Compare commits

...
200 Commits
Author SHA1 Message Date
thisgun 5605b539f4 버전 5.5.10 수정 2023-11-10 14:12:48 +09:00
thisgun a8baa8dd7d ss_mb_key 체크함수의 user_agent 에 hook 추가 2023-11-10 13:57:24 +09:00
thisgun 16051b3049 비회원이 비밀글을 작성할 경우 패스워드를 묻는 오류 문제 수정 2023-11-10 12:47:10 +09:00
thisgun db1d56e07b G5_DOMAIN 설정시 url에 타 도메인을 지정할수 없습니다. 메시지가 나오는 오류 수정 #290 2023-11-10 12:21:19 +09:00
thisgun 4455f7d3c9 버전 5.5.9 수정 2023-10-19 11:29:24 +09:00
thisgun 398967f804 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-10-19 11:28:28 +09:00
KkigomiandGitHub ee75b32b3c adm/index.php 페이지에 컨텐츠를 삽입할 수 있는 Hook 추가 (#283)
* 코드 포맷

* adm/index.php 페이지에 컨텐츠를 삽입할 수 있는 Hook 추가

- adm_index_addtional_content_before
- adm_index_addtional_content_after
2023-10-19 11:27:18 +09:00
MayCactusandGitHub c869f29f0d 세션 쿠키 보안 강화 (#282)
* Enhance Session Cookie Security

* Fix user registration link path
2023-10-19 11:27:00 +09:00
KkigomiandGitHub c95168fb0c IP 변경으로 인한 관리페이지 접근 시 접속이 제한되는 문제 해결 (#284)
* `ss_mb_key`를 생성하고 검증할 때 IP를 제거하고 대체 함

프록시 등의 사용으로 IP가 수시로 변경되는 환경이라면 관리페이지 접근에 수시로 제한이 되는 문제를 해결하기 위함

* `ss_mb_key` 세션 값 생성 코드의 중복을 제거하기 위해 정리

* client_key 유효 시간을 세션 동안만 유지되도록 변경
2023-10-19 11:26:28 +09:00
thisgun b8ffd99362 비밀글이 게시판 목록에서 내용, 썸네일이 노출되는 문제 수정#287 2023-10-19 11:17:16 +09:00
thisgun 64e1fbe786 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-10-18 17:23:56 +09:00
thisgun 91715ff830 KG이니시스 통합인증 테스트키 수정 2023-10-18 17:23:43 +09:00
thisgunandGitHub 1fb9e28510 Merge pull request #273 from maycactus-FOSS/bug
Refactor: str_encrypt 클래스의 변수 이름 수정
2023-10-18 12:58:13 +09:00
thisgunandGitHub babbc9afdb Merge pull request #278 from kkigomi/master-2
`$wr_id` 전역변수의 값이 잘못된 타입으로 할당되는 문제 고침
2023-10-18 12:57:37 +09:00
thisgunandGitHub 04030f9274 Merge pull request #280 from kkigomi/patch-comment
불필요한 주석 제거
2023-10-18 12:56:55 +09:00
thisgunandGitHub 3085703c61 Merge pull request #279 from kkigomi/patch-1
`delete_cache_latest` Hook 추가
2023-10-18 12:56:31 +09:00
thisgunandGitHub 20dc211a82 Merge pull request #285 from kkigomi/feature/auth.au_menu
관리권한 설정 시 메뉴명(au_menu)의 길이 제한으로 인한 문제 개선
2023-10-18 10:33:39 +09:00
thisgunandGitHub a773839338 Merge pull request #289 from kkigomi/feature/deprecated-sql_password
sql_password() 함수를 사용하는 것을 권장하지 않음을 표기
2023-10-18 10:31:04 +09:00
kkigomi 84b22909c5 sql_password() 함수를 사용하는 것을 권장하지 않음을 표기
https://github.com/gnuboard/gnuboard5/issues/247
2023-10-15 20:39:44 +09:00
kkigomi 28bfcea9c2 관리권한 설정 시 메뉴 ID(au_menu)의 길이 제한을 20에서 50으로 확장 2023-09-09 21:48:34 +09:00
kkigomi 8cd1df0f43 불필요한 주석 제거 2023-08-31 21:18:41 +09:00
KkigomiandGitHub cf2a8ab282 delete_cache_latest Hook 추가
`delete_cache_latest()` 함수에 `delete_cache_latest` Hook 추가
2023-08-30 01:06:07 +09:00
KkigomiandGitHub 941f3e135a $wr_id 전역변수의 값이 잘못된 타입으로 할당되는 문제 고침
짧은 주소 '글 이름' 주소로 접근할 때 `$wr_id` 전역변수의 값이 `string` 타입으로  잘못 할당되는 문제를 `int` 타입으로 올바르게 바로 잡습니다
2023-08-21 09:24:30 +09:00
thisgun 4b9b1af01e 버전 5.5.8.3.4 수정 2023-08-17 14:40:08 +09:00
thisgun 41d48891f4 wr_num 필드 값이 동시성 문제로 겹치는 경우 답변글에 대한 권한이 잘못 주어지는 등의 문제 다시 수정 #265 2023-08-17 14:39:05 +09:00
maycactus 616f5b8d46 Refactor: str_encrypt 클래스의 변수 이름 수정 2023-08-16 15:37:08 -04:00
thisgun a96460948c 버전 5.5.8.3.3 수정 2023-08-16 15:52:11 +09:00
thisgun 337ee4e68f Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-08-16 15:49:14 +09:00
thisgunandGitHub 7af4888458 Merge pull request #268 from kkigomi/feature/hook-qawrite_update
1:1문의 답변 시 `qawrite_update` Hook에서 답변 글의 ID를 전달하도록 개선
2023-08-16 15:47:52 +09:00
thisgunandGitHub fdc695d08c Merge pull request #270 from kkigomi/feature/hook-shop-itemcopy
영카트 상품 복사 후 `shop_admin_itemcopy` Event Hook 추가
2023-08-16 15:47:09 +09:00
thisgunandGitHub 9fe34dae1d Merge pull request #267 from kkigomi/feature/hook-qa_delete
`qa_delete` Event Hook에서 실제 삭제된 ID 목록을 전달하도록 개선
2023-08-16 15:46:28 +09:00
thisgunandGitHub 4364058313 Merge pull request #266 from kkigomi/patch-qadelete-answer
QA에서 질문글 삭제 시 답변글의 첨부파일 및 썸네일을 삭제하지 못하는 문제 수정
2023-08-16 15:45:25 +09:00
thisgunandGitHub 0642c48106 Merge pull request #263 from kkigomi/patch-owl
owl.video.play.png 파일이 없어 발생하는 오류 수정
2023-08-16 15:44:15 +09:00
thisgunandGitHub d74c7b24bf Merge pull request #259 from kkigomi/patch-1
adm/view.php 파일에서 $sub_menu 등 변수 위치를 변경
2023-08-16 15:43:58 +09:00
thisgunandGitHub fec5569c71 Merge pull request #256 from maycactus-FOSS/bug
코드 일관성, 가독성 향상 및 버그 수정
2023-08-16 15:43:42 +09:00
thisgun 876534a440 wr_num 필드 값이 동시성 문제로 겹치는 경우 답변글에 대한 권한이 잘못 주어지는 등의 문제 #265 2023-08-16 13:01:05 +09:00
thisgun 5d4ba1030e 관리페이지 메뉴 접근 권한이 부여된 경우 관리페이지의 index 페이지의 정보가 노출되는 문제 #258 2023-08-16 11:44:42 +09:00
thisgun e43e424d80 세션 고정 취약점 수정 #257 2023-08-16 10:01:07 +09:00
kkigomi 5036254b69 php 5.2 호환성 문제 수정 2023-08-13 21:48:08 +09:00
kkigomi 2ae4046d29 영카트 상품 복사 후 shop_admin_itemcopy Event Hook 추가 2023-08-12 19:08:39 +09:00
kkigomi ccdbdebdec 1:1문의 답변 시 qawrite_update Hook에서 답변 글의 ID를 전달하도록 개선 2023-08-11 21:19:42 +09:00
kkigomi 1c4465a692 qa_delete Event Hook에서 실제 삭제된 ID 목록을 전달하도록 개선
`$tmp_array` 목록은 삭제를 요청한 목록이지만 작성자, 답글 등의 이유로 실제 삭제되지 않을 수 있음. 두번째 인자로 실제로 삭제 처리된 목록을 넘겨주도록 개선 함.
2023-08-11 19:41:25 +09:00
kkigomi bcbabf50f2 QA에서 질문글 삭제 시 답변글의 첨부파일 및 썸네일을 삭제하지 못하는 문제 수정
답변글의 정보를 잘못 가져오는 문제로 답변글의 첨부파일, 첨부파일의 썸네일, 에디터 이미지의 썸네일을 삭제하지 못하는 문제 고침
2023-08-11 19:29:50 +09:00
maycactus 3da5145bef Fix undefined variable issue in mobile login page 2023-08-09 11:48:53 -04:00
thisgun 6868cee8d1 영카트 모바일 주문시 SQL Injection 취약점 수정 2023-08-07 10:26:50 +09:00
kkigomi 870dcec68d owl.video.play.png 파일이 없어 발생하는 오류 수정
https://github.com/OwlCarousel2/OwlCarousel2/blob/develop/dist/assets/owl.video.play.png
2023-08-01 00:38:45 +09:00
kkigomiandGitHub 4735d62770 adm/view.php 파일에서 $sub_menu 등 변수 위치를 변경
`$sub_menu`, `$g5['title']` 변수를 생성처리가 `admin_request_handler_*` Event Hook 보다 이후에 실행되어 해당 Hook에서 이를 활용하지 못하는 문제를 해결합니다.
2023-07-26 12:13:07 +09:00
maycactus 2c88ef6d13 Update CSS styles for improved consistency
This commit updates the CSS styles for better consistency and correctness. The changes involve:

1. Replacing 'z-index: -1px' with 'z-index: -1' to correct the z-index value. The value should be an integer, not a length with a unit.
2. Replacing 'font-size:bold;' with 'font-weight:bold;' to set the font weight to bold properly.

Please note that I haven't tested the changes yet, but they should have a positive impact on the overall appearance and functionality of the elements styled with these CSS rules.
2023-07-25 14:06:43 -04:00
maycactus 12ce06c2d2 Refactor CSS styles for improved readability
This commit refactors the CSS styles by removing unnecessary closing parentheses from the box-shadow declarations and redundant empty color declarations. Additionally, it corrects the missing CSS property values in the .btn_submit and #mb_login_notmb p rules for proper styling.

The changes do not affect the visual appearance of the elements but make the CSS code cleaner and more maintainable.
2023-07-25 13:50:30 -04:00
maycactus 3a7d06b19e Fix array element and string offset access using square brackets
In accordance with the PHP RFC deprecating the curly brace syntax for accessing array elements and string offsets, this commit replaces all instances of {} with [].

By making this change, we ensure the codebase remains compliant with the recommended syntax, enhancing code readability and maintainability. The deprecation of curly brace syntax was done to align with best practices and promote a consistent code style.
2023-07-25 13:34:00 -04:00
thisgun 641656047d 버전 5.5.8.3.2 수정 2023-07-17 12:12:52 +09:00
thisgun 3becc03d23 CHEditor에서 이미지 업로드시 서버 내 경로가 노출되는 문제 수정 #248 2023-07-17 11:55:45 +09:00
thisgun 6eaa6ee22a Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-07-17 11:54:08 +09:00
thisgunandGitHub a8524eb070 Merge pull request #243 from kkigomi/feature/admin-hooks
관리자 페이지 및 일부 데이터 업데이트 시 Event hook 추가
2023-07-17 11:47:50 +09:00
thisgunandGitHub db9b4ffd50 Merge pull request #246 from kkigomi/feature/cheditor-hook-get_editor_upload_url
CHEditor에서 이미지 업로드시 get_editor_upload_url Hook에 파일의 정보 추가
2023-07-17 11:47:37 +09:00
thisgunandGitHub 9416b7dd9a Merge pull request #250 from kkigomi/patch-1
add_replace()에서 $args 값을 1로 변경
2023-07-17 11:47:24 +09:00
thisgunandGitHub 1634065870 Merge pull request #252 from kkigomi/patch-3
get_microtime 함수 개선
2023-07-17 11:47:11 +09:00
thisgun 14af11d0fa 옵션 재고 이후에 상품 재고를 체크하도록 수정 2023-07-11 11:17:29 +09:00
thisgun ec3fdce5c7 장바구니 업데이트시 sum_qty변수 형변환 수정 2023-07-11 10:41:33 +09:00
thisgun 79ce9ec984 6월 25일 제보한 영카트 보안취약점 수정 #249 2023-07-11 10:33:39 +09:00
thisgun 8eb1d46be1 저장소에 포함된 의미없는 파일삭제 #245 2023-07-10 18:38:22 +09:00
thisgun cbdaccbdec Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-07-10 18:03:15 +09:00
thisgunandGitHub ff6b160774 Merge pull request #244 from kkigomi/patch-2
Hook에 Closure를 리스너로 등록할 수 있도록 개선
2023-07-10 12:38:34 +09:00
kkigomiandGitHub f96ff445b9 get_microtime 함수 개선
불필요한 연산 제거
2023-07-09 05:05:12 +09:00
kkigomiandGitHub 6e684e80f2 add_replace()에서 $args 값을 1로 변경
replace hook은 값을 반환해야하므로 항상 최소 1개의 인자를 받아야하지만 기본 값이 0이어서 매번 이를 변경해줘야하는 문제
2023-07-08 06:58:03 +09:00
thisgun ffc8706a76 [KVE-2023-5153] XSS 취약점 수정 2023-07-04 18:37:23 +09:00
kkigomi 8ec09b0059 CHEditor에서 이미지 업로드시 get_editor_upload_url Hook에 파일의 정보 추가
`get_editor_upload_url` Hook의 세번째 인자에 파일의 추가 정보를 전달.
smarteditor2에서 정의한 것과 동일한 유형으로 데이터를 담음.
