order = (isset($_POST['it_order']) && is_array($_POST['it_order'])) ? strip_tags($_POST['it_order'][$k]) : '';
|
||||
$p_it_id = isset($_POST['it_id'][$k]) ? preg_replace('/[^a-z0-9_\-]/i', '', $_POST['it_id'][$k]) : '';
|
||||
|
||||
if (function_exists('check_shop_skin_dir')) {
|
||||
check_shop_skin_dir($p_it_skin, 'PC용 스킨');
|
||||
check_shop_skin_dir($p_it_mobile_skin, '모바일용 스킨', true);
|
||||
}
|
||||
|
||||
if ($is_admin != 'super') { // 최고관리자가 아니면 체크
|
||||
$sql = "select a.it_id, b.ca_mb_id from {$g5['g5_shop_item_table']} a , {$g5['g5_shop_category_table']} b where (a.ca_id = b.ca_id) and a.it_id = '$p_it_id'";
|
||||
$checks = sql_fetch($sql);
|
||||
@@ -89,4 +94,4 @@ if ($post_act_button == "선택수정") {
|
||||
}
|
||||
}
|
||||
|
||||
goto_url("./itemlist.php?sca=$sca&sst=$sst&sod=$sod&sfl=$sfl&stx=$stx&page=$page");
|
||||
goto_url("./itemlist.php?sca=$sca&sst=$sst&sod=$sod&sfl=$sfl&stx=$stx&page=$page");
|
||||
|
||||
@@ -84,11 +84,11 @@ if($po_run) {
|
||||
?>
|
||||
<tr>
|
||||
<td class="td_chk">
|
||||
<input type="hidden" name="opt_id[]" value="<?php echo $opt_id; ?>">
|
||||
<input type="hidden" name="opt_id[]" value="<?php echo get_text($opt_id); ?>">
|
||||
<label for="opt_chk_<?php echo $i; ?>" class="sound_only"></label>
|
||||
<input type="checkbox" name="opt_chk[]" id="opt_chk_<?php echo $i; ?>" value="1">
|
||||
</td>
|
||||
<td class="opt-cell"><?php echo $opt_1; if ($opt_2_len) echo ' <small>></small> '.$opt_2; if ($opt_3_len) echo ' <small>></small> '.$opt_3; ?></td>
|
||||
<td class="opt-cell"><?php echo get_text($opt_1); if ($opt_2_len) echo ' <small>></small> '.get_text($opt_2); if ($opt_3_len) echo ' <small>></small> '.get_text($opt_3); ?></td>
|
||||
<td class="td_numsmall">
|
||||
<label for="opt_price_<?php echo $i; ?>" class="sound_only"></label>
|
||||
<input type="text" name="opt_price[]" value="<?php echo $opt_price; ?>" id="opt_price_<?php echo $i; ?>" class="frm_input" size="9">
|
||||
|
||||
@@ -31,6 +31,9 @@ if (!$sst) {
|
||||
$sst = "iq_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('iq_id', 'a.it_id', 'it_name', 'iq_time');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'iq_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
|
||||
$sql_common = " from {$g5['g5_shop_item_qa_table']} a
|
||||
left join {$g5['g5_shop_item_table']} b on (a.it_id = b.it_id)
|
||||
@@ -79,7 +82,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
$nbsp = "";
|
||||
for ($i=0; $i<$len; $i++) $nbsp .= " ";
|
||||
$selected = ($row1['ca_id'] == $sca) ? ' selected="selected"' : '';
|
||||
echo '<option value="'.$row1['ca_id'].'"'.$selected.'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
|
||||
echo '<option value="'.$row1['ca_id'].'"'.$selected.'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
@@ -68,10 +68,10 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
</div>
|
||||
|
||||
<form name="flist" class="local_sch01 local_sch">
|
||||
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
|
||||
<input type="hidden" name="page" value="<?php echo $page; ?>">
|
||||
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
|
||||
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
|
||||
|
||||
<label for="sel_ca_id" class="sound_only">검색대상</label>
|
||||
<select name="sel_ca_id" id="sel_ca_id">
|
||||
@@ -83,7 +83,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
$len = strlen($row1['ca_id']) / 2 - 1;
|
||||
$nbsp = "";
|
||||
for ($i=0; $i<$len; $i++) $nbsp .= " ";
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
@@ -35,7 +35,7 @@ $sql_common .= $sql_search;
|
||||
// 테이블의 전체 레코드수만 얻음
|
||||
$sql = " select count(*) as cnt " . $sql_common;
|
||||
$row = sql_fetch($sql);
|
||||
$total_count = $row['cnt'];
|
||||
$total_count = isset($row['cnt']) ? $row['cnt'] : 0;
|
||||
|
||||
$rows = $config['cf_page_rows'];
|
||||
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
|
||||
@@ -67,10 +67,10 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
</div>
|
||||
|
||||
<form name="flist" class="local_sch01 local_sch">
|
||||
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
|
||||
<input type="hidden" name="page" value="<?php echo $page; ?>">
|
||||
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
|
||||
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
|
||||
|
||||
<label for="sel_ca_id" class="sound_only">분류선택</label>
|
||||
<select name="sel_ca_id" id="sel_ca_id">
|
||||
@@ -82,7 +82,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
$len = strlen($row1['ca_id']) / 2 - 1;
|
||||
$nbsp = "";
|
||||
for ($i=0; $i<$len; $i++) $nbsp .= " ";
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
@@ -159,7 +161,6 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
$it_stock_qty_st = ''; // 스타일 정의
|
||||
if($row['it_stock_qty'] <= $row['it_noti_qty']) {
|
||||
$it_stock_qty_st = ' sit_stock_qty_alert';
|
||||
$it_stock_qty = ''.$it_stock_qty.' !<span class="sound_only"> 재고부족 </span>';
|
||||
}
|
||||
|
||||
$bg = 'bg'.($i%2);
|
||||
@@ -171,7 +172,7 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
<?php echo $row['it_id']; ?>
|
||||
</td>
|
||||
<td class="td_left"><a href="<?php echo $href; ?>"><?php echo get_it_image($row['it_id'], 50, 50); ?> <?php echo cut_str(stripslashes($row['it_name']), 60, "…"); ?></a></td>
|
||||
<td class="td_num<?php echo $it_stock_qty_st; ?>"><?php echo (int)$it_stock_qty; ?></td>
|
||||
<td class="td_num<?php echo $it_stock_qty_st; ?>"><?php echo $it_stock_qty; ?></td>
|
||||
<td class="td_num"><?php echo number_format((float)$wait_qty); ?></td>
|
||||