2023-06-30 22:18:30 +09:00
kkigomi af64737b63 PRS-12 코드 포맷 2023-06-30 22:02:42 +09:00
kkigomiandGitHub 81792d2595 Hook에 Closure를 리스너로 등록할 수 있도록 개선 2023-06-26 22:34:49 +09:00
kkigomi bbbc568db8 관리자 페이지 및 일부 데이터 업데이트 시 Event hook 추가 2023-06-25 03:49:10 +09:00
thisgun 4eba618a82 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-06-19 17:55:43 +09:00
thisgun accf20044f 버전 5.5.8.3.1 수정 2023-06-19 17:52:34 +09:00
thisgun aaadf1487d 영카트 쿠폰 발행 시 UX 오류 #230 2023-06-19 17:36:14 +09:00
thisgun 44798a4ef5 설치시 자동생성되는 게시판 글읽기 포인트로 인한 문제 수정 #231 2023-06-19 17:20:51 +09:00
thisgun 992641dfad 구글 서치 콘솔에 맞지 않는 게시판xml 수정 #234 2023-06-19 17:00:42 +09:00
thisgunandGitHub 451ece8d8c Merge pull request #238 from kkigomi/feature/html-purifier
Hook - HTMLPurifier 설정을 변경할 수 있는 `html_purifier_config` 이벤트 Hook 추가
2023-06-19 15:10:39 +09:00
thisgun bcda18cbd5 1:1문의 삭제시 hook 이벤트 추가 2023-06-19 15:08:56 +09:00
thisgun 2a8f5f6035 상품 검색 페이지 xss 취약점 수정 2023-06-16 17:20:18 +09:00
thisgun f4821aa49a 비회원으로 상품을 장바구니에 담아두고 후 로그인하면 mb_id가 누락되는 문제 수정 2023-06-15 17:16:47 +09:00
kkigomi 476b06792a 코드 포맷 2023-06-01 18:15:48 +09:00
kkigomi 9489254bbf html_purifier() 함수에 html_purifier_config 이벤트 Hook 추가
리스너에서는 첫번째 인자로 `HTMLPurifier_Config` 객체를 받아 설정을 변경할 수 있다
2023-06-01 18:15:26 +09:00
thisgun 8bcac60bda 버전 5.5.8.3 수정 2023-04-17 14:42:58 +09:00
thisgun fe03163cce XSS 취약점 수정 2023-04-17 14:41:38 +09:00
thisgun 8ecc5ba241 min_wr_num Undefined 경고문이 나올수 있는 코드 수정 2023-04-17 12:29:42 +09:00
thisgun 4204f7970e 안드로이드 chrome 112.0.5615.48에서 상품옵션선택이 안되는 문제 수정 2023-04-17 12:16:12 +09:00
thisgun 9cd2841006 버전 5.5.8.2.9 수정 2023-04-13 20:11:54 +09:00
thisgun 4b92543c61 KG이니시스 TX모듈을 사용하는 코드를 API로 전환 건 2023-04-13 20:10:48 +09:00
thisgun b01adc51c7 버전 5.5.8.2.8 수정 2023-03-23 12:54:34 +09:00
thisgun bfdc48b021 NHN_KCP 애플페이 추가 2023-03-23 12:52:40 +09:00
thisgun 10b3a9c841 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-03-23 12:25:33 +09:00
thisgunandGitHub 3f27a5e32d Merge pull request #223 from kkigomi/feature/rewrite
rewrite 룰 제안에 Hook 추가
2023-03-23 12:18:59 +09:00
thisgun a904c5c634 Object cache의 데이터를 삭제하지 못하는 버그 수정 2023-03-23 12:00:05 +09:00
thisgun d603f2d5b3 undefined error 경고문에 따른 return_url변수 초기화 2023-03-23 11:19:29 +09:00
thisgun 275f7e5d8a PHP8버전대에서 경고문 나오는 FAQ Undefined variable 수정 2023-03-23 11:10:28 +09:00
thisgun 2595a7a45d 모바일 위시리스트 상품 URL 코드 수정 2023-03-21 19:07:44 +09:00
thisgun cb346b08c1 쇼핑몰 상품 주문시 it_name 에 태그가 포함되어있는 경우 발생되는 오류 수정 2023-03-21 19:00:13 +09:00
kkigomiandGitHub 3db2dc8be3 Merge branch 'gnuboard:master' into feature/rewrite 2023-01-25 19:32:47 +09:00
kkigomi b3451f1cc2 rewrite 설정 코드 보기에서 기존 hook 보다 앞선 출력 위치에 hook 추가
기존 rule 때문에 hook으로 추가해도 접근 차단등의 룰을 적용하지 못하는 문제를 해결하기 위함
- add_nginx_conf_pre_rules
- add_mod_rewrite_pre_rules
2023-01-25 16:58:00 +09:00
kkigomi b557483e1d 코드 포맷. PSR-12 2023-01-25 16:53:10 +09:00
thisgun d28be44108 버전 5.5.8.2.7 수정 2023-01-25 16:52:29 +09:00
thisgun f61d6cc09a SMS관리 휴대폰관리 페이지 PHP특정버전에서 오류나는 문제 수정 2023-01-25 12:30:13 +09:00
thisgun 6fa0f0e704 정렬 기능에 짧은 주소 적용 오류를 다시 수정 2023-01-25 11:06:07 +09:00
thisgun 66039a4b37 PHP8 버전에서 경고문이 나오는 코드 수정 2023-01-20 11:17:50 +09:00
thisgun aca4733b12 쇼핑몰 장바구니에서 재고 이상 주문할수 있는 오류 수정 2023-01-20 11:17:20 +09:00
thisgun 85b97f4b29 버전 5.5.8.2.6 수정 2023-01-13 11:06:48 +09:00
thisgun 724a4e4bf6 [KVE-2023-0046] 그누보드5(gnuboard5) SQL Injection 취약점 2023-01-13 11:00:00 +09:00
thisgun 9cf8804611 Merge branch 'master' of github.com:gnuboard/g5-update 2023-01-12 10:43:41 +09:00
thisgun 8f3893bb43 중복코드 삭제 및 경고문이 나오는 코드 수정 2023-01-12 10:43:25 +09:00
kir rio 7617aba611 cheditor this.URI 추가 2023-01-11 12:06:25 +09:00
kir rio d99641d122 cheditor 5.1.9.4 버전 업데이트 2023-01-11 10:21:44 +09:00
thisgun 7516424989 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-01-09 16:06:27 +09:00
thisgunandGitHub 1cb12d9f2c Merge pull request #215 from kkigomi/feature/sql_query_fix
#212 PR에서 DB 커넥션 지정 오류 수정 & sql_query_after 이벤트에 누락된 $source 파라메터 추가
2023-01-09 16:00:52 +09:00
thisgunandGitHub dbcb6a2cb6 Merge pull request #218 from kkigomi/feature/sideview
회원 sideview 메뉴에 Replace Hook 추가
2023-01-09 16:00:38 +09:00
thisgunandGitHub 18c42a648e Merge pull request #219 from kkigomi/feature/goto_url
goto_url 함수에 Event Hook 추가
2023-01-09 16:00:06 +09:00
thisgunandGitHub f5e2252997 Merge pull request #220 from kkigomi/feature/html_process_buffer
html_process->run()에 Replace Hook 추가
2023-01-09 15:59:44 +09:00
thisgun 6fd339174e 내용관리 hook 코드 추가 2023-01-09 15:33:03 +09:00
kkigomi 1891b5eb38 회원 sideview 메뉴에 Replace Hook 추가 2023-01-08 03:35:26 +09:00
kkigomi 3fcc1f2d5f html_process->run()에 Replace Hook 추가 2023-01-07 01:32:14 +09:00
kkigomi 4958cc9e35 goto_url 함수에 Event Hook 추가 2023-01-07 01:31:05 +09:00
thisgun 1750e957d2 모바일 상품 페이지 오타 수정 2023-01-03 15:16:33 +09:00
thisgun abfeee5e92 1:1문의 답변 파일첨부 기능 추가 2023-01-03 14:53:08 +09:00
thisgun c3272f9170 게시판, 1:1문의, 쇼핑몰상품 상단내용 하단내용에 hook 적용 2023-01-02 17:58:22 +09:00
thisgun df176c6ad9 NHN_KCP 본인인증 모바일에서 새창열기 방식으로 수정 2022-12-20 17:41:22 +09:00
thisgun 22bfc5e9bb 모바일에서 패스워드 찾기 본인인증시 NHN_KCP 본인인증 스크립트 오류 수정 2022-12-19 14:05:33 +09:00
thisgun 4e0cd0d911 게시판 정렬 기능에 짧은주소 적용 2022-12-19 11:18:28 +09:00
thisgun 25091a201b PHP8 버전에서 경고문이 나올수 있는 코드 수정 2022-12-19 11:13:08 +09:00
kkigomi 3706ef99d3 #212 PR에서 DB 커넥션 지정 오류 수정 & sql_query_after 이벤트에 누락된 $source 파라메터 추가 2022-12-10 17:12:22 +09:00
thisgun 69a4998fce 버전 5.5.8.2.5 수정 2022-12-08 16:19:16 +09:00
thisgun 513976b5a2 [KVE-2022-2037] Gnuboard5 관리자페이지 내 Stored XSS 취약점 수정 2022-12-08 16:12:48 +09:00
thisgun 97a8352117 [KVE-2022-2036] Gnuboard5 관리자페이지 내 Stored XSS 취약점 수정 2022-12-01 15:22:48 +09:00
thisgun 21dc36199f Merge branch 'master' of github.com:gnuboard/gnuboard5 2022-12-01 10:27:52 +09:00
thisgunandGitHub 0a18368759 Merge pull request #212 from kkigomi/feature/sql_query
debugbar 쿼리 오류 표시 추가 및 G5_COLLECT_QUERY 설정 추가
2022-11-28 09:43:01 +09:00
kkigomi 6d9db83789 debugbar 쿼리 오류 표시 추가 및 G5_COLLECT_QUERY 설정 추가
- 210 이슈에서 제안했던 개선안
- debugbar에 오류 등으로 실패한 쿼리가 나오지 않는 문제 수정
- 실패한 쿼리에 오류 메시지 출력
- 쿼리가 실행된 파일, 라인 함수 표시
- G5_COLLECT_QUERY 상수 설정 추가로 디버그 모드(G5_DEBUG)를 켜지 않아도 서드파티 플러그인에서 쿼리 목록을 수집할 수 있도록 개선
2022-11-28 07:20:30 +09:00
thisgun 3e53cd8ff6 회원 탈퇴파일 오타 수정 및 이벤트 추가 #209 2022-11-22 19:36:35 +09:00
thisgun 816a32d5c9 set_cookie 함수의 httponly 인자의 기본값을 true로 수정 #208 2022-11-22 19:27:13 +09:00
thisgun 529b8a1004 html_process 에서 title link 태그가 없을경우 css 파일을 로드 못하는 문제 수정 #207 2022-11-22 17:25:10 +09:00
thisgun 62d0bf5c4e html_process 클래스 싱글톤 적용 #206 2022-11-22 16:29:43 +09:00
thisgun 4c6b833f73 새로운 인증 수단을 위한 패스워드 확인 없는 로그인 처리 지원 #205 2022-11-22 15:08:22 +09:00
thisgun 21532eb9bf Merge branch 'master' of github.com:gnuboard/g5-update into next_55825 2022-11-22 11:56:29 +09:00
kjh cd50af93fd 버전 5.5.8.2.4 수정 2022-11-22 11:30:07 +09:00
thisgun 589b7f4e39 테마설정에서 이미지가 영역을 벗어나는 문제 수정#204 2022-11-21 14:07:06 +09:00
thisgun 9c8f7128f2 css 코드중 오타 수정 2022-11-21 11:54:52 +09:00
thisgun a93008d392 set_http 함수 코드 수정 2022-11-21 11:47:32 +09:00
thisgun d3561623aa 휴대폰번호 입력 필수 입력 오류 수정 2022-11-21 11:41:18 +09:00
thisgun 311e879563 [KVE-2022-1984]관리자 개인결제 Stored XSS 취약점 수정 2022-11-21 10:35:49 +09:00
thisgun 9932b99a51 KG이니시스 가상계좌 노티 전송 IP 추가 2022-10-21 10:04:07 +09:00
thisgun 5c9ed36bf2 kakao cdn에 async 속성 추가 2022-10-17 11:56:41 +09:00
thisgun dbc8e1676a 버전 5.5.8.2.3 수정 2022-10-17 10:59:59 +09:00
thisgun 749345e502 Merge branch 'master' of github.com:gnuboard/g5-update 2022-10-17 10:57:35 +09:00
thisgun 7c8a21ecc0 카카오 우편번호 서비스 url 수정 및 속성에 async 추가 2022-10-17 10:57:00 +09:00
KimTom89andGitHub 8751ab122a Merge pull request #10 from gnuboard/G5-154/search-keyword-trim
[fix] 사이트 내 전체검색 > 검색어 양 끝의 공백 제거
2022-10-05 12:20:50 +09:00
kjh 0f3e6125b5 [fix] 사이트 내 전체검색 > 검색어 양 끝의 공백 제거 2022-10-05 11:50:08 +09:00
kjh a21d02f4c5 버전 5.5.8.2.2 수정 2022-10-04 15:14:35 +09:00
thisgun 2f9fb355e3 [KVE-2022-0992] 취약점 다시 재수정 2022-09-27 17:15:46 +09:00
thisgun 8074bce274 Merge branch 'master' of github.com:gnuboard/g5-update 2022-09-27 10:13:35 +09:00
thisgun 85dbbe946a 비번찾기 후 빈 페이지가 나오는 문제 수정 2022-09-27 10:12:18 +09:00
kjh 1f2e79b188 Merge branch 'master' of github.com:gnuboard/g5-update 2022-09-16 16:59:50 +09:00
thisgun 27434107e8 [KVE-2022-0992] 그누보드5 스크립트 실행 취약점 수정 2022-09-15 11:30:10 +09:00
thisgun f1a303e445 버전 5.5.8.2.1 수정 2022-09-13 10:38:05 +09:00
thisgun ba062ca5b6 [KVE-2022-0981] 그누보드 Reflected XSS 취약점 2022-09-01 16:08:08 +09:00
thisgun 34774f0fc3 Merge branch 'master' of github.com:gnuboard/gnuboard5 2022-09-01 15:15:00 +09:00
thisgunandGitHub 26b22ac9ca Merge pull request #199 from 39hn/fix/delivery-company-url
fix: 택배사 배송조회 주소 수정
2022-09-01 15:10:03 +09:00
thisgunandGitHub 9e4a8a95b0 Merge pull request #201 from KimTom89/fix/samesite-condition
Fix gnuboard/gnuboard5#200 HTTP_X_FORWARDED_PROTO 조건 추가
2022-09-01 15:07:29 +09:00
thisgun 1bca642b33 모바일 쿠폰적용 후 취소 오류 수정 2022-09-01 15:05:41 +09:00
thisgun 3a59bca369 관리자 회원 수정에서 관리자는 탈퇴일자 또는 접근차단일자를 적용못하게 수정 2022-08-25 10:29:11 +09:00
thisgun 5ad2307175 메일보내기 메일주소를 도메인과 동일하게 권장하는 문구 추가 2022-08-25 10:10:29 +09:00
kjh 25b3d8f6ed Fix gnuboard/gnuboard5#200 HTTP_X_FORWARDED_PROTO 조건 추가 2022-08-22 15:57:20 +09:00
thisgun 0d02afd712 장바구니 레이어 z-index 속성 수정 2022-08-19 09:55:22 +09:00
39hn 78d5dce761 fix: 택배사 배송조회 주소 수정
대신택배, 우체국, 한진택배, CVSnet편의점택배, 건영택배 주소 수정
2022-08-10 13:05:17 +09:00
kjh 45d5404520 Merge branch 'master' of github.com:gnuboard/g5-update 2022-08-05 14:50:01 +09:00
thisgun 1e6710a55b 투표에 사용, 미사용 기능 추가 (크레이티브님,210910) merge 2022-07-28 11:51:33 +09:00
thisgun 463ca06a21 버전 5.5.8.2 수정 2022-07-26 14:03:46 +09:00
thisgun 71f58f3108 KVE-2021-1116 그누보드 XSS 취약점 수정 2022-07-26 13:38:20 +09:00
thisgun a6e302ff84 KCAPTCHA php5.3 버전 이하에서 나는 오류 수정 2022-07-26 11:35:33 +09:00
thisgun 0c275d0907 본인인증 업데이트시 hook 이벤트 추가 2022-07-25 10:34:51 +09:00
thisgun fa7d0bc717 로그인시 쓰기권한 fclose전에 is_resource로 검사 2022-07-25 10:30:28 +09:00
thisgun 95492a5cd8 G5-82 <사용하지 않는 구글플러스 관련 코드 삭제> 2022-07-11 11:02:46 +09:00
thisgun 58dc48d3ea 영카트 상품리스트 sort 키에 it_name 추가 2022-07-11 10:32:49 +09:00
thisgun 281bb5427c 영카트 상품리스트 sort 키에 it_name 추가 2022-07-07 10:04:40 +09:00
thisgunandGitHub 0577882c6c Merge pull request #185 from seeoya/master
프론트 버그 신고 내역 처리
2022-07-04 17:37:40 +09:00
thisgun be758d57a5 버전 5.5.8.1.2 수정 2022-07-01 09:56:11 +09:00
thisgun 3cee6ede91 토큰 오류로 상품복사가 안되는 오류 수정 2022-07-01 09:55:11 +09:00
thisgun 5d86287069 영카트 주문내역에서 기타선택->반품,품절 검색이 안되는 오류 수정 2022-06-28 09:52:12 +09:00
thisgun 1a12b3e52b 버전 5.5.8.1.1 수정 2022-06-23 16:28:21 +09:00
thisgun 929183b3e3 [KVE-2022-0175] 그누보드 sql 취약점 수정 2022-06-23 14:29:14 +09:00
seeoya c1a45a1bec G5-137 모바일 쇼핑몰 장바구니 닫힘 태그 누락 (eyoom님, 220621) 2022-06-21 18:42:06 +09:00
Hailey KimandGitHub 444c6d88c2 Merge branch 'gnuboard:master' into master 2022-06-21 18:06:23 +09:00
thisgun 2366e8ebfb 버전 5.5.8.1 수정 2022-06-20 14:16:28 +09:00
thisgun a0bfc2cf6a sql_query 함수내 불필요한 코드 삭제 2022-06-20 11:32:35 +09:00
thisgun 22ea3d39c1 [KVE-2022-0193] 그누보드(영카트) SSRF & Business Logic Bug 취약점 수정 2022-06-17 17:11:05 +09:00
thisgun d4f4612b22 안전하지 않는 변수에 필터링 추가 2022-06-17 12:23:21 +09:00
thisgun e061ad852b [KVE-2022-0158] 그누보드(영카트)5 Reflected XSS 및 SQL Injection 취약점 수정 2022-06-17 12:13:54 +09:00
thisgun 4883fb18ae [KVE-2022-0133] 그누보드 XSS, CSRF 취약점 수정 2022-06-16 16:06:33 +09:00
thisgun 32e9797fef [KVE-2022-0143] 그누보드 Open Redirect, Reflected XSS 취약점 수정 2022-06-16 14:15:07 +09:00
thisgun bafa1c43bf [KVE-2022-0120]그누보드_부적절한_권한_검증_취약점_수정 2022-06-15 16:11:06 +09:00
thisgun d8b6297579 check_url_host 함수에 hook 적용 2022-06-15 13:40:18 +09:00
thisgun 251dfc26e8 [KVE-2022-0137] 그누보드 XSS, SQL Injection 취약점 수정 2022-06-14 18:18:05 +09:00
수영andGitHub 958b9342b5 Merge branch 'gnuboard:master' into master 2022-06-07 17:24:23 +09:00
seeoya adc8e94774 G5-88 관리자 : 미사용 CSS 제거 (묵혼님, 220503) 2022-05-03 17:29:20 +09:00
seeoya 26857a8d50 G5-87 쇼핑몰 : KCP 결제창 표시될 때 화면이 스크롤되지 않도록 수정 (HSCOMM님, 220503) 2022-05-03 16:12:34 +09:00
262 changed files with 2941 additions and 8051 deletions
+1
View File
@@ -87,6 +87,7 @@ if (!empty($_COOKIE['g5_admin_btn_gnb'])) {
?>
<script>
var g5_admin_csrf_token_key = "<?php echo (function_exists('admin_csrf_token_key')) ? admin_csrf_token_key() : ''; ?>";
var tempX = 0;
var tempY = 0;
+3 -1
View File
@@ -83,11 +83,13 @@ function delete_confirm2(msg)
function get_ajax_token()
{
var token = "";
var token = "",
admin_csrf_token_key = (typeof g5_admin_csrf_token_key !== "undefined") ? g5_admin_csrf_token_key : "";
$.ajax({
type: "POST",
url: g5_admin_url+"/ajax.token.php",
data : {admin_csrf_token_key:admin_csrf_token_key},
cache: false,
async: false,
dataType: "json",
+31 -6
View File
@@ -421,6 +421,16 @@ function get_sanitize_input($s, $is_html = false)
return $s;
}
function domain_mail_host($is_at=true){
list($domain_host,) = explode(':', $_SERVER['HTTP_HOST']);
if ('www.' === substr($domain_host, 0, 4)) {
$domain_host = substr($domain_host, 4);
}
return $is_at ? '@'.$domain_host : $domain_host;
}
function check_log_folder($log_path, $is_delete = true)
{
@@ -481,6 +491,18 @@ function check_admin_token()
return true;
}
function admin_csrf_token_key($is_must=0){
global $member;
$key = '';
if($is_must || !((isset($_SERVER['HTTP_X_REQUESTED_WITH']) && strtolower($_SERVER['HTTP_X_REQUESTED_WITH']) == 'xmlhttprequest'))){
$key = md5((isset($_SERVER['SERVER_SOFTWARE']) ? $_SERVER['SERVER_SOFTWARE'] : '').(defined('G5_TOKEN_ENCRYPTION_KEY') ? G5_TOKEN_ENCRYPTION_KEY : '').$member['mb_id'].$_SERVER['DOCUMENT_ROOT']);
}
return run_replace('admin_csrf_token_key', $key, $is_must);
}
// 관리자 페이지 referer 체크
function admin_referer_check($return = false)
{
@@ -595,13 +617,12 @@ if (!$member['mb_id']) {
}
}
// 관리자의 아이피, 브라우저와 다르다면 세션을 끊고 관리자에게 메일을 보낸다.
$admin_key = md5($member['mb_datetime'] . get_real_client_ip() . $_SERVER['HTTP_USER_AGENT']);
if (get_session('ss_mb_key') !== $admin_key) {
// 관리자의 클라이언트를 검증하여 일치하지 않으면 세션을 끊고 관리자에게 메일을 보낸다.
if (!verify_mb_key($member)) {
session_destroy();
include_once G5_LIB_PATH . '/mailer.lib.php';
// 메일 알림
mailer($member['mb_nick'], $member['mb_email'], $member['mb_email'], 'XSS 공격 알림', $_SERVER['REMOTE_ADDR'] . ' 아이피로 XSS 공격이 있었습니다.<br><br>관리자 권한을 탈취하려는 접근이므로 주의하시기 바랍니다.<br><br>해당 아이피는 차단하시고 의심되는 게시물이 있는지 확인하시기 바랍니다.' . G5_URL, 0);
@@ -663,5 +684,9 @@ if (isset($_REQUEST) && $_REQUEST) {
}
}
// 관리자에서는 추가 스크립트는 사용하지 않는다.