<td class="td_num"><?php echo number_format((float)$temporary_qty); ?></td>
|
||||
<td class="td_num">
|
||||
|
||||
@@ -74,10 +74,10 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
</div>
|
||||
|
||||
<form name="flist" class="local_sch01 local_sch">
|
||||
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
|
||||
<input type="hidden" name="page" value="<?php echo $page; ?>">
|
||||
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
|
||||
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
|
||||
|
||||
<label for="sel_field" class="sound_only">검색대상</label>
|
||||
<select name="sel_field" id="sel_field">
|
||||
@@ -170,13 +170,16 @@ function fitemstocksms_submit(f)
|
||||
return false;
|
||||
}
|
||||
|
||||
if(document.pressed == "선택삭제") {
|
||||
if(!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
var action = document.pressed;
|
||||
|
||||
return true;
|
||||
switch (action) {
|
||||
case "선택삭제":
|
||||
return confirm("선택한 자료를 정말 삭제하시겠습니까?");
|
||||
case "선택SMS전송":
|
||||
return confirm("선택한 자료에 대해서 SMS로 재입고 알림을 전송하시겠습니까?");
|
||||
default:
|
||||
return true;
|
||||
}
|
||||
}
|
||||
</script>
|
||||
|
||||
|
||||
@@ -55,12 +55,12 @@ if($ps_run) {
|
||||
?>
|
||||
<tr>
|
||||
<td class="td_chk">
|
||||
<input type="hidden" name="spl_id[]" value="<?php echo $spl_id; ?>">
|
||||
<label for="spl_chk_<?php echo $i; ?>" class="sound_only"><?php echo $spl_subject.' '.$spl; ?></label>
|
||||
<input type="hidden" name="spl_id[]" value="<?php echo get_text($spl_id); ?>">
|
||||
<label for="spl_chk_<?php echo $i; ?>" class="sound_only"><?php echo get_text($spl_subject.' '.$spl); ?></label>
|
||||
<input type="checkbox" name="spl_chk[]" id="spl_chk_<?php echo $i; ?>" value="1">
|
||||
</td>
|
||||
<td class="spl-subject-cell"><?php echo $spl_subject; ?></td>
|
||||
<td class="spl-cell"><?php echo $spl; ?></td>
|
||||
<td class="spl-subject-cell"><?php echo get_text($spl_subject); ?></td>
|
||||
<td class="spl-cell"><?php echo get_text($spl); ?></td>
|
||||
<td class="td_numsmall">
|
||||
<label for="spl_price_<?php echo $i; ?>" class="sound_only">상품금액</label>
|
||||
<input type="text" name="spl_price[]" value="<?php echo $spl_price; ?>" id="spl_price_<?php echo $i; ?>" class="frm_input" size="5">
|
||||
|
||||
@@ -46,6 +46,9 @@ if (!$sst) {
|
||||
$sst = "it_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('it_id', 'it_name', 'it_type1', 'it_type2', 'it_type3', 'it_type4', 'it_type5', 'ca_id');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'it_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = "order by $sst $sod";
|
||||
|
||||
$sql_common = " from {$g5['g5_shop_item_table']} ";
|
||||
@@ -85,8 +88,8 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
</div>
|
||||
|
||||
<form name="flist" class="local_sch01 local_sch">
|
||||
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
|
||||
<input type="hidden" name="page" value="<?php echo $page; ?>">
|
||||
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
|
||||
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
|
||||
|
||||
<label for="sca" class="sound_only">분류선택</label>
|
||||
<select name="sca" id="sca">
|
||||
@@ -98,7 +101,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
$len = strlen($row1['ca_id']) / 2 - 1;
|
||||
$nbsp = "";
|
||||
for ($i=0; $i<$len; $i++) $nbsp .= " ";
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sca, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].PHP_EOL;
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sca, $row1['ca_id']).'>'.$nbsp.$category_path.PHP_EOL;
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
@@ -18,8 +18,10 @@ foreach($check_keys as $key){
|
||||
|
||||
if( in_array($key, array('is_content', 'is_reply_content')) ){
|
||||
$posts[$key] = isset($_POST[$key]) ? $_POST[$key] : '';
|
||||
} else if( $key === 'is_id' ) {
|
||||
$posts[$key] = isset($_POST[$key]) ? (int) $_POST[$key] : 0;
|
||||
} else {
|
||||
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
|
||||
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
|
||||
}
|
||||
}
|
||||
|
||||
@@ -46,4 +48,4 @@ if ($w == "u")
|
||||
else
|
||||
{
|
||||
alert();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -33,6 +33,9 @@ if (!$sst) {
|
||||
$sst = "is_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('is_id', 'a.it_id', 'it_name', 'is_name', 'is_score', 'is_time');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'is_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
|
||||
$sql_common = " from {$g5['g5_shop_item_use_table']} a
|
||||
left join {$g5['g5_shop_item_table']} b on (a.it_id = b.it_id)
|
||||
@@ -81,7 +84,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
$nbsp = "";
|
||||
for ($i=0; $i<$len; $i++) $nbsp .= " ";
|
||||
$selected = ($row1['ca_id'] == $sca) ? ' selected="selected"' : '';
|
||||
echo '<option value="'.$row1['ca_id'].'"'.$selected.'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
|
||||
echo '<option value="'.$row1['ca_id'].'"'.$selected.'>'.$nbsp.$category_path.PHP_EOL;
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
@@ -69,10 +69,10 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
</div>
|
||||
|
||||
<form name="flist" class="local_sch01 local_sch">
|
||||
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
|
||||
<input type="hidden" name="page" value="<?php echo $page; ?>">
|
||||
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
|
||||
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
|
||||
|
||||
<label for="sel_ca_id" class="sound_only">분류선택</label>
|
||||