//$config['cf_add_script'] = '';
// 관리자에서는 추가 스크립트와 추가 매타태그, 방문자분석 스크립트가 실행되지 않게 빈값으로 합니다.
if (run_replace('safe_admin_add_script_boolean', false) === false) {
$config['cf_analytics'] = '';
$config['cf_add_script'] = '';
$config['cf_add_meta'] = '';
}
+1 -1
View File
@@ -5,7 +5,7 @@ if (!defined('_GNUBOARD_')) {
// 그누보드5.4.5.5 버전과 영카트5.4.5.5.1 버전이 통합됨에 따라 그누보드 버전만 표시
// $print_version = defined('G5_YOUNGCART_VER') ? 'YoungCart Version '.G5_YOUNGCART_VER : 'Version '.G5_GNUBOARD_VER;
$print_version = 'Version ' . G5_GNUBOARD_VER;
$print_version = ($is_admin == 'super') ? 'Version ' . G5_GNUBOARD_VER : '';
?>
<noscript>
+6
View File
@@ -3,6 +3,12 @@ require_once './_common.php';
set_session('ss_admin_token', '');
$admin_csrf_token_key = isset($_POST['admin_csrf_token_key']) ? $_POST['admin_csrf_token_key'] : '';
if(function_exists('admin_csrf_token_key') && $admin_csrf_token_key !== admin_csrf_token_key(1)){
die(json_encode(array('error' => '토큰키 에러!', 'url' => G5_URL)));
}
$error = admin_referer_check(true);
if ($error) {
die(json_encode(array('error' => $error, 'url' => G5_URL)));
+3 -2
View File
@@ -7,12 +7,13 @@ auth_check_menu($auth, $sub_menu, 'w');
$g5['title'] = '게시판 복사';
require_once G5_PATH . '/head.sub.php';
$bo_table = $_REQUEST['bo_table'];
if (empty($bo_table)) {
alert_close("정상적인 방법으로 이용해주세요.");
}
?>
<script>
var g5_admin_csrf_token_key = "<?php echo (function_exists('admin_csrf_token_key')) ? admin_csrf_token_key() : ''; ?>";
</script>
<script src="<?php echo G5_ADMIN_URL ?>/admin.js?ver=<?php echo G5_JS_VER; ?>"></script>
<div class="new_win">
+4 -5
View File
@@ -89,10 +89,10 @@ $sql = " insert into {$g5['board_table']}
bo_new = '{$board['bo_new']}',
bo_hot = '{$board['bo_hot']}',
bo_image_width = '{$board['bo_image_width']}',
bo_skin = '{$board['bo_skin']}',
bo_mobile_skin = '{$board['bo_mobile_skin']}',
bo_include_head = '{$board['bo_include_head']}',
bo_include_tail = '{$board['bo_include_tail']}',
bo_skin = '" . sql_real_escape_string($board['bo_skin']). "',
bo_mobile_skin = '" . sql_real_escape_string($board['bo_mobile_skin']). "',
bo_include_head = '" . sql_real_escape_string($board['bo_include_head']). "',
bo_include_tail = '" . sql_real_escape_string($board['bo_include_tail']). "',
bo_content_head = '" . addslashes($board['bo_content_head']) . "',
bo_content_tail = '" . addslashes($board['bo_content_tail']) . "',
bo_mobile_content_head = '" . addslashes($board['bo_mobile_content_head']) . "',
@@ -191,7 +191,6 @@ if ($copy_case == 'schema_data_both') {
sql_query($sql, false);
// 4.00.01
// 위의 코드는 같은 테이블명을 사용하였다는 오류가 발생함. (희한하네 ㅡㅡ;)
$sql = " select * from {$g5['board_file_table']} where bo_table = '$bo_table' ";
$result = sql_query($sql, false);
for ($i = 0; $row = sql_fetch_array($result); $i++) {
+5 -4
View File
@@ -914,7 +914,7 @@ $pg_anchor = '<ul class="anchor">
<tr>
<th scope="row"><label for="bo_include_head">상단 파일 경로</label></th>
<td>
<input type="text" name="bo_include_head" value="<?php echo $board['bo_include_head'] ?>" id="bo_include_head" class="frm_input" size="50">
<input type="text" name="bo_include_head" value="<?php echo get_sanitize_input($board['bo_include_head']); ?>" id="bo_include_head" class="frm_input" size="50">
</td>
<td class="td_grpset">
<input type="checkbox" name="chk_grp_include_head" value="1" id="chk_grp_include_head">
@@ -926,7 +926,7 @@ $pg_anchor = '<ul class="anchor">
<tr>
<th scope="row"><label for="bo_include_tail">하단 파일 경로</label></th>
<td>
<input type="text" name="bo_include_tail" value="<?php echo $board['bo_include_tail'] ?>" id="bo_include_tail" class="frm_input" size="50">
<input type="text" name="bo_include_tail" value="<?php echo get_sanitize_input($board['bo_include_tail']); ?>" id="bo_include_tail" class="frm_input" size="50">
</td>
<td class="td_grpset">
<input type="checkbox" name="chk_grp_include_tail" value="1" id="chk_grp_include_tail">
@@ -1423,9 +1423,10 @@ function use_captcha_check(){
});
}
var bo_include_head = jQuery.trim(jQuery("#bo_include_head").val()),
bo_include_tail = jQuery.trim(jQuery("#bo_include_tail").val());
function frm_check_file(){
var bo_include_head = "<?php echo $board['bo_include_head']; ?>";
var bo_include_tail = "<?php echo $board['bo_include_tail']; ?>";
var head = jQuery.trim(jQuery("#bo_include_head").val());
var tail = jQuery.trim(jQuery("#bo_include_tail").val());
+4
View File
@@ -161,6 +161,10 @@ $bo_comment_min = isset($_POST['bo_comment_min']) ? (int) $_POST['bo_comment_min
$bo_comment_max = isset($_POST['bo_comment_max']) ? (int) $_POST['bo_comment_max'] : 0;
$bo_sort_field = isset($_POST['bo_sort_field']) ? clean_xss_tags($_POST['bo_sort_field'], 1, 1) : '';
if (strpbrk($bo_skin.$bo_mobile_skin, "?%*:|\"<>") !== false) {
alert('스킨 디렉토리명 오류!');
}
$etcs = array();
for ($i = 1; $i <= 10; $i++) {
+10 -5
View File
@@ -8,6 +8,8 @@ if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
$copy_config = get_config(true);
if (!isset($config['cf_add_script'])) {
sql_query(
" ALTER TABLE `{$g5['config_table']}`
@@ -475,6 +477,9 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<td colspan="3">
<?php echo help('관리자가 보내고 받는 용도로 사용하는 메일 주소를 입력합니다. (회원가입, 인증메일, 테스트, 회원메일발송 등에서 사용)') ?>
<input type="text" name="cf_admin_email" value="<?php echo get_sanitize_input($config['cf_admin_email']); ?>" id="cf_admin_email" required class="required email frm_input" size="40">
<?php if (function_exists('domain_mail_host') && $config['cf_admin_email'] && stripos($config['cf_admin_email'], domain_mail_host()) === false) { ?>
<?php echo help('외부메일설정이나 기타 설정을 하지 않았다면, 도메인과 다른 헤더로 여겨 스팸이나 차단될 가능성이 있습니다.<br>name'.domain_mail_host().' 과 같은 도메인 형식으로 설정할것을 권장합니다.') ?>
<?php } ?>
</td>
</tr>
<tr>
@@ -693,15 +698,15 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<tr>
<th scope="row"><label for="cf_analytics">방문자분석 스크립트</label></th>
<td colspan="3">
<?php echo help('방문자분석 스크립트 코드를 입력합니다. 예) 구글 애널리틱스'); ?>
<textarea name="cf_analytics" id="cf_analytics"><?php echo get_text($config['cf_analytics']); ?></textarea>
<?php echo help('방문자분석 스크립트 코드를 입력합니다. 예) 구글 애널리틱스<br>관리자 페이지에서는 이 코드를 사용하지 않습니다.'); ?>
<textarea name="cf_analytics" id="cf_analytics"><?php echo get_text($copy_config['cf_analytics']); ?></textarea>
</td>
</tr>
<tr>
<th scope="row"><label for="cf_add_meta">추가 메타태그</label></th>
<td colspan="3">
<?php echo help('추가로 사용하실 meta 태그를 입력합니다.'); ?>
<textarea name="cf_add_meta" id="cf_add_meta"><?php echo get_text($config['cf_add_meta']); ?></textarea>
<?php echo help('추가로 사용하실 meta 태그를 입력합니다.<br>관리자 페이지에서는 이 코드를 사용하지 않습니다.'); ?>
<textarea name="cf_add_meta" id="cf_add_meta"><?php echo get_text($copy_config['cf_add_meta']); ?></textarea>
</td>
</tr>
<tr>
@@ -1387,7 +1392,7 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<th scope="row"><label for="cf_add_script">추가 script, css</label></th>
<td>
<?php echo help('HTML의 &lt;/HEAD&gt; 태그위로 추가될 JavaScript와 css 코드를 설정합니다.<br>관리자 페이지에서는 이 코드를 사용하지 않습니다.') ?>
<textarea name="cf_add_script" id="cf_add_script"><?php echo get_text($config['cf_add_script']); ?></textarea>
<textarea name="cf_add_script" id="cf_add_script"><?php echo get_text($copy_config['cf_add_script']); ?></textarea>
</td>
</tr>
</tbody>
+2 -2
View File
@@ -137,14 +137,14 @@ require_once G5_ADMIN_PATH . '/admin.head.php';
<th scope="row"><label for="co_include_head">상단 파일 경로</label></th>
<td>
<?php echo help("설정값이 없으면 기본 상단 파일을 사용합니다."); ?>
<input type="text" name="co_include_head" value="<?php echo $co['co_include_head']; ?>" id="co_include_head" class="frm_input" size="60">
<input type="text" name="co_include_head" value="<?php echo get_sanitize_input($co['co_include_head']); ?>" id="co_include_head" class="frm_input" size="60">
</td>
</tr>
<tr>
<th scope="row"><label for="co_include_tail">하단 파일 경로</label></th>
<td>
<?php echo help("설정값이 없으면 기본 하단 파일을 사용합니다."); ?>
<input type="text" name="co_include_tail" value="<?php echo $co['co_include_tail']; ?>" id="co_include_tail" class="frm_input" size="60">
<input type="text" name="co_include_tail" value="<?php echo get_sanitize_input($co['co_include_tail']); ?>" id="co_include_tail" class="frm_input" size="60">
</td>
</tr>
<tr id="admin_captcha_box" style="display:none;">
+3
View File
@@ -113,17 +113,20 @@ if ($w == "") {
set co_id = '$co_id',
$sql_common ";
sql_query($sql);
run_event('admin_content_created', $co_id);
} elseif ($w == "u") {
$sql = " update {$g5['content_table']}
set $sql_common
where co_id = '$co_id' ";
sql_query($sql);
run_event('admin_content_updated', $co_id);
} elseif ($w == "d") {
@unlink(G5_DATA_PATH . "/content/{$co_id}_h");
@unlink(G5_DATA_PATH . "/content/{$co_id}_t");
$sql = " delete from {$g5['content_table']} where co_id = '$co_id' ";
sql_query($sql);
run_event('admin_content_deleted', $co_id);
}
if (function_exists('get_admin_captcha_by')) {
+2 -15
View File
@@ -447,6 +447,7 @@ tfoot th {}
.td_delino {width:130px}
.td_device {width:70px;text-align:center}
.td_etc {width:80px;text-align:center}
.td_use {width:80px;text-align:center}
.td_extra label {display:inline-block;width:100px}
.td_extra input {margin-right:5px;width:130px}
.td_grid {width:60px;text-align:center}
@@ -876,20 +877,6 @@ strong.sodr_nonpay {display:block;padding:5px 0;text-align:right}
.sbn_img {text-align:center}
.sbn_image {display:none;margin:0 0 10px;text-align:left}
/* SMS문자전송 */
#sms_send {padding-bottom:100px;zoom:1}
#sms_send:after {display:block;visibility:hidden;clear:both;content:""}
#sms_frm {float:left;width:650px}
#sms_frm table {margin:0 0 30px}
#sms_frm textarea {height:70px}
#sms_sm {position:relative;float:left;width:229px;height:418px;background:url('../shop_admin/img/mobilebg.jpg') no-repeat}
#sms_sm_text {position:absolute;top:75px;left:27px;width:180px;color:#fff;font-size:2em;word-break:break-all}
#sms_sm p {position:absolute;bottom:-70px;left:0;font-size:0.95em;letter-spacing:-0.1em}
#sms_send .local_desc01 {min-width:320px}
/* 가격비교사이트 */
#anc_pricecompare_info li {margin:5px 0 5px -1px}
@@ -1075,7 +1062,7 @@ box-shadow: 1px 2px 5px rgba(150,150,150,0.5);z-index:1000}
#theme_detail:after{display:block;visibility:hidden;clear:both;content:""}
#theme_detail h2{font-size:1.25em;background:#fff;padding:0 15px;line-height:40px;border-bottom:1px solid #d8d8d8;margin:0}
.theme_dt_img{float:left;padding:20px}
.theme_dt_img img{border:1px solid #aaa;}
.theme_dt_img img{border:1px solid #aaa;max-width:600px;max-height:460px}
.theme_dt_if{float:left;width:235px;padding:20px 0}
.theme_dt_if table{width:100%;border-collapse:collapse;margin:15px 0 0 ;font-size:0.92em}
.theme_dt_if table th{padding:5px;background:#fff;border-bottom:1px solid #f3f3f3;vertical-align:top;color:#3f51b5}
+12
View File
@@ -207,6 +207,18 @@ if (defined('G5_USE_SHOP') && G5_USE_SHOP) {
}
}
// auth.au_menu 컬럼 크기 조정
$sql = " SHOW COLUMNS FROM `{$g5['auth_table']}` LIKE 'au_menu' ";
$row = sql_fetch($sql);
if (
stripos($row['Type'], 'varchar') !== false
&& (int) preg_replace('/[^0-9]/', '', $row['Type']) <= 50
) {
sql_query(" ALTER TABLE `{$g5['auth_table']}` CHANGE `au_menu` `au_menu` VARCHAR(50) NOT NULL; ", true);
$is_check = true;
}
$is_check = run_replace('admin_dbupgrade', $is_check);
$db_upgrade_msg = $is_check ? 'DB 업그레이드가 완료되었습니다.' : '더 이상 업그레이드 할 내용이 없습니다.<br>현재 DB 업그레이드가 완료된 상태입니다.';
+4
View File
@@ -30,6 +30,7 @@ if ($w == "")
sql_query($sql);
$fa_id = sql_insert_id();
run_event('admin_faq_item_created', $fa_id, $fm_id);
}
else if ($w == "u")
{
@@ -37,11 +38,14 @@ else if ($w == "u")
set $sql_common
where fa_id = '$fa_id' ";
sql_query($sql);
run_event('admin_faq_item_updated', $fa_id, $fm_id);
}
else if ($w == "d")
{
$sql = " delete from {$g5['faq_table']} where fa_id = '$fa_id' ";
sql_query($sql);
run_event('admin_faq_item_deleted', $fa_id, $fm_id);
}
if ($w == 'd')
+6
View File
@@ -49,9 +49,13 @@ if ($w == "") {
sql_query($sql);
$fm_id = sql_insert_id();
run_event('admin_faq_master_created', $fm_id);
} elseif ($w == "u") {
$sql = " update {$g5['faq_master_table']} $sql_common where fm_id = '$fm_id' ";
sql_query($sql);
run_event('admin_faq_master_updated', $fm_id);
} elseif ($w == "d") {
@unlink(G5_DATA_PATH . "/faq/{$fm_id}_h");
@unlink(G5_DATA_PATH . "/faq/{$fm_id}_t");
@@ -63,6 +67,8 @@ if ($w == "") {
// FAQ상세삭제
$sql = " delete from {$g5['faq_table']} where fm_id = '$fm_id' ";
sql_query($sql);
run_event('admin_faq_master_deleted', $fm_id);
}
if ($w == "" || $w == "u") {
+298 -277
View File
@@ -3,8 +3,10 @@ $sub_menu = '100000';
require_once './_common.php';
@require_once './safe_check.php';
if (function_exists('social_log_file_delete')) {
social_log_file_delete(86400); //소셜로그인 디버그 파일 24시간 지난것은 삭제
//소셜로그인 디버그 파일 24시간 지난것은 삭제
social_log_file_delete(86400);
}
$g5['title'] = '관리자메인';
@@ -14,304 +16,323 @@ $new_member_rows = 5;
$new_point_rows = 5;
$new_write_rows = 5;
$sql_common = " from {$g5['member_table']} ";
$sql_search = " where (1) ";
if ($is_admin != 'super') {
$sql_search .= " and mb_level <= '{$member['mb_level']}' ";
$addtional_content_before = run_replace('adm_index_addtional_content_before', '', $is_admin, $auth, $member);
if ($addtional_content_before) {
echo $addtional_content_before;
}
if (!$sst) {
$sst = "mb_datetime";
$sod = "desc";
}
if (!auth_check_menu($auth, '200100', 'r', true)) {
$sql_common = " from {$g5['member_table']} ";
$sql_order = " order by {$sst} {$sod} ";
$sql_search = " where (1) ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
// 탈퇴회원수
$sql = " select count(*) as cnt {$sql_common} {$sql_search} and mb_leave_date <> '' {$sql_order} ";
$row = sql_fetch($sql);
$leave_count = $row['cnt'];
// 차단회원수
$sql = " select count(*) as cnt {$sql_common} {$sql_search} and mb_intercept_date <> '' {$sql_order} ";
$row = sql_fetch($sql);
$intercept_count = $row['cnt'];
$sql = " select * {$sql_common} {$sql_search} {$sql_order} limit {$new_member_rows} ";
$result = sql_query($sql);
$colspan = 12;
?>
<section>
<h2>신규가입회원 <?php echo $new_member_rows ?>건 목록</h2>
<div class="local_desc02 local_desc">
총회원수 <?php echo number_format($total_count) ?>명 중 차단 <?php echo number_format($intercept_count) ?>명, 탈퇴 : <?php echo number_format($leave_count) ?>명
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>신규가입회원</caption>
<thead>
<tr>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">권한</th>
<th scope="col">포인트</th>
<th scope="col">수신</th>
<th scope="col">공개</th>
<th scope="col">인증</th>
<th scope="col">차단</th>
<th scope="col">그룹</th>
</tr>
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
// 접근가능한 그룹수
$sql2 = " select count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
$group = "";
if ($row2['cnt']) {
$group = '<a href="./boardgroupmember_form.php?mb_id=' . $row['mb_id'] . '">' . $row2['cnt'] . '</a>';
}
if ($is_admin == 'group') {
$s_mod = '';
$s_del = '';
} else {
$s_mod = '<a href="./member_form.php?$qstr&amp;w=u&amp;mb_id=' . $row['mb_id'] . '">수정</a>';
$s_del = '<a href="./member_delete.php?' . $qstr . '&amp;w=d&amp;mb_id=' . $row['mb_id'] . '&amp;url=' . $_SERVER['SCRIPT_NAME'] . '" onclick="return delete_confirm(this);">삭제</a>';
}
$s_grp = '<a href="./boardgroupmember_form.php?mb_id=' . $row['mb_id'] . '">그룹</a>';
$leave_date = $row['mb_leave_date'] ? $row['mb_leave_date'] : date("Ymd", G5_SERVER_TIME);
$intercept_date = $row['mb_intercept_date'] ? $row['mb_intercept_date'] : date("Ymd", G5_SERVER_TIME);
$mb_nick = get_sideview($row['mb_id'], get_text($row['mb_nick']), $row['mb_email'], $row['mb_homepage']);
$mb_id = $row['mb_id'];
?>
<tr>
<td class="td_mbid"><?php echo $mb_id ?></td>
<td class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td class="td_mbname sv_use">
<div><?php echo $mb_nick ?></div>
</td>
<td class="td_num"><?php echo $row['mb_level'] ?></td>
<td><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo number_format($row['mb_point']) ?></a></td>
<td class="td_boolean"><?php echo $row['mb_mailling'] ? '예' : '아니오'; ?></td>
<td class="td_boolean"><?php echo $row['mb_open'] ? '예' : '아니오'; ?></td>
<td class="td_boolean"><?php echo preg_match('/[1-9]/', $row['mb_email_certify']) ? '예' : '아니오'; ?></td>
<td class="td_boolean"><?php echo $row['mb_intercept_date'] ? '예' : '아니오'; ?></td>
<td class="td_category"><?php echo $group ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="./member_list.php">회원 전체보기</a>
</div>
</section>
<?php
$sql_common = " from {$g5['board_new_table']} a, {$g5['board_table']} b, {$g5['group_table']} c where a.bo_table = b.bo_table and b.gr_id = c.gr_id ";
if ($gr_id) {
$sql_common .= " and b.gr_id = '$gr_id' ";
}
if (isset($view) && $view) {
if ($view == 'w') {
$sql_common .= " and a.wr_id = a.wr_parent ";
} elseif ($view == 'c') {
$sql_common .= " and a.wr_id <> a.wr_parent ";
if ($is_admin != 'super') {
$sql_search .= " and mb_level <= '{$member['mb_level']}' ";
}
}
$sql_order = " order by a.bn_id desc ";
$sql = " select count(*) as cnt {$sql_common} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
if (!$sst) {
$sst = "mb_datetime";
$sod = "desc";
}
$colspan = 5;
?>
$sql_order = " order by {$sst} {$sod} ";
<section>
<h2>최근게시물</h2>
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
<div class="tbl_head01 tbl_wrap">
<table>
<caption>최근게시물</caption>
<thead>
<tr>
<th scope="col">그룹</th>
<th scope="col">게시판</th>
<th scope="col">제목</th>
<th scope="col">이름</th>
<th scope="col">일시</th>
</tr>
</thead>
<tbody>
<?php
$sql = " select a.*, b.bo_subject, c.gr_subject, c.gr_id {$sql_common} {$sql_order} limit {$new_write_rows} ";
$result = sql_query($sql);
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$tmp_write_table = $g5['write_prefix'] . $row['bo_table'];
// 탈퇴회원수
$sql = " select count(*) as cnt {$sql_common} {$sql_search} and mb_leave_date <> '' {$sql_order} ";
$row = sql_fetch($sql);
$leave_count = $row['cnt'];
// 원글
if ($row['wr_id'] == $row['wr_parent']) {
$comment = "";
$comment_link = "";
$row2 = sql_fetch(" select * from $tmp_write_table where wr_id = '{$row['wr_id']}' ");
// 차단회원수
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} and mb_intercept_date <> '' {$sql_order} ";
$row = sql_fetch($sql);
$intercept_count = $row['cnt'];
$name = get_sideview($row2['mb_id'], get_text(cut_str($row2['wr_name'], $config['cf_cut_name'])), $row2['wr_email'], $row2['wr_homepage']);
// 당일인 경우 시간으로 표시함
$datetime = substr($row2['wr_datetime'], 0, 10);
$datetime2 = $row2['wr_datetime'];
if ($datetime == G5_TIME_YMD) {
$datetime2 = substr($datetime2, 11, 5);
} else {
$datetime2 = substr($datetime2, 5, 5);
}
} else // 코멘트
{
$comment = '댓글. ';
$comment_link = '#c_' . $row['wr_id'];
$row2 = sql_fetch(" select * from {$tmp_write_table} where wr_id = '{$row['wr_parent']}' ");
$row3 = sql_fetch(" select mb_id, wr_name, wr_email, wr_homepage, wr_datetime from {$tmp_write_table} where wr_id = '{$row['wr_id']}' ");
$sql = " SELECT * {$sql_common} {$sql_search} {$sql_order} limit {$new_member_rows} ";
$result = sql_query($sql);
$name = get_sideview($row3['mb_id'], get_text(cut_str($row3['wr_name'], $config['cf_cut_name'])), $row3['wr_email'], $row3['wr_homepage']);
// 당일인 경우 시간으로 표시함
$datetime = substr($row3['wr_datetime'], 0, 10);
$datetime2 = $row3['wr_datetime'];
if ($datetime == G5_TIME_YMD) {
$datetime2 = substr($datetime2, 11, 5);
} else {
$datetime2 = substr($datetime2, 5, 5);
}
}
?>
$colspan = 12;
?>
<section>
<h2>신규가입회원 <?php echo $new_member_rows ?>건 목록</h2>
<div class="local_desc02 local_desc">
총회원수 <?php echo number_format($total_count) ?>명 중 차단 <?php echo number_format($intercept_count) ?>명, 탈퇴 : <?php echo number_format($leave_count) ?>명
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>신규가입회원</caption>
<thead>
<tr>
<td class="td_category"><a href="<?php echo G5_BBS_URL ?>/new.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo cut_str($row['gr_subject'], 10) ?></a></td>
<td class="td_category"><a href="<?php echo get_pretty_url($row['bo_table']) ?>"><?php echo cut_str($row['bo_subject'], 20) ?></a></td>
<td><a href="<?php echo get_pretty_url($row['bo_table'], $row2['wr_id']); ?><?php echo $comment_link ?>"><?php echo $comment ?><?php echo conv_subject($row2['wr_subject'], 100) ?></a></td>
<td class="td_mbname">
<div><?php echo $name ?></div>
</td>
<td class="td_datetime"><?php echo $datetime ?></td>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">권한</th>
<th scope="col">포인트</th>
<th scope="col">수신</th>
<th scope="col">공개</th>
<th scope="col">인증</th>
<th scope="col">차단</th>
<th scope="col">그룹</th>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="<?php echo G5_BBS_URL ?>/new.php">최근게시물 더보기</a>
</div>
</section>
<?php
$sql_common = " from {$g5['point_table']} ";
$sql_search = " where (1) ";
$sql_order = " order by po_id desc ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql = " select * {$sql_common} {$sql_search} {$sql_order} limit {$new_point_rows} ";
$result = sql_query($sql);
$colspan = 7;
?>
<section>
<h2>최근 포인트 발생내역</h2>
<div class="local_desc02 local_desc">