<select name="sel_ca_id" id="sel_ca_id">
|
||||
@@ -84,7 +84,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
$len = strlen($row1['ca_id']) / 2 - 1;
|
||||
$nbsp = "";
|
||||
for ($i=0; $i<$len; $i++) $nbsp .= " ";
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
|
||||
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
@@ -30,17 +30,17 @@ if(! function_exists('column_char')) {
|
||||
$rows = array();
|
||||
|
||||
for($i=1; $row=sql_fetch_array($result); $i++) {
|
||||
$rows[] =
|
||||
array(' '.$row['od_id'],
|
||||
$row['od_name'],
|
||||
' '.$row['od_tel'],
|
||||
' '.$row['od_hp'],
|
||||
$row['od_b_name'],
|
||||
' '.$row['od_b_tel'],
|
||||
' '.$row['od_b_hp'],
|
||||
print_address($row['od_b_addr1'], $row['od_b_addr2'], $row['od_b_addr3'], $row['od_b_addr_jibeon']),
|
||||
$row['od_delivery_company'],
|
||||
$row['od_invoice']);
|
||||
$rows[] =
|
||||
array(' '.$row['od_id'],
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell($row['od_name']) : $row['od_name'],
|
||||
' '.$row['od_tel'],
|
||||
' '.$row['od_hp'],
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell($row['od_b_name']) : $row['od_b_name'],
|
||||
' '.$row['od_b_tel'],
|
||||
' '.$row['od_b_hp'],
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell(print_address($row['od_b_addr1'], $row['od_b_addr2'], $row['od_b_addr3'], $row['od_b_addr_jibeon'])) : print_address($row['od_b_addr1'], $row['od_b_addr2'], $row['od_b_addr3'], $row['od_b_addr_jibeon']),
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell($row['od_delivery_company']) : $row['od_delivery_company'],
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell($row['od_invoice']) : $row['od_invoice']);
|
||||
}
|
||||
|
||||
$data = array_merge(array($headers), $rows);
|
||||
|
||||
@@ -6,6 +6,8 @@ include_once(G5_LIB_PATH.'/mailer.lib.php');
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
check_admin_token();
|
||||
|
||||
define("_ORDERMAIL_", true);
|
||||
|
||||
$sms_count = 0;
|
||||
|
||||
@@ -107,6 +107,12 @@ if($od['od_pg'] == 'lg') {
|
||||
}
|
||||
}
|
||||
|
||||
$print_od_deposit_name = $od['od_deposit_name'];
|
||||
// nicepay 로 주문하고 가상계좌인 경우
|
||||
if ($od['od_pg'] === 'nicepay' && $od['od_settle_case'] === '가상계좌' && $od['od_deposit_name']){
|
||||
$print_od_deposit_name .= '_NICE';
|
||||
}
|
||||
|
||||
// add_javascript('js 구문', 출력순서); 숫자가 작을 수록 먼저 출력됨
|
||||
add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
?>
|
||||
@@ -376,8 +382,8 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<input type="hidden" name="sel_field" value="<?php echo $sel_field; ?>">
|
||||
<input type="hidden" name="search" value="<?php echo $search; ?>">
|
||||
<input type="hidden" name="page" value="<?php echo $page; ?>">
|
||||
<input type="hidden" name="od_name" value="<?php echo $od['od_name']; ?>">
|
||||
<input type="hidden" name="od_hp" value="<?php echo $od['od_hp']; ?>">
|
||||
<input type="hidden" name="od_name" value="<?php echo get_text($od['od_name']); ?>">
|
||||
<input type="hidden" name="od_hp" value="<?php echo get_text($od['od_hp']); ?>">
|
||||
<input type="hidden" name="od_tno" value="<?php echo $od['od_tno']; ?>">
|
||||
<input type="hidden" name="od_escrow" value="<?php echo $od['od_escrow']; ?>">
|
||||
<input type="hidden" name="od_pg" value="<?php echo $od['od_pg']; ?>">
|
||||
@@ -408,7 +414,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
</tr>
|
||||
<tr>
|
||||
<th scope="row">입금자</th>
|
||||
<td><?php echo get_text($od['od_deposit_name']); ?></td>
|
||||
<td><?php echo get_text($print_od_deposit_name); ?></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<th scope="row">입금확인일시</th>
|
||||
@@ -503,31 +509,33 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<?php
|
||||
if ($od['od_settle_case'] != '무통장') {
|
||||
switch($od['od_pg']) {
|
||||
case 'lg':
|
||||
$pg_url = 'http://pgweb.uplus.co.kr';
|
||||
$pg_test = '토스페이먼츠';
|
||||
if ($default['de_card_test']) {
|
||||
$pg_url = 'http://pgweb.uplus.co.kr/tmert';
|
||||
$pg_test .= ' 테스트 ';
|
||||
}
|
||||
break;
|
||||
case 'inicis':
|
||||
$pg_url = 'https://iniweb.inicis.com/';
|
||||
$pg_test = 'KG이니시스';
|
||||
$pg_test = 'KG이니시스 ';
|
||||
break;
|
||||
case 'KAKAOPAY':
|
||||
$pg_url = 'https://mms.cnspay.co.kr';
|
||||
$pg_test = 'KAKAOPAY';
|
||||
$pg_test = 'KAKAOPAY ';
|
||||
break;
|
||||
case 'nicepay':
|
||||
$pg_url = 'https://npg.nicepay.co.kr/';
|
||||
$pg_test = 'NICEPAY ';
|
||||
break;
|
||||
case 'lg':
|
||||
case 'toss':
|
||||
$pg_url = 'https://app.tosspayments.com';
|
||||
$pg_test = '토스페이먼츠 ';
|
||||
// 상점관리자 로그인 후 상단 '테스트 모드' 활성화 시 테스트 화면 노출
|
||||
break;
|
||||
default:
|
||||
$pg_url = 'http://admin8.kcp.co.kr';
|
||||
$pg_test = 'KCP';
|
||||
$pg_url = 'https://partner.kcp.co.kr';
|
||||
$pg_test = 'KCP ';
|
||||
if ($default['de_card_test']) {
|
||||
// 로그인 아이디 / 비번
|
||||
// 일반 : test1234 / test12345
|
||||
// 에스크로 : escrow / escrow913
|
||||
$pg_url = 'http://testadmin8.kcp.co.kr';
|
||||
$pg_test .= ' 테스트 ';
|
||||
$pg_url = 'https://testpartner.kcp.co.kr';
|
||||
$pg_test .= '테스트 ';
|
||||
}
|
||||
|
||||
}
|
||||
@@ -620,9 +628,23 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
break;
|
||||
}
|
||||
$cash_receipt_script = 'javascript:showCashReceipts(\''.$LGD_MID.'\',\''.$od['od_id'].'\',\''.$od['od_casseqno'].'\',\''.$trade_type.'\',\''.$CST_PLATFORM.'\');';
|
||||
} else if($od['od_pg'] == 'toss') {
|
||||
$cash_receipt_script = 'window.open(\'https://dashboard.tosspayments.com/receipt/mids/si_'.$config['cf_lg_mid'].'/orders/'.$od['od_id'].'/cash-receipt?ref=dashboard\',\'receipt\',\'width=430,height=700\');';