전체 <?php echo number_format($total_count) ?> 건 중 <?php echo $new_point_rows ?>건 목록
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>최근 포인트 발생내역</caption>
<thead>
<tr>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">일시</th>
<th scope="col">포인트 내용</th>
<th scope="col">포인트</th>
<th scope="col">포인트합</th>
</tr>
</thead>
<tbody>
<?php
$row2['mb_id'] = '';
for ($i = 0; $row = sql_fetch_array($result); $i++) {
if ($row2['mb_id'] != $row['mb_id']) {
$sql2 = " select mb_id, mb_name, mb_nick, mb_email, mb_homepage, mb_point from {$g5['member_table']} where mb_id = '{$row['mb_id']}' ";
</thead>
<tbody>
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
// 접근가능한 그룹수
$sql2 = " SELECT count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
$group = "";
if ($row2['cnt']) {
$group = '<a href="./boardgroupmember_form.php?mb_id=' . $row['mb_id'] . '">' . $row2['cnt'] . '</a>';
}
if ($is_admin == 'group') {
$s_mod = '';
$s_del = '';
} else {
$s_mod = '<a href="./member_form.php?$qstr&amp;w=u&amp;mb_id=' . $row['mb_id'] . '">수정</a>';
$s_del = '<a href="./member_delete.php?' . $qstr . '&amp;w=d&amp;mb_id=' . $row['mb_id'] . '&amp;url=' . $_SERVER['SCRIPT_NAME'] . '" onclick="return delete_confirm(this);">삭제</a>';
}
$s_grp = '<a href="./boardgroupmember_form.php?mb_id=' . $row['mb_id'] . '">그룹</a>';
$leave_date = $row['mb_leave_date'] ? $row['mb_leave_date'] : date("Ymd", G5_SERVER_TIME);
$intercept_date = $row['mb_intercept_date'] ? $row['mb_intercept_date'] : date("Ymd", G5_SERVER_TIME);
$mb_nick = get_sideview($row['mb_id'], get_text($row['mb_nick']), $row['mb_email'], $row['mb_homepage']);
$mb_id = $row['mb_id'];
?>
<tr>
<td class="td_mbid"><?php echo $mb_id ?></td>
<td class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
<td class="td_mbname sv_use">
<div><?php echo $mb_nick ?></div>
</td>
<td class="td_num"><?php echo $row['mb_level'] ?></td>
<td><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo number_format($row['mb_point']) ?></a></td>
<td class="td_boolean"><?php echo $row['mb_mailling'] ? '예' : '아니오'; ?></td>
<td class="td_boolean"><?php echo $row['mb_open'] ? '예' : '아니오'; ?></td>
<td class="td_boolean"><?php echo preg_match('/[1-9]/', $row['mb_email_certify']) ? '예' : '아니오'; ?></td>
<td class="td_boolean"><?php echo $row['mb_intercept_date'] ? '예' : '아니오'; ?></td>
<td class="td_category"><?php echo $group ?></td>
</tr>
<?php
}
$mb_nick = get_sideview($row['mb_id'], $row2['mb_nick'], $row2['mb_email'], $row2['mb_homepage']);
$link1 = $link2 = "";
if (!preg_match("/^\@/", $row['po_rel_table']) && $row['po_rel_table']) {
$link1 = '<a href="' . get_pretty_url($row['po_rel_table'], $row['po_rel_id']) . '" target="_blank">';
$link2 = '</a>';
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="./member_list.php">회원 전체보기</a>
</div>
</section>
<?php
} //endif 최신 회원
if (!auth_check_menu($auth, '300100', 'r', true)) {
$sql_common = " from {$g5['board_new_table']} a, {$g5['board_table']} b, {$g5['group_table']} c where a.bo_table = b.bo_table and b.gr_id = c.gr_id ";
if ($gr_id) {
$sql_common .= " and b.gr_id = '{$gr_id}' ";
}
if (isset($view) && $view) {
if ($view == 'w') {
$sql_common .= " and a.wr_id = a.wr_parent ";
} elseif ($view == 'c') {
$sql_common .= " and a.wr_id <> a.wr_parent ";
}
}
$sql_order = " order by a.bn_id desc ";
$sql = " SELECT count(*) as cnt {$sql_common} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$colspan = 5;
?>
<section>
<h2>최근게시물</h2>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>최근게시물</caption>
<thead>
<tr>
<td class="td_mbid"><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
<td class="td_mbname"><?php echo get_text($row2['mb_name']); ?></td>
<td class="td_name sv_use">
<div><?php echo $mb_nick ?></div>
</td>
<td class="td_datetime"><?php echo $row['po_datetime'] ?></td>
<td><?php echo $link1 . $row['po_content'] . $link2 ?></td>
<td class="td_numbig"><?php echo number_format($row['po_point']) ?></td>
<td class="td_numbig"><?php echo number_format($row['po_mb_point']) ?></td>
<th scope="col">그룹</th>
<th scope="col">게시판</th>
<th scope="col">제목</th>
<th scope="col">이름</th>
<th scope="col">일시</th>
</tr>
</thead>
<tbody>
<?php
$sql = " SELECT a.*, b.bo_subject, c.gr_subject, c.gr_id {$sql_common} {$sql_order} limit {$new_write_rows} ";
$result = sql_query($sql);
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$tmp_write_table = $g5['write_prefix'] . $row['bo_table'];
<?php
}
if ($row['wr_id'] == $row['wr_parent']) {
// 원글
$comment = "";
$comment_link = "";
$row2 = sql_fetch(" SELECT * from {$tmp_write_table} where wr_id = '{$row['wr_id']}' ");
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
$name = get_sideview($row2['mb_id'], get_text(cut_str($row2['wr_name'], $config['cf_cut_name'])), $row2['wr_email'], $row2['wr_homepage']);
// 당일인 경우 시간으로 표시함
$datetime = substr($row2['wr_datetime'], 0, 10);
$datetime2 = $row2['wr_datetime'];
if ($datetime == G5_TIME_YMD) {
$datetime2 = substr($datetime2, 11, 5);
} else {
$datetime2 = substr($datetime2, 5, 5);
}
} else {
// 코멘트
$comment = '댓글. ';
$comment_link = '#c_' . $row['wr_id'];
$row2 = sql_fetch(" SELECT * from {$tmp_write_table} where wr_id = '{$row['wr_parent']}' ");
$row3 = sql_fetch(" SELECT mb_id, wr_name, wr_email, wr_homepage, wr_datetime from {$tmp_write_table} where wr_id = '{$row['wr_id']}' ");
<div class="btn_list03 btn_list">
<a href="./point_list.php">포인트내역 전체보기</a>
</div>
</section>
$name = get_sideview($row3['mb_id'], get_text(cut_str($row3['wr_name'], $config['cf_cut_name'])), $row3['wr_email'], $row3['wr_homepage']);
// 당일인 경우 시간으로 표시함
$datetime = substr($row3['wr_datetime'], 0, 10);
$datetime2 = $row3['wr_datetime'];
if ($datetime == G5_TIME_YMD) {
$datetime2 = substr($datetime2, 11, 5);
} else {
$datetime2 = substr($datetime2, 5, 5);
}
}
?>
<?php
require_once './admin.tail.php';
<tr>
<td class="td_category"><a href="<?php echo G5_BBS_URL ?>/new.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo cut_str($row['gr_subject'], 10) ?></a></td>
<td class="td_category"><a href="<?php echo get_pretty_url($row['bo_table']) ?>"><?php echo cut_str($row['bo_subject'], 20) ?></a></td>
<td><a href="<?php echo get_pretty_url($row['bo_table'], $row2['wr_id']); ?><?php echo $comment_link ?>"><?php echo $comment ?><?php echo conv_subject($row2['wr_subject'], 100) ?></a></td>
<td class="td_mbname">
<div><?php echo $name ?></div>
</td>
<td class="td_datetime"><?php echo $datetime ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="<?php echo G5_BBS_URL ?>/new.php">최근게시물 더보기</a>
</div>
</section>
<?php
} //endif 최근게시물
if (!auth_check_menu($auth, '200200', 'r', true)) {
$sql_common = " from {$g5['point_table']} ";
$sql_search = " where (1) ";
$sql_order = " order by po_id desc ";
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql = " SELECT * {$sql_common} {$sql_search} {$sql_order} limit {$new_point_rows} ";
$result = sql_query($sql);
$colspan = 7;
?>
<section>
<h2>최근 포인트 발생내역</h2>
<div class="local_desc02 local_desc">
전체 <?php echo number_format($total_count) ?> 건 중 <?php echo $new_point_rows ?>건 목록
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>최근 포인트 발생내역</caption>
<thead>
<tr>
<th scope="col">회원아이디</th>
<th scope="col">이름</th>
<th scope="col">닉네임</th>
<th scope="col">일시</th>
<th scope="col">포인트 내용</th>
<th scope="col">포인트</th>
<th scope="col">포인트합</th>
</tr>
</thead>
<tbody>
<?php
$row2['mb_id'] = '';
for ($i = 0; $row = sql_fetch_array($result); $i++) {
if ($row2['mb_id'] != $row['mb_id']) {
$sql2 = " SELECT mb_id, mb_name, mb_nick, mb_email, mb_homepage, mb_point from {$g5['member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
}
$mb_nick = get_sideview($row['mb_id'], $row2['mb_nick'], $row2['mb_email'], $row2['mb_homepage']);
$link1 = $link2 = "";
if (!preg_match("/^\@/", $row['po_rel_table']) && $row['po_rel_table']) {
$link1 = '<a href="' . get_pretty_url($row['po_rel_table'], $row['po_rel_id']) . '" target="_blank">';
$link2 = '</a>';
}
?>
<tr>
<td class="td_mbid"><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
<td class="td_mbname"><?php echo get_text($row2['mb_name']); ?></td>
<td class="td_name sv_use">
<div><?php echo $mb_nick ?></div>
</td>
<td class="td_datetime"><?php echo $row['po_datetime'] ?></td>
<td><?php echo $link1 . $row['po_content'] . $link2 ?></td>
<td class="td_numbig"><?php echo number_format($row['po_point']) ?></td>
<td class="td_numbig"><?php echo number_format($row['po_mb_point']) ?></td>
</tr>
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
}
?>
</tbody>
</table>
</div>
<div class="btn_list03 btn_list">
<a href="./point_list.php">포인트내역 전체보기</a>
</div>
</section>
<?php
} //endif
$addtional_content_after = run_replace('adm_index_addtional_content_after', '', $is_admin, $auth, $member);
if ($addtional_content_after) {
echo $addtional_content_after;
}
require_once './admin.tail.php';
+1
View File
@@ -19,6 +19,7 @@ for ($i = 0; $i < $post_count_chk; $i++) {
$sql = " delete from {$g5['mail_table']} where ma_id = '$ma_id' ";
sql_query($sql);
run_event('admin_mail_deleted', $ma_id);
}
goto_url('./mail_list.php');
+7 -5
View File
@@ -4,18 +4,20 @@ require_once './_common.php';
auth_check_menu($auth, $sub_menu, 'r');
$ma_id = isset($_REQUEST['ma_id']) ? (int) $_REQUEST['ma_id'] : 0;
$ma_last_option = "";
$sql_common = " from {$g5['member_table']} ";
$sql_where = " where (1) ";
$mb_id1 = isset($_POST['mb_id1']) ? $_POST['mb_id1'] : 1;
$mb_id1 = isset($_POST['mb_id1']) ? (int) $_POST['mb_id1'] : 1;
$mb_id1_from = isset($_POST['mb_id1_from']) ? clean_xss_tags($_POST['mb_id1_from'], 1, 1, 30) : '';
$mb_id1_to = isset($_POST['mb_id1_to']) ? clean_xss_tags($_POST['mb_id1_to'], 1, 1, 30) : '';
$mb_email = isset($_POST['mb_email']) ? clean_xss_tags($_POST['mb_email'], 1, 1, 100) : '';
$mb_mailling = isset($_POST['mb_mailling']) ? clean_xss_tags($_POST['mb_mailling'], 1, 1, 100) : '';
$mb_level_from = isset($_POST['mb_level_from'])? $_POST['mb_level_from'] : 1;
$mb_level_to = isset($_POST['mb_level_to']) ? $_POST['mb_level_to'] : 10;
$mb_level_from = isset($_POST['mb_level_from'])? (int) $_POST['mb_level_from'] : 1;
$mb_level_to = isset($_POST['mb_level_to']) ? (int) $_POST['mb_level_to'] : 10;
// 회원ID ..에서 ..까지
if ($mb_id1 != 1) {
@@ -81,7 +83,7 @@ require_once './admin.head.php';
<form name="fmailselectlist" id="fmailselectlist" method="post" action="./mail_select_update.php">
<input type="hidden" name="token" value="">
<input type="hidden" name="ma_id" value="<?php echo $ma_id ?>">
<input type="hidden" name="ma_id" value="<?php echo get_text($ma_id); ?>">
<div class="tbl_head01 tbl_wrap">
<table>
@@ -119,7 +121,7 @@ require_once './admin.head.php';
<?php } ?>
</tbody>
</table>
<textarea name="ma_list" style="display:none"><?php echo $ma_list ?></textarea>
<textarea name="ma_list" style="display:none"><?php echo html_purifier($ma_list); ?></textarea>
</div>
<div class="btn_confirm01 btn_confirm">
+7
View File
@@ -21,6 +21,10 @@ if ($w == '') {
ma_time = '" . G5_TIME_YMDHIS . "',
ma_ip = '{$_SERVER['REMOTE_ADDR']}' ";
sql_query($sql);
$ma_id = sql_insert_id();
run_event('admin_mail_created', $ma_id);
} elseif ($w == 'u') {
$sql = " update {$g5['mail_table']}
set ma_subject = '{$ma_subject}',
@@ -29,9 +33,12 @@ if ($w == '') {
ma_ip = '{$_SERVER['REMOTE_ADDR']}'
where ma_id = '{$ma_id}' ";
sql_query($sql);
run_event('admin_mail_updated', $ma_id);
} elseif ($w == 'd') {
$sql = " delete from {$g5['mail_table']} where ma_id = '{$ma_id}' ";
sql_query($sql);
run_event('admin_mail_deleted', $ma_id);
}
goto_url('./mail_list.php');
+43 -4
View File
@@ -240,7 +240,19 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<?php if ($w == 'u') { ?><a href="./boardgroupmember_form.php?mb_id=<?php echo $mb['mb_id'] ?>" class="btn_frmline">접근가능그룹보기</a><?php } ?>
</td>
<th scope="row"><label for="mb_password">비밀번호<?php echo $sound_only ?></label></th>
<td><input type="password" name="mb_password" id="mb_password" <?php echo $required_mb_password ?> class="frm_input <?php echo $required_mb_password ?>" size="15" maxlength="20"></td>
<td>
<div>
<input type="password" name="mb_password" id="mb_password" <?php echo $required_mb_password ?> class="frm_input <?php echo $required_mb_password ?>" size="15" maxlength="20">
</div>
<div id="mb_password_captcha_wrap" style="display:none">
<?php
require_once G5_CAPTCHA_PATH . '/captcha.lib.php';
$captcha_html = captcha_html();
$captcha_js = chk_captcha_js();
echo $captcha_html;
?>
</div>
</td>
</tr>
<tr>
<th scope="row"><label for="mb_name">이름(실명)<strong class="sound_only">필수</strong></label></th>
@@ -368,15 +380,15 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
</tr>
<tr>
<th scope="row"><label for="mb_signature">서명</label></th>
<td colspan="3"><textarea name="mb_signature" id="mb_signature"><?php echo $mb['mb_signature'] ?></textarea></td>
<td colspan="3"><textarea name="mb_signature" id="mb_signature"><?php echo html_purifier($mb['mb_signature']); ?></textarea></td>
</tr>
<tr>
<th scope="row"><label for="mb_profile">자기 소개</label></th>
<td colspan="3"><textarea name="mb_profile" id="mb_profile"><?php echo $mb['mb_profile'] ?></textarea></td>
<td colspan="3"><textarea name="mb_profile" id="mb_profile"><?php echo html_purifier($mb['mb_profile']); ?></textarea></td>
</tr>
<tr>
<th scope="row"><label for="mb_memo">메모</label></th>
<td colspan="3"><textarea name="mb_memo" id="mb_memo"><?php echo $mb['mb_memo'] ?></textarea></td>
<td colspan="3"><textarea name="mb_memo" id="mb_memo"><?php echo html_purifier($mb['mb_memo']); ?></textarea></td>
</tr>
<tr>
<th scope="row"><label for="mb_cert_history">본인인증 내역</label></th>
@@ -582,8 +594,35 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
return false;
}
if( jQuery("#mb_password").val() ){
<?php echo $captcha_js; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
}
return true;
}
jQuery(function($){
$("#captcha_key").prop('required', false).removeAttr("required").removeClass("required");
$("#mb_password").on("keyup", function(e) {
var $warp = $("#mb_password_captcha_wrap"),
tooptipid = "mp_captcha_tooltip",
$span_text = $("<span>", {id:tooptipid, style:"font-size:0.95em;letter-spacing:-0.1em"}).html("비밀번호를 수정할 경우 캡챠를 입력해야 합니다."),
$parent = $(this).parent(),
is_invisible_recaptcha = $("#captcha").hasClass("invisible_recaptcha");
if($(this).val()){
$warp.show();
if(! is_invisible_recaptcha) {
$warp.css("margin-top","1em");
if(! $("#"+tooptipid).length){ $parent.append($span_text) }
}
} else {
$warp.hide();
if($("#"+tooptipid).length && ! is_invisible_recaptcha){ $parent.find("#"+tooptipid).remove(); }
}
});
});
</script>
<?php
run_event('admin_member_form_after', $mb, $w);
+20 -1
View File
@@ -18,6 +18,15 @@ $mb_certify_case = isset($_POST['mb_certify_case']) ? preg_replace('/[^0-9a-z_]/
$mb_certify = isset($_POST['mb_certify']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_certify']) : '';
$mb_zip = isset($_POST['mb_zip']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_zip']) : '';
// 관리자가 자동등록방지를 사용해야 할 경우 ( 회원의 비밀번호 변경시 캡챠를 체크한다 )
if ($mb_password && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
}
// 휴대폰번호 체크
$mb_hp = hyphen_hp_number($_POST['mb_hp']);
if ($mb_hp) {
@@ -149,7 +158,13 @@ if ($w == '') {
}
if ($mb_id === $member['mb_id'] && $_POST['mb_level'] != $mb['mb_level']) {
alert($mb['mb_id'] . ' : 로그인 중인 관리자 레벨은 수정 할 수 없습니다.');
alert($mb['mb_id'] . ' : 로그인 중인 관리자 레벨은 수정할 수 없습니다.');
}
if ($posts['mb_leave_date'] || $posts['mb_intercept_date']){
if ($member['mb_id'] === $mb['mb_id'] || is_admin($mb['mb_id']) === 'super'){
alert('해당 관리자의 탈퇴 일자 또는 접근 차단 일자를 수정할 수 없습니다.');
}
}
// 닉네임중복체크
@@ -289,6 +304,10 @@ if ($w == '' || $w == 'u') {
}
}
if (function_exists('get_admin_captcha_by')) {
get_admin_captcha_by('remove');
}
run_event('admin_member_form_update', $w, $mb_id);
goto_url('./member_form.php?' . $qstr . '&amp;w=u&amp;mb_id=' . $mb_id, false);
+3 -1
View File
@@ -59,14 +59,16 @@ $sql_common = " nw_device = '{$posts['nw_device']}',
if ($w == "") {
$sql = " insert {$g5['new_win_table']} set $sql_common ";
sql_query($sql);
$nw_id = sql_insert_id();
run_event('admin_newwin_created', $nw_id);
} elseif ($w == "u") {
$sql = " update {$g5['new_win_table']} set $sql_common where nw_id = '$nw_id' ";
sql_query($sql);
run_event('admin_newwin_updated', $nw_id);
} elseif ($w == "d") {
$sql = " delete from {$g5['new_win_table']} where nw_id = '$nw_id' ";
sql_query($sql);
run_event('admin_newwin_deleted', $nw_id);
}
if ($w == "d") {
+10 -2
View File
@@ -23,6 +23,10 @@ if ($w == '') {
alert('w 값이 제대로 넘어오지 않았습니다.');
}
if (!isset($po['po_use'])) {
sql_query(" alter table `{$g5['poll_table']}` add `po_use` tinyint not null default '0' after `mb_ids` ", false);
}
$g5['title'] = $html_title;
require_once './admin.head.php';
?>
@@ -94,17 +98,21 @@ require_once './admin.head.php';
</tr>
<?php if ($w == 'u') { ?>
<tr>
<th scope="row">투표사용</th>
<td><input type="checkbox" name="po_use" id="po_use" value="1" <?php if ($po['po_use']) { echo 'checked="checked"'; } ?>> <label for="po_use">사용</label></td>
</tr>
<tr>
<th scope="row">투표등록일</th>
<td><?php echo $po['po_date']; ?></td>
</tr>
<tr>
<th scope="row"><label for="po_ips">투표참가 IP</label></th>
<td><textarea name="po_ips" id="po_ips" readonly rows="10"><?php echo preg_replace("/\n/", " / ", $po['po_ips']) ?></textarea></td>
<td><textarea name="po_ips" id="po_ips" readonly rows="10"><?php echo html_purifier(preg_replace("/\n/", " / ", $po['po_ips'])); ?></textarea></td>
</tr>
<tr>
<th scope="row"><label for="mb_ids">투표참가 회원</label></th>
<td><textarea name="mb_ids" id="mb_ids" readonly rows="10"><?php echo preg_replace("/\n/", " / ", $po['mb_ids']) ?></textarea></td>
<td><textarea name="mb_ids" id="mb_ids" readonly rows="10"><?php echo html_purifier(preg_replace("/\n/", " / ", $po['mb_ids'])); ?></textarea></td>
</tr>
<?php } ?>
</tbody>
+4 -3
View File
@@ -51,8 +51,8 @@ $po_id = isset($_POST['po_id']) ? $_POST['po_id'] : '';
if ($w == '') {
$sql = " insert {$g5['poll_table']}
( po_subject, po_poll1, po_poll2, po_poll3, po_poll4, po_poll5, po_poll6, po_poll7, po_poll8, po_poll9, po_cnt1, po_cnt2, po_cnt3, po_cnt4, po_cnt5, po_cnt6, po_cnt7, po_cnt8, po_cnt9, po_etc, po_level, po_point, po_date )
values ( '{$_POST['po_subject']}', '{$_POST['po_poll1']}', '{$_POST['po_poll2']}', '{$_POST['po_poll3']}', '{$_POST['po_poll4']}', '{$_POST['po_poll5']}', '{$_POST['po_poll6']}', '{$_POST['po_poll7']}', '{$_POST['po_poll8']}', '{$_POST['po_poll9']}', '{$_POST['po_cnt1']}', '{$_POST['po_cnt2']}', '{$_POST['po_cnt3']}', '{$_POST['po_cnt4']}', '{$_POST['po_cnt5']}', '{$_POST['po_cnt6']}', '{$_POST['po_cnt7']}', '{$_POST['po_cnt8']}', '{$_POST['po_cnt9']}', '{$_POST['po_etc']}', '{$_POST['po_level']}', '{$_POST['po_point']}', '" . G5_TIME_YMD . "' ) ";
( po_subject, po_poll1, po_poll2, po_poll3, po_poll4, po_poll5, po_poll6, po_poll7, po_poll8, po_poll9, po_cnt1, po_cnt2, po_cnt3, po_cnt4, po_cnt5, po_cnt6, po_cnt7, po_cnt8, po_cnt9, po_etc, po_level, po_point, po_date, po_use )
values ( '{$_POST['po_subject']}', '{$_POST['po_poll1']}', '{$_POST['po_poll2']}', '{$_POST['po_poll3']}', '{$_POST['po_poll4']}', '{$_POST['po_poll5']}', '{$_POST['po_poll6']}', '{$_POST['po_poll7']}', '{$_POST['po_poll8']}', '{$_POST['po_poll9']}', '{$_POST['po_cnt1']}', '{$_POST['po_cnt2']}', '{$_POST['po_cnt3']}', '{$_POST['po_cnt4']}', '{$_POST['po_cnt5']}', '{$_POST['po_cnt6']}', '{$_POST['po_cnt7']}', '{$_POST['po_cnt8']}', '{$_POST['po_cnt9']}', '{$_POST['po_etc']}', '{$_POST['po_level']}', '{$_POST['po_point']}', '" . G5_TIME_YMD . "', 1 ) ";
sql_query($sql);
$po_id = sql_insert_id();
@@ -79,7 +79,8 @@ if ($w == '') {
po_cnt9 = '{$_POST['po_cnt9']}',
po_etc = '{$_POST['po_etc']}',
po_level = '{$_POST['po_level']}',
po_point = '{$_POST['po_point']}'
po_point = '{$_POST['po_point']}',
po_use = '{$_POST['po_use']}'
where po_id = '{$_POST['po_id']}' ";
sql_query($sql);
} elseif ($w == 'd') {
+4 -1
View File
@@ -49,7 +49,7 @@ $listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall">전체
$g5['title'] = '투표관리';
require_once './admin.head.php';
$colspan = 7;
$colspan = 8;
?>
<div class="local_ov01 local_ov">
@@ -92,6 +92,7 @@ $colspan = 7;
<th scope="col">투표권한</th>
<th scope="col">투표수</th>
<th scope="col">기타의견</th>
<th scope="col">사용</th>
<th scope="col">관리</th>
</tr>
</thead>
@@ -101,6 +102,7 @@ $colspan = 7;
$sql2 = " select sum(po_cnt1+po_cnt2+po_cnt3+po_cnt4+po_cnt5+po_cnt6+po_cnt7+po_cnt8+po_cnt9) as sum_po_cnt from {$g5['poll_table']} where po_id = '{$row['po_id']}' ";
$row2 = sql_fetch($sql2);
$po_etc = ($row['po_etc']) ? "사용" : "미사용";
$po_use = ($row['po_use']) ? "사용" : "미사용";
$s_mod = '<a href="./poll_form.php?' . $qstr . '&amp;w=u&amp;po_id=' . $row['po_id'] . '" class="btn btn_03">수정</a>';
@@ -117,6 +119,7 @@ $colspan = 7;
<td class="td_num"><?php echo $row['po_level'] ?></td>
<td class="td_num"><?php echo $row2['sum_po_cnt'] ?></td>