|
||||
} else if($od['od_pg'] == 'inicis') {
|
||||
$cash = unserialize($od['od_cash_info']);
|
||||
$cash_receipt_script = 'window.open(\'https://iniweb.inicis.com/DefaultWebApp/mall/cr/cm/Cash_mCmReceipt.jsp?noTid='.$cash['TID'].'&clpaymethod=22\',\'showreceipt\',\'width=380,height=540,scrollbars=no,resizable=no\');';
|
||||
} else if($od['od_pg'] == 'nicepay') {
|
||||
|
||||
$od_tid = $od['od_tno'];
|
||||
$cash_type = 0;
|
||||
|
||||
if (! $od_tid) {
|
||||
$cash = unserialize($od['od_cash_info']);
|
||||
$od_tid = isset($cash['TID']) ? $cash['TID'] : '';
|
||||
$cash_type = $od_tid ? 1 : 0;
|
||||
}
|
||||
|
||||
$cash_receipt_script = 'window.open(\'https://npg.nicepay.co.kr/issue/IssueLoader.do?type='.$cash_type.'&TID='.$od_tid.'&noMethod=1\',\'receipt\',\'width=430,height=700\');';
|
||||
} else {
|
||||
require G5_SHOP_PATH.'/settle_kcp.inc.php';
|
||||
|
||||
@@ -697,6 +719,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<label for="od_sms_ipgum_check">SMS 입금 문자전송</label>
|
||||
<br>
|
||||
<?php } ?>
|
||||
|
||||
<input type="text" name="od_deposit_name" value="<?php echo get_text($od['od_deposit_name']); ?>" id="od_deposit_name" class="frm_input">
|
||||
</td>
|
||||
</tr>
|
||||
@@ -804,6 +827,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
|
||||
<label for="od_sms_baesong_check">SMS 배송 문자전송</label>
|
||||
<br>
|
||||
<?php } ?>
|
||||
|
||||
<input type="text" name="od_invoice" value="<?php echo $od['od_invoice']; ?>" id="od_invoice" class="frm_input">
|
||||
</td>
|
||||
</tr>
|
||||
@@ -1075,7 +1099,7 @@ function form_submit(f)
|
||||
|
||||
var msg = "";
|
||||
|
||||
<?php if($od['od_settle_case'] == '신용카드' || $od['od_settle_case'] == 'KAKAOPAY' || $od['od_settle_case'] == '간편결제' || ($od['od_pg'] == 'inicis' && is_inicis_order_pay($od['od_settle_case']) )) { ?>
|
||||
<?php if (is_cancel_shop_pg_order($od)) { ?>
|
||||
if(status == "취소" || status == "반품" || status == "품절") {
|
||||
var $ct_chk = $("input[name^=ct_chk]");
|
||||
var chk_cnt = $ct_chk.length;
|
||||
@@ -1140,4 +1164,4 @@ function chk_receipt_price()
|
||||
</script>
|
||||
|
||||
<?php
|
||||
include_once(G5_ADMIN_PATH.'/admin.tail.php');
|
||||
include_once(G5_ADMIN_PATH.'/admin.tail.php');
|
||||
|
||||
@@ -191,7 +191,7 @@ if (in_array($_POST['ct_status'], $status_cancel)) {
|
||||
$sql = " select * from {$g5['g5_shop_order_table']} where od_id = '$od_id' ";
|
||||
$od = sql_fetch($sql);
|
||||
|
||||
if($od['od_tno'] && ($od['od_settle_case'] == '신용카드' || $od['od_settle_case'] == '간편결제' || $od['od_settle_case'] == 'KAKAOPAY') || ($od['od_pg'] == 'inicis' && is_inicis_order_pay($od['od_settle_case']) )) {
|
||||
if ($od['od_tno'] && is_cancel_shop_pg_order($od)) {
|
||||
switch($od['od_pg']) {
|
||||
case 'lg':
|
||||
include_once(G5_SHOP_PATH.'/settle_lg.inc.php');
|
||||
@@ -220,6 +220,10 @@ if (in_array($_POST['ct_status'], $status_cancel)) {
|
||||
$pg_res_msg = $xpay->Response_Msg();
|
||||
}
|
||||
break;
|
||||
case 'toss':
|
||||
$cancel_msg = '쇼핑몰 운영자 승인 취소';
|
||||
include_once(G5_SHOP_PATH.'/toss/toss_cancel.php');
|
||||
break;
|
||||
case 'inicis':
|
||||
include_once(G5_SHOP_PATH.'/settle_inicis.inc.php');
|
||||
$cancel_msg = '쇼핑몰 운영자 승인 취소';
|
||||
@@ -243,6 +247,32 @@ if (in_array($_POST['ct_status'], $status_cancel)) {
|
||||
$pg_res_msg = 'curl 로 데이터를 받지 못했습니다.';
|
||||
}
|
||||
|
||||
break;
|
||||
case 'nicepay':
|
||||
include_once(G5_SHOP_PATH.'/settle_nicepay.inc.php');
|
||||
$cancel_msg = '쇼핑몰 운영자 승인 취소';
|
||||
|
||||
$tno = $od['od_tno'];
|
||||
|
||||
$cancelAmt = $od['od_receipt_price'];
|
||||
|
||||
// 0:전체 취소, 1:부분 취소(별도 계약 필요)
|
||||
$partialCancelCode = 0;
|
||||
|
||||
|
||||
include G5_SHOP_PATH.'/nicepay/cancel_process.php';
|
||||
|
||||
if (isset($result['ResultCode'])) {
|
||||
// 실패했다면
|
||||
if ($result['ResultCode'] !== '2001') {
|
||||
$pg_res_cd = $result['ResultCode'];
|
||||
$pg_res_msg = $result['ResultMsg'];
|
||||
}
|
||||
} else {
|
||||
$pg_res_cd = '';
|
||||
$pg_res_msg = 'curl 로 데이터를 받지 못하거나 통신에 실패했습니다.';
|
||||
}
|
||||
|
||||
break;
|
||||
case 'KAKAOPAY':
|
||||
include_once(G5_SHOP_PATH.'/settle_kakaopay.inc.php');
|
||||
@@ -296,7 +326,7 @@ if (in_array($_POST['ct_status'], $status_cancel)) {
|
||||
|
||||
// PG 취소요청 성공했으면
|
||||
if($pg_res_cd == '') {
|
||||
$pg_cancel_log = ' PG 신용카드 승인취소 처리';
|
||||
$pg_cancel_log = ' PG '.$od['od_settle_case'].' 승인취소 처리';
|
||||
$sql = " update {$g5['g5_shop_order_table']}
|
||||
set od_refund_price = '{$od['od_receipt_price']}'
|
||||
where od_id = '$od_id' ";
|
||||
|
||||
@@ -35,7 +35,7 @@ $check_keys = array(
|
||||
$posts = array();
|
||||
|
||||
foreach($check_keys as $key){
|
||||
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
|
||||
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
|
||||
}
|
||||
|
||||
$od_send_mail = $posts['od_send_mail'];
|
||||
@@ -175,4 +175,4 @@ if($posts['od_tno'] && $posts['od_escrow'] == 1)
|
||||
|
||||
$qstr = "sort1=$sort1&sort2=$sort2&sel_field=$sel_field&search=$search&page=$page";
|
||||
|
||||
goto_url("./orderform.php?od_id=$od_id&$qstr");
|
||||
goto_url("./orderform.php?od_id=$od_id&$qstr");
|
||||
|
||||
@@ -4,7 +4,7 @@ include_once('./_common.php');
|
||||
|
||||
check_admin_token();
|
||||
|
||||
$od_shop_memo = isset($_POST['od_shop_memo']) ? strip_tags($_POST['od_shop_memo']) : '';
|
||||
$od_shop_memo = isset($_POST['od_shop_memo']) ? addslashes(strip_tags(stripslashes($_POST['od_shop_memo']))) : '';
|
||||
$od_id = isset($_POST['od_id']) ? safe_replace_regex($_POST['od_id'], 'od_id') : '';
|
||||
|
||||
$search = isset($_REQUEST['search']) ? get_search_string($_REQUEST['search']) : '';
|
||||
@@ -17,22 +17,22 @@ if(isset($_POST['mod_type']) && $_POST['mod_type'] === 'info') {
|
||||
$od_zip2 = isset($_POST['od_zip']) ? preg_replace('/[^0-9]/', '', substr($_POST['od_zip'], 3)) : '';
|
||||
$od_b_zip1 = isset($_POST['od_b_zip']) ? preg_replace('/[^0-9]/', '', substr($_POST['od_b_zip'], 0, 3)) : '';
|
||||
$od_b_zip2 = isset($_POST['od_b_zip']) ? preg_replace('/[^0-9]/', '', substr($_POST['od_b_zip'], 3)) : '';
|
||||
$od_email = isset($_POST['od_email']) ? strip_tags(clean_xss_attributes($_POST['od_email'])) : '';
|
||||
$od_name = isset($_POST['od_name']) ? clean_xss_tags($_POST['od_name'], 1, 1) : '';
|
||||
$od_tel = isset($_POST['od_tel']) ? clean_xss_tags($_POST['od_tel'], 1, 1) : '';
|
||||
$od_hp = isset($_POST['od_hp']) ? clean_xss_tags($_POST['od_hp'], 1, 1) : '';
|
||||
$od_addr1 = isset($_POST['od_addr1']) ? clean_xss_tags($_POST['od_addr1'], 1, 1) : '';
|
||||
$od_addr2 = isset($_POST['od_addr2']) ? clean_xss_tags($_POST['od_addr2'], 1, 1) : '';
|
||||
$od_addr3 = isset($_POST['od_addr3']) ? clean_xss_tags($_POST['od_addr3'], 1, 1) : '';
|
||||
$od_addr_jibeon = isset($_POST['od_addr_jibeon']) ? clean_xss_tags($_POST['od_addr_jibeon'], 1, 1) : '';
|
||||
$od_b_name = isset($_POST['od_b_name']) ? clean_xss_tags($_POST['od_b_name'], 1, 1) : '';
|
||||
$od_b_tel = isset($_POST['od_b_tel']) ? clean_xss_tags($_POST['od_b_tel'], 1, 1) : '';
|
||||
$od_b_hp = isset($_POST['od_b_hp']) ? clean_xss_tags($_POST['od_b_hp'], 1, 1) : '';
|
||||
$od_b_addr1 = isset($_POST['od_b_addr1']) ? clean_xss_tags($_POST['od_b_addr1'], 1, 1) : '';
|
||||
$od_b_addr2 = isset($_POST['od_b_addr2']) ? clean_xss_tags($_POST['od_b_addr2'], 1, 1) : '';
|
||||
$od_b_addr3 = isset($_POST['od_b_addr3']) ? clean_xss_tags($_POST['od_b_addr3'], 1, 1) : '';
|
||||
$od_b_addr_jibeon = isset($_POST['od_b_addr_jibeon']) ? clean_xss_tags($_POST['od_b_addr_jibeon'], 1, 1) : '';
|
||||
$od_hope_date = isset($_POST['od_hope_date']) ? clean_xss_tags($_POST['od_hope_date'], 1, 1) : '';
|
||||
$od_email = isset($_POST['od_email']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['od_email'])))) : '';
|
||||
$od_name = isset($_POST['od_name']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_name']), 1, 1)) : '';
|
||||
$od_tel = isset($_POST['od_tel']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_tel']), 1, 1)) : '';
|
||||
$od_hp = isset($_POST['od_hp']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_hp']), 1, 1)) : '';
|
||||
$od_addr1 = isset($_POST['od_addr1']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_addr1']), 1, 1)) : '';
|
||||
$od_addr2 = isset($_POST['od_addr2']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_addr2']), 1, 1)) : '';
|
||||
$od_addr3 = isset($_POST['od_addr3']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_addr3']), 1, 1)) : '';
|
||||
$od_addr_jibeon = isset($_POST['od_addr_jibeon']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_addr_jibeon']), 1, 1)) : '';
|
||||
$od_b_name = isset($_POST['od_b_name']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_name']), 1, 1)) : '';
|
||||
$od_b_tel = isset($_POST['od_b_tel']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_tel']), 1, 1)) : '';
|
||||
$od_b_hp = isset($_POST['od_b_hp']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_hp']), 1, 1)) : '';
|
||||
$od_b_addr1 = isset($_POST['od_b_addr1']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_addr1']), 1, 1)) : '';
|
||||
$od_b_addr2 = isset($_POST['od_b_addr2']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_addr2']), 1, 1)) : '';
|
||||
$od_b_addr3 = isset($_POST['od_b_addr3']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_addr3']), 1, 1)) : '';
|
||||
$od_b_addr_jibeon = isset($_POST['od_b_addr_jibeon']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_addr_jibeon']), 1, 1)) : '';
|
||||
$od_hope_date = isset($_POST['od_hope_date']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_hope_date']), 1, 1)) : '';
|
||||
|
||||
$sql = " update {$g5['g5_shop_order_table']}
|
||||
set od_name = '$od_name',
|
||||
@@ -66,4 +66,4 @@ sql_query($sql);
|
||||
|
||||
$qstr = "sort1=$sort1&sort2=$sort2&sel_field=$sel_field&search=$search&page=$page";
|
||||
|
||||
goto_url("./orderform.php?od_id=$od_id&$qstr");
|
||||
goto_url("./orderform.php?od_id=$od_id&$qstr");
|
||||
|
||||
@@ -16,6 +16,7 @@ $sort2 = (isset($_GET['sort2']) && in_array($_GET['sort2'], array('desc', 'asc')
|
||||
$sel_field = (isset($_GET['sel_field']) && in_array($_GET['sel_field'], array('od_id', 'mb_id', 'od_name', 'od_tel', 'od_hp', 'od_b_name', 'od_b_tel', 'od_b_hp', 'od_deposit_name', 'od_invoice')) ) ? $_GET['sel_field'] : '';
|
||||
$od_status = isset($_GET['od_status']) ? get_search_string($_GET['od_status']) : '';
|
||||
$search = isset($_GET['search']) ? get_search_string($_GET['search']) : '';
|
||||
$save_search = isset($_GET['save_search']) ? get_search_string($_GET['save_search']) : '';
|
||||
|
||||
$fr_date = (isset($_GET['fr_date']) && preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $_GET['fr_date'])) ? $_GET['fr_date'] : '';
|
||||
$to_date = (isset($_GET['to_date']) && preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $_GET['to_date'])) ? $_GET['to_date'] : '';
|
||||
@@ -25,8 +26,8 @@ $od_cancel_price = isset($_GET['od_cancel_price']) ? preg_replace('/[^0-9a-z]/i'
|
||||
$od_refund_price = isset($_GET['od_refund_price']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_refund_price']) : '';
|
||||
$od_receipt_point = isset($_GET['od_receipt_point']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_receipt_point']) : '';
|
||||
$od_coupon = isset($_GET['od_coupon']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_coupon']) : '';
|
||||
$od_settle_case = isset($_GET['od_settle_case']) ? clean_xss_tags($_GET['od_settle_case'], 1, 1) : '';
|
||||
$od_escrow = isset($_GET['od_escrow']) ? clean_xss_tags($_GET['od_escrow'], 1, 1) : '';
|
||||
$od_settle_case = isset($_GET['od_settle_case']) ? addslashes(clean_xss_tags(stripslashes($_GET['od_settle_case']), 1, 1)) : '';
|
||||
$od_escrow = isset($_GET['od_escrow']) ? addslashes(clean_xss_tags(stripslashes($_GET['od_escrow']), 1, 1)) : '';
|
||||
|
||||
$tot_itemcount = $tot_orderprice = $tot_receiptprice = $tot_ordercancel = $tot_misu = $tot_couponprice = 0;
|
||||
$sql_search = "";
|
||||
@@ -160,11 +161,11 @@ if( function_exists('pg_setting_check') ){
|
||||
</div>
|
||||
|
||||
<form name="frmorderlist" class="local_sch01 local_sch">
|
||||
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
|
||||
<input type="hidden" name="page" value="<?php echo $page; ?>">
|
||||
<input type="hidden" name="save_search" value="<?php echo $search; ?>">
|
||||
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
|
||||
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
|
||||
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
|
||||
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
|
||||
<input type="hidden" name="save_search" value="<?php echo get_sanitize_input($search); ?>">
|
||||
|
||||
<label for="sel_field" class="sound_only">검색대상</label>
|
||||
<select name="sel_field" id="sel_field">
|
||||
@@ -349,7 +350,7 @@ if( function_exists('pg_setting_check') ){
|
||||
if($default['de_escrow_use'] && $row['od_escrow'])
|
||||
$od_paytype .= '<span class="list_escrow">에스크로</span>';
|
||||
|
||||
$uid = md5($row['od_id'].$row['od_time'].$row['od_ip']);
|
||||
$uid = function_exists('get_shop_uid') ? get_shop_uid('order', $row['od_id'], $row['od_time'], $row['od_ip']) : md5($row['od_id'].$row['od_time'].$row['od_ip']);
|
||||
|
||||
$invoice_time = is_null_time($row['od_invoice_time']) ? G5_TIME_YMDHIS : $row['od_invoice_time'];
|
||||
$delivery_company = $row['od_delivery_company'] ? $row['od_delivery_company'] : $default['de_delivery_company'];
|
||||
|
||||
@@ -4,6 +4,8 @@ include_once('./_common.php');
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
check_admin_token();
|
||||
|
||||
$tax_mny = isset($_POST['mod_tax_mny']) ? preg_replace('/[^0-9]/', '', $_POST['mod_tax_mny']) : 0;
|
||||
$free_mny = isset($_POST['mod_free_mny']) ? preg_replace('/[^0-9]/', '', $_POST['mod_free_mny']) : 0;
|
||||
|
||||
|
||||
@@ -49,7 +49,7 @@ if ($csv == 'csv')
|
||||
$to_date = date_conv($to_date);
|
||||
|
||||
|
||||
$sql = " SELECT a.od_id, od_b_zip1, od_b_zip2, od_b_addr1, od_b_addr2, od_b_addr3, od_b_addr_jibeon, od_b_name, od_b_tel, od_b_hp, b.it_name, ct_qty, b.it_id, a.od_id, od_memo, od_invoice, b.ct_option, b.ct_send_cost, b.it_sc_type
|
||||
$sql = " SELECT a.od_id, od_b_zip1, od_b_zip2, od_b_addr1, od_b_addr2, od_b_addr3, od_b_addr_jibeon, od_b_name, od_b_tel, od_b_hp, b.it_name, ct_qty, b.it_id, od_memo, od_invoice, b.ct_option, b.ct_send_cost, b.it_sc_type
|
||||
FROM {$g5['g5_shop_order_table']} a, {$g5['g5_shop_cart_table']} b
|
||||
where a.od_id = b.od_id ";
|
||||
if ($case == 1) // 출력기간
|
||||
@@ -65,7 +65,7 @@ if ($csv == 'csv')
|
||||
alert("출력할 내역이 없습니다.");
|
||||
|
||||
//header('Content-Type: text/x-csv');
|
||||
header("Content-charset=utf-8");
|
||||
header("Content-Type: text/csv; charset=utf-8");
|
||||
header('Content-Type: doesn/matter');
|
||||
header('Expires: ' . gmdate('D, d M Y H:i:s') . ' GMT');
|
||||
header('Content-Disposition: attachment; filename="orderlist-' . date("ymd", time()) . '.csv"');
|
||||
@@ -118,21 +118,21 @@ if ($csv == 'csv')
|
||||
}
|
||||
|
||||
echo '"\''.$row['od_b_zip1'].$row['od_b_zip2'].'"\''.',';
|
||||
echo '"'.$pull_address.'"'.',';
|
||||
echo '"'.$row['od_b_name'].'"'.',';
|
||||
echo '"'.(function_exists('csv_safe_cell') ? csv_safe_cell($pull_address) : $pull_address).'"'.',';
|
||||
echo '"'.(function_exists('csv_safe_cell') ? csv_safe_cell($row['od_b_name']) : $row['od_b_name']).'"'.',';
|
||||
//echo '"'.multibyte_digit((string)$row[od_b_tel]).'"'.',';
|
||||
//echo '"'.multibyte_digit((string)$row[od_b_hp]).'"'.',';
|
||||
echo '"'.conv_telno($row['od_b_tel']) . '"'.',';
|
||||
echo '"'.conv_telno($row['od_b_hp']) . '"'.',';
|
||||
echo '"'.preg_replace("/\"/", """, $row['it_name']) . '"'.',';
|
||||
echo '"'.(function_exists('csv_safe_cell') ? csv_safe_cell(preg_replace("/\"/", """, $row['it_name'])) : preg_replace("/\"/", """, $row['it_name'])) . '"'.',';
|
||||
echo '"'.$row['ct_qty'].'"'.',';
|
||||
echo '"'.$row['ct_option'].'"'.',';
|
||||
echo '"'.(function_exists('csv_safe_cell') ? csv_safe_cell($row['ct_option']) : $row['ct_option']).'"'.',';
|
||||
echo '"'.$ct_send_cost.'"'.',';
|
||||
echo '"\''.$row['it_id'].'\'"'.',';
|
||||
echo '"\''.$row['od_id'].'\'"'.',';
|
||||
echo '"'.$row['od_invoice'].'"'.',';
|
||||
echo '"'.(function_exists('csv_safe_cell') ? csv_safe_cell($row['od_invoice']) : $row['od_invoice']).'"'.',';
|
||||
//echo '"'.preg_replace("/\"/", """, preg_replace("/\n/", "", $row[od_memo])).'"';
|
||||
echo '"'.preg_replace("/\"/", """, $row['od_memo']).'"';
|
||||
echo '"'.(function_exists('csv_safe_cell') ? csv_safe_cell(preg_replace("/\"/", """, $row['od_memo'])) : preg_replace("/\"/", """, $row['od_memo'])).'"';
|
||||
echo "\n";
|
||||
}
|
||||
if ($i == 0)
|
||||
@@ -153,7 +153,7 @@ if ($csv == 'xls')
|
||||
$fr_date = date_conv($fr_date);
|
||||
$to_date = date_conv($to_date);
|
||||
|
||||
$sql = " SELECT a.od_id, od_b_zip1, od_b_zip2, od_b_addr1, od_b_addr2, od_b_addr3, od_b_addr_jibeon, od_b_name, od_b_tel, od_b_hp, b.it_name, ct_qty, b.it_id, a.od_id, od_memo, od_invoice, b.ct_option, b.ct_send_cost, b.it_sc_type
|
||||
$sql = " SELECT a.od_id, od_b_zip1, od_b_zip2, od_b_addr1, od_b_addr2, od_b_addr3, od_b_addr_jibeon, od_b_name, od_b_tel, od_b_hp, b.it_name, ct_qty, b.it_id, od_memo, od_invoice, b.ct_option, b.ct_send_cost, b.it_sc_type
|
||||
FROM {$g5['g5_shop_order_table']} a, {$g5['g5_shop_cart_table']} b
|
||||
where a.od_id = b.od_id ";
|
||||
if ($case == 1) // 출력기간
|
||||
@@ -217,18 +217,18 @@ if ($csv == 'xls')
|
||||
}
|
||||
|
||||
$rows[] = array(' '.$row['od_b_zip1'].$row['od_b_zip2'],
|
||||
$pull_address,
|
||||
$row['od_b_name'],
|
||||
' '.conv_telno($row['od_b_tel']),
|
||||
' '.conv_telno($row['od_b_hp']),
|
||||
preg_replace("/\"/", """, $row['it_name']),
|
||||
' '.$row['ct_qty'],
|
||||
$row['ct_option'],
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell($pull_address) : $pull_address,
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell($row['od_b_name']) : $row['od_b_name'],
|
||||
' '.conv_telno($row['od_b_tel']),
|
||||
' '.conv_telno($row['od_b_hp']),
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell(preg_replace("/\"/", """, $row['it_name'])) : preg_replace("/\"/", """, $row['it_name']),
|
||||
' '.$row['ct_qty'],
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell($row['ct_option']) : $row['ct_option'],
|
||||
$ct_send_cost,
|
||||
' '.$row['it_id'],
|
||||
' '.$row['od_id'],
|
||||
' '.$row['od_invoice'],
|
||||
preg_replace("/\"/", """, $row['od_memo']));
|
||||
function_exists('csv_safe_cell') ? csv_safe_cell(preg_replace("/\"/", """, $row['od_memo'])) : preg_replace("/\"/", """, $row['od_memo']));
|
||||
}
|
||||
|
||||
$data = array_merge(array($headers), $rows);
|
||||
|
||||
@@ -44,6 +44,12 @@ if($popup == 'yes') { // 팝업창일 때
|
||||
$pp['pp_price'] = $od['od_misu'];
|
||||
$wrp_tag_st = '<div class="new_win">'.PHP_EOL.'<h1 id="new_win_title">'.$html_title.'</h1>';
|
||||
$wrp_tag_end = '</div>';
|
||||
|
||||
echo '<script>
|
||||
if (typeof g5_admin_csrf_token_key === "undefined") {
|
||||
var g5_admin_csrf_token_key = "' . (function_exists('admin_csrf_token_key') ? admin_csrf_token_key() : '') . '";
|
||||
}
|
||||
</script>';
|
||||
}
|
||||
else { // 현재페이지일 때
|
||||
include_once (G5_ADMIN_PATH.'/admin.head.php');
|
||||
@@ -204,6 +210,8 @@ if(!sql_query(" select pp_cash from {$g5['g5_shop_personalpay_table']} limit 1 "
|
||||
break;
|
||||
}
|
||||
$cash_receipt_script = 'javascript:showCashReceipts(\''.$LGD_MID.'\',\''.$pp['pp_id'].'\',\''.$pp['pp_casseqno'].'\',\''.$trade_type.'\',\''.$CST_PLATFORM.'\');';
|
||||
} else if($pp['pp_pg'] == 'toss') {
|
||||
$cash_receipt_script = 'window.open(\'https://dashboard.tosspayments.com/receipt/mids/si_'.$config['cf_lg_mid'].'/orders/'.$pp['pp_id'].'/cash-receipt?ref=dashboard\',\'receipt\',\'width=430,height=700\');';
|
||||
} else if($pp['pp_pg'] == 'inicis') {
|
||||
$cash = unserialize($pp['pp_cash_info']);
|
||||
$cash_receipt_script = 'window.open(\'https://iniweb.inicis.com/DefaultWebApp/mall/cr/cm/Cash_mCmReceipt.jsp?noTid='.$cash['TID'].'&clpaymethod=22\',\'showreceipt\',\'width=380,height=540,scrollbars=no,resizable=no\');';
|
||||
|
||||
@@ -4,7 +4,7 @@ include_once('./_common.php');
|
||||
|
||||
check_admin_token();
|
||||
|
||||
$pp_name = isset($_POST['pp_name']) ? strip_tags(clean_xss_attributes($_POST['pp_name'])) : '';
|
||||
$pp_name = isset($_POST['pp_name']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['pp_name'])))) : '';
|
||||
$pp_id = isset($_REQUEST['pp_id']) ? preg_replace('/[^0-9]/', '', $_REQUEST['pp_id']) : 0;
|
||||
$pp_price = isset($_POST['pp_price']) ? preg_replace('/[^0-9]/', '', $_REQUEST['pp_price']) : 0;
|
||||
|
||||
@@ -40,8 +40,8 @@ if($w == 'd') {
|
||||
|
||||
$post_pp_content = isset($_POST['pp_content']) ? $_POST['pp_content'] : '';
|
||||
$post_pp_receipt_price = isset($_POST['pp_receipt_price']) ? (int) $_POST['pp_receipt_price'] : 0;
|
||||
$post_pp_settle_case = isset($_POST['pp_settle_case']) ? clean_xss_tags($_POST['pp_settle_case'], 1, 1) : '';
|
||||
$post_pp_receipt_time = isset($_POST['pp_receipt_time']) ? clean_xss_tags($_POST['pp_receipt_time'], 1, 1) : '';
|
||||
$post_pp_settle_case = isset($_POST['pp_settle_case']) ? addslashes(clean_xss_tags(stripslashes($_POST['pp_settle_case']), 1, 1)) : '';
|
||||
$post_pp_receipt_time = isset($_POST['pp_receipt_time']) ? safe_replace_regex($_POST['pp_receipt_time'], 'time') : '';
|
||||
$post_pp_shop_memo = isset($_POST['pp_shop_memo']) ? $_POST['pp_shop_memo'] : '';
|
||||
$post_pp_use = isset($_POST['pp_use']) ? (int) $_POST['pp_use'] : 0;
|
||||
|
||||
@@ -79,4 +79,4 @@ if($w == '') {
|
||||
if($popup == 'yes')
|
||||
alert_close('개인결제가 추가됐습니다.');
|
||||
else
|
||||
goto_url('./personalpayform.php?w=u&pp_id='.$pp_id.'&'.$qstr);
|
||||
goto_url('./personalpayform.php?w=u&pp_id='.$pp_id.'&'.$qstr);
|
||||
|
||||
@@ -27,6 +27,9 @@ if (!$sst) {
|
||||
$sst = "pp_id";
|
||||
$sod = "desc";
|
||||
}
|
||||
$allowed_sst = array('pp_id', 'od_id', 'pp_receipt_time');
|
||||
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'pp_id';
|
||||
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
|
||||
$sql_order = " order by {$sst} {$sod} ";
|
||||
|
||||
$sql = " select count(*) as cnt
|
||||
|
||||
@@ -87,7 +87,7 @@ $result = sql_query($sql);
|
||||
?>
|
||||
<tr>
|
||||
<td class="td_alignc"><a href="./orderform.php?od_id=<?php echo $row['od_id']; ?>"><?php echo $row['od_id']; ?></a></td>
|
||||
<td class="td_name"><?php echo $href; ?><?php echo $row['od_name']; ?></a></td>
|
||||
<td class="td_name"><?php echo $href; ?><?php echo get_text($row['od_name']); ?></a></td>
|
||||
<td class="td_numsum"><?php echo number_format($row['orderprice']); ?></td>
|
||||
<td class="td_numincome"><?php echo number_format($row['couponprice']); ?></td>
|
||||
<td class="td_numincome"><?php echo number_format($receipt_bank); ?></td>
|
||||
|
||||
@@ -22,7 +22,7 @@ if($w == 'd') {
|
||||
sql_query(" delete from {$g5['g5_shop_sendcost_table']} where sc_id = '$sc_id' ");
|
||||
}
|
||||
} else {
|
||||
$sc_name = isset($_POST['sc_name']) ? trim(strip_tags(clean_xss_attributes($_POST['sc_name']))) : '';
|
||||
$sc_name = isset($_POST['sc_name']) ? addslashes(trim(strip_tags(clean_xss_attributes(stripslashes($_POST['sc_name']))))) : '';
|
||||
$sc_zip1 = isset($_POST['sc_zip1']) ? preg_replace('/[^0-9]/', '', $_POST['sc_zip1']) : '';
|
||||
$sc_zip2 = isset($_POST['sc_zip2']) ? preg_replace('/[^0-9]/', '', $_POST['sc_zip2']) : '';
|
||||
$sc_price = isset($_POST['sc_price']) ? preg_replace('/[^0-9]/', '', $_POST['sc_price']) : '';
|
||||
@@ -43,4 +43,4 @@ if($w == 'd') {
|
||||
sql_query($sql);
|
||||
}
|
||||
|
||||
goto_url('./sendcostlist.php?page='.$page);
|
||||
goto_url('./sendcostlist.php?page='.$page);
|
||||
|
||||
@@ -58,8 +58,8 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
</div>
|
||||
|
||||
<form name="flist" class="local_sch01 local_sch">
|
||||
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
|
||||
<input type="hidden" name="page" value="<?php echo $page; ?>">
|
||||
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
|
||||
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
|
||||
|
||||
<label for="sel_ca_id" class="sound_only">검색대상</label>
|
||||
<select name="sel_ca_id" id="sel_ca_id">
|
||||
@@ -71,7 +71,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
|
||||
$len = strlen($row1['ca_id']) / 2 - 1;
|
||||
$nbsp = "";
|
||||
for ($i=0; $i<$len; $i++) $nbsp .= " ";
|
||||
echo "<option value='{$row1['ca_id']}'".get_selected($row1['ca_id'], $sel_ca_id).">$nbsp{$row1['ca_name']}\n";
|
||||
// 전체 카테고리 경로 표시
|
||||
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
|
||||
echo "<option value='{$row1['ca_id']}'".get_selected($row1['ca_id'], $sel_ca_id).">$nbsp{$category_path}\n";
|
||||
}
|
||||
?>
|
||||
</select>
|
||||
|
||||
@@ -4,7 +4,17 @@ include_once ('../../common.php');
|
||||
include_once(G5_ADMIN_PATH.'/admin.lib.php');
|
||||
include_once(G5_SMS5_PATH.'/sms5.lib.php');
|
||||
|
||||
if (!strstr($_SERVER['SCRIPT_NAME'], 'install.php')) {
|
||||
if (strpos($_SERVER['SCRIPT_NAME'], 'install.php') === false) {
|
||||
// SMS5 테이블 G5_TABLE_PREFIX 적용
|
||||
if($g5['sms5_prefix'] != 'sms5_' && sql_num_rows(sql_query("show tables like 'sms5_config'")))
|
||||
{
|
||||
echo '<script>
|
||||
alert("기존 SMS5 테이블을 sms5 prefix 기준으로 변경합니다.\n(DB 업그레이드에서 자동 적용됩니다.)");
|
||||
location.href = "'.G5_ADMIN_URL.'/dbupgrade.php";
|
||||
</script>';
|
||||
exit;
|
||||
}
|
||||
|
||||
if(!sql_num_rows(sql_query(" show tables like '{$g5['sms5_config_table']}' ")))
|
||||
goto_url('install.php');
|
||||
|
||||
|
||||
@@ -10,14 +10,14 @@ check_admin_token();
|
||||
|
||||
$g5['title'] = "SMS 기본설정";
|
||||
|
||||
$cf_phone = isset($_REQUEST['cf_phone']) ? clean_xss_tags($_REQUEST['cf_phone'], 1, 1) : '';
|
||||
$cf_sms_use = isset($_REQUEST['cf_sms_use']) ? clean_xss_tags($_REQUEST['cf_sms_use'], 1, 1) : '';
|
||||
$cf_sms_type = isset($_REQUEST['cf_sms_type']) ? clean_xss_tags($_REQUEST['cf_sms_type'], 1, 1) : '';
|
||||
$cf_icode_id = isset($_REQUEST['cf_icode_id']) ? clean_xss_tags($_REQUEST['cf_icode_id'], 1, 1) : '';
|
||||
$cf_icode_pw = isset($_REQUEST['cf_icode_pw']) ? clean_xss_tags($_REQUEST['cf_icode_pw'], 1, 1) : '';
|
||||
$cf_icode_server_ip = isset($_REQUEST['cf_icode_server_ip']) ? clean_xss_tags($_REQUEST['cf_icode_server_ip'], 1, 1) : '';
|
||||
$cf_phone = isset($_REQUEST['cf_phone']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_phone']), 1, 1)) : '';
|
||||
$cf_sms_use = isset($_REQUEST['cf_sms_use']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_sms_use']), 1, 1)) : '';
|
||||
$cf_sms_type = isset($_REQUEST['cf_sms_type']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_sms_type']), 1, 1)) : '';
|
||||
$cf_icode_id = isset($_REQUEST['cf_icode_id']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_icode_id']), 1, 1)) : '';
|
||||
$cf_icode_pw = isset($_REQUEST['cf_icode_pw']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_icode_pw']), 1, 1)) : '';
|
||||
$cf_icode_server_ip = isset($_REQUEST['cf_icode_server_ip']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_icode_server_ip']), 1, 1)) : '';
|
||||
$cf_icode_server_port = isset($_REQUEST['cf_icode_server_port']) ? clean_xss_tags($_REQUEST['cf_icode_server_port'], 1, 1) : '';
|
||||
$cf_icode_token_key = isset($_REQUEST['cf_icode_token_key']) ? clean_xss_tags($_REQUEST['cf_icode_token_key'], 1, 1) : '';
|
||||
$cf_icode_token_key = isset($_REQUEST['cf_icode_token_key']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_icode_token_key']), 1, 1)) : '';
|
||||
|
||||
// 회신번호 체크
|
||||
if(!check_vaild_callback($cf_phone))
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user