<td class="td_etc"><?php echo $po_etc ?></td>
<td class="td_use"><?php echo $po_use ?></td>
<td class="td_mng td_mng_s"><?php echo $s_mod ?></td>
</tr>
+5 -5
View File
@@ -266,13 +266,13 @@ if (!isset($qaconfig['qa_include_head'])) {
<tr>
<th scope="row"><label for="qa_include_head">상단 파일 경로</label></th>
<td>
<input type="text" name="qa_include_head" value="<?php echo $qaconfig['qa_include_head'] ?>" id="qa_include_head" class="frm_input" size="50">
<input type="text" name="qa_include_head" value="<?php echo get_sanitize_input($qaconfig['qa_include_head']); ?>" id="qa_include_head" class="frm_input" size="50">
</td>
</tr>
<tr>
<th scope="row"><label for="qa_include_tail">하단 파일 경로</label></th>
<td>
<input type="text" name="qa_include_tail" value="<?php echo $qaconfig['qa_include_tail'] ?>" id="qa_include_tail" class="frm_input" size="50">
<input type="text" name="qa_include_tail" value="<?php echo get_sanitize_input($qaconfig['qa_include_tail']); ?>" id="qa_include_tail" class="frm_input" size="50">
</td>
</tr>
<tr id="admin_captcha_box" style="display:none;">
@@ -344,7 +344,9 @@ if (!isset($qaconfig['qa_include_head'])) {
</form>
<script>
var captcha_chk = false;
var captcha_chk = false,
qa_include_head = jQuery.trim(jQuery("#qa_include_head").val()),
qa_include_tail = jQuery.trim(jQuery("#qa_include_tail").val());
function use_captcha_check() {
$.ajax({
@@ -361,8 +363,6 @@ if (!isset($qaconfig['qa_include_head'])) {
}
function frm_check_file() {
var qa_include_head = "<?php echo $qaconfig['qa_include_head']; ?>";
var qa_include_tail = "<?php echo $qaconfig['qa_include_tail']; ?>";
var head = jQuery.trim(jQuery("#qa_include_head").val());
var tail = jQuery.trim(jQuery("#qa_include_tail").val());
+2
View File
@@ -108,6 +108,8 @@ $sql = " update {$g5['qa_config_table']}
qa_5 = '{$_POST['qa_5']}' ";
sql_query($sql);
run_event('admin_qa_config_updated');
if (function_exists('get_admin_captcha_by')) {
get_admin_captcha_by('remove');
}
+5
View File
@@ -41,6 +41,7 @@ if (isset($_POST['email'])) {
echo '해당 주소로 테스트 메일이 도착했는지 확인해 주십시오.<br>';
echo '만약, 테스트 메일이 오지 않는다면 더 다양한 계정의 메일 주소로 메일을 보내 보십시오.<br>';
echo '그래도 메일이 하나도 도착하지 않는다면 메일 서버(sendmail server)의 오류일 가능성이 높으니, 웹 서버관리자에게 문의하여 주십시오.<br>';
echo '도메인을 소유하고 있을시 SPF, DKIM 설정이 필요할수 있습니다.<br>';
echo '</p></div>';
echo '</section>';
}
@@ -53,6 +54,10 @@ if (isset($_POST['email'])) {
<p>
메일서버가 정상적으로 동작 중인지 확인할 수 있습니다.<br>
아래 입력칸에 테스트 메일을 발송하실 메일 주소를 입력하시면, [메일검사] 라는 제목으로 테스트 메일을 발송합니다.<br>
보내는 메일주소 : <?php echo get_sanitize_input($config['cf_admin_email']); ?><br>
<?php if (function_exists('domain_mail_host') && $config['cf_admin_email'] && stripos($config['cf_admin_email'], domain_mail_host()) === false) { ?>
<?php echo '외부메일설정이나 기타 설정을 하지 않았다면, 도메인과 다른 헤더로 여겨 스팸이나 차단될 가능성이 있습니다.<br>기본환경설정에서 관리자 메일 주소를 name'.domain_mail_host().' 과 같은 도메인 형식으로 설정할것을 권장합니다.'; ?>
<?php } ?>
</p>
</div>
<form name="fsendmailtest" method="post">
+1 -1
View File
@@ -72,7 +72,7 @@ function order_update_delivery($od_id, $mb_id, $change_status, $delivery)
if($change_status != '배송')
return;
$sql = " update {$g5['g5_shop_order_table']} set od_delivery_company = '{$delivery['delivery_company']}', od_invoice = '{$delivery['invoice']}', od_invoice_time = '{$delivery['invoice_time']}' where od_id = '$od_id' and od_status = '준비' ";
$sql = " update {$g5['g5_shop_order_table']} set od_delivery_company = '".sql_real_escape_string($delivery['delivery_company'])."', od_invoice = '".sql_real_escape_string($delivery['invoice'])."', od_invoice_time = '".sql_real_escape_string($delivery['invoice_time'])."' where od_id = '$od_id' and od_status = '준비' ";
sql_query($sql);
$sql = " select * from {$g5['g5_shop_cart_table']} where od_id = '$od_id' ";
-1
View File
@@ -12,7 +12,6 @@ $ca = array(
'ca_name'=>'',
'ca_order'=>'',
'ca_mb_id'=>'',
'ca_skin_dir'=>'',
'ca_cert_use'=>0,
'ca_adult_use'=>0,
'ca_sell_email'=>'',
+3
View File
@@ -193,6 +193,7 @@ if ($w == "")
ca_name = '$ca_name',
$sql_common ";
sql_query($sql);
run_event('shop_admin_category_created', $ca_id);
}
else if ($w == "u")
{
@@ -212,6 +213,7 @@ else if ($w == "u")
$sql .= " and ca_mb_id = '{$member['mb_id']}' ";
sql_query($sql);
}
run_event('shop_admin_category_updated', $ca_id);
}
else if ($w == "d")
{
@@ -243,6 +245,7 @@ else if ($w == "d")
// 분류 삭제
$sql = " delete from {$g5['g5_shop_category_table']} where ca_id = '$ca_id' ";
sql_query($sql);
run_event('shop_admin_category_deleted', $ca_id);
}
if(function_exists('get_admin_captcha_by'))
+1 -1
View File
@@ -17,7 +17,7 @@ if ($stx != "") {
$sql_search .= " $where $sfl like '%$stx%' ";
$where = " and ";
}
if ($save_stx && ($save_stx != $stx))
if (isset($save_stx) && $save_stx && ($save_stx != $stx))
$page = 1;
}
+32 -31
View File
@@ -13,8 +13,6 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
$userinfo = get_icode_userinfo($config['cf_icode_id'], $config['cf_icode_pw']);
}
check_log_folder(G5_SHOP_PATH.'/inicis/key', false);
$g5['title'] = '쇼핑몰설정';
include_once (G5_ADMIN_PATH.'/admin.head.php');
@@ -68,8 +66,7 @@ if(!isset($default['de_pg_service'])) {
// inicis 필드 추가
if(!isset($default['de_inicis_mid'])) {
sql_query(" ALTER TABLE `{$g5['g5_shop_default_table']}`
ADD `de_inicis_mid` varchar(255) NOT NULL DEFAULT '' AFTER `de_kcp_site_key`,
ADD `de_inicis_admin_key` varchar(255) NOT NULL DEFAULT '' AFTER `de_inicis_mid` ", true);
ADD `de_inicis_mid` varchar(255) NOT NULL DEFAULT '' AFTER `de_kcp_site_key` ", true);
}
// 모바일 초기화면 이미지 줄 수 필드 추가
@@ -137,7 +134,7 @@ if(!isset($default['de_kakaopay_mid'])) {
// 이니시스 웹결제 사인키 필드 추가
if(!isset($default['de_inicis_sign_key'])) {
sql_query(" ALTER TABLE `{$g5['g5_shop_default_table']}`
ADD `de_inicis_sign_key` varchar(255) NOT NULL DEFAULT '' AFTER `de_inicis_admin_key` ", true);
ADD `de_inicis_sign_key` varchar(255) NOT NULL DEFAULT '' ", true);
}
// 네이버페이 필드추가
@@ -202,6 +199,14 @@ if( ! isset($default['de_easy_pay_services']) ){
sql_query($sql, false);
}
// KG 이니시스 iniapi_key 추가
if( ! isset($default['de_inicis_iniapi_key']) ){
$sql = "ALTER TABLE `{$g5['g5_shop_default_table']}`
ADD COLUMN `de_inicis_iniapi_key` VARCHAR(30) NOT NULL DEFAULT '' AFTER `de_inicis_sign_key`,
ADD COLUMN `de_inicis_iniapi_iv` VARCHAR(30) NOT NULL DEFAULT '' AFTER `de_inicis_iniapi_key`; ";
sql_query($sql, false);
}
if( function_exists('pg_setting_check') ){
pg_setting_check(true);
}
@@ -593,7 +598,7 @@ if(!$default['de_kakaopay_cancelpwd']){
<tr>
<th scope="row"><label for="de_bank_account">은행계좌번호</label></th>
<td>
<textarea name="de_bank_account" id="de_bank_account"><?php echo $default['de_bank_account']; ?></textarea>
<textarea name="de_bank_account" id="de_bank_account"><?php echo html_purifier($default['de_bank_account']); ?></textarea>
</td>
</tr>
<tr>
@@ -781,10 +786,11 @@ if(!$default['de_kakaopay_cancelpwd']){
<tr class="pg_info_fld kcp_info_fld">
<th scope="row"><label for="de_kcp_easy_pays">NHN KCP 간편결제</label></th>
<td>
<?php echo help("체크시 NHN KCP 간편결제들을 활성화 합니다.\nNHN_KCP > 네이버페이, 카카오페이는 테스트결제가 되지 않습니다."); ?>
<?php echo help("체크시 NHN KCP 간편결제들을 활성화 합니다.\nNHN_KCP > 네이버페이, 카카오페이는 테스트결제가 되지 않습니다.\n애플페이는 IOS 기기에 모바일결제만 가능합니다."); ?>
<input type="checkbox" id="de_easy_nhnkcp_payco" name="de_easy_pays[]" value="nhnkcp_payco" <?php if(stripos($default['de_easy_pay_services'], 'nhnkcp_payco') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nhnkcp_payco" disabled>PAYCO (페이코)</label><br>
<input type="checkbox" id="de_easy_nhnkcp_naverpay" name="de_easy_pays[]" value="nhnkcp_naverpay" <?php if(stripos($default['de_easy_pay_services'], 'nhnkcp_naverpay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nhnkcp_naverpay">NAVERPAY (네이버페이)</label><br>
<input type="checkbox" id="de_easy_nhnkcp_kakaopay" name="de_easy_pays[]" value="nhnkcp_kakaopay" <?php if(stripos($default['de_easy_pay_services'], 'nhnkcp_kakaopay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nhnkcp_kakaopay">KAKAOPAY (카카오페이)</label>
<input type="checkbox" id="de_easy_nhnkcp_kakaopay" name="de_easy_pays[]" value="nhnkcp_kakaopay" <?php if(stripos($default['de_easy_pay_services'], 'nhnkcp_kakaopay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nhnkcp_kakaopay">KAKAOPAY (카카오페이)</label><br>
<input type="checkbox" id="de_easy_nhnkcp_applepay" name="de_easy_pays[]" value="nhnkcp_applepay" <?php if(stripos($default['de_easy_pay_services'], 'nhnkcp_applepay') !== false){ echo 'checked="checked"'; } ?> > <label for="de_easy_nhnkcp_applepay">APPLEPAY (애플페이)</label>
</td>
</tr>
<tr class="pg_info_fld kcp_info_fld">
@@ -829,17 +835,24 @@ if(!$default['de_kakaopay_cancelpwd']){
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_admin_key">KG이니시스 키패스워드</label></th>
<th scope="row"><label for="de_inicis_sign_key">KG이니시스 웹결제 사인키</label></th>
<td>
<?php echo help("KG이니시스에서 발급받은 4자리 상점 키패스워드를 입력합니다.\nKG이니시스 상점관리자 패스워드와 관련이 없습니다.\n키패스워드 값을 확인하시려면 상점측에 발급된 키파일 안의 readme.txt 파일을 참조해 주십시오"); ?>
<input type="text" name="de_inicis_admin_key" value="<?php echo get_sanitize_input($default['de_inicis_admin_key']); ?>" id="de_inicis_admin_key" class="frm_input" size="5" maxlength="4">
<?php echo help("KG이니시스에서 발급받은 웹결제 사인키를 입력합니다.\n<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > 부가정보의 웹결제 signkey생성 조회 버튼 클릭, 팝업창에서 생성 버튼 클릭 후 해당 값을 입력합니다."); ?>
<input type="text" name="de_inicis_sign_key" value="<?php echo get_sanitize_input($default['de_inicis_sign_key']); ?>" id="de_inicis_sign_key" class="frm_input" size="40" maxlength="50">
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_sign_key">KG이니시스 웹결제 사인키</label></th>
<th scope="row"><label for="de_inicis_iniapi_key">KG이니시스 INIAPI KEY</label></th>
<td>
<?php echo help("KG이니시스에서 발급받은 웹결제 사인키를 입력합니다.\nKG이니시스 상점관리자 > 상점정보 > 계약정보 > 부가정보의 웹결제 signkey생성 조회 버튼 클릭, 팝업창에서 생성 버튼 클릭 후 해당 값을 입력합니다."); ?>
<input type="text" name="de_inicis_sign_key" value="<?php echo get_sanitize_input($default['de_inicis_sign_key']); ?>" id="de_inicis_sign_key" class="frm_input" size="40" maxlength="50">
<?php echo help("<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > 부가정보 > INIAPI key 생성 조회 하여 KEY를 여기에 입력합니다.\n이 항목은 영카트 주문에서 kg이니시스 PG 결제 취소, 부분취소, 에스크로 배송등록, 현금영수증 발급에 필요합니다."); ?>
<input type="text" name="de_inicis_iniapi_key" value="<?php echo get_sanitize_input($default['de_inicis_iniapi_key']); ?>" id="de_inicis_iniapi_key" class="frm_input" size="30" maxlength="30">
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_iniapi_iv">KG이니시스 INIAPI IV</label></th>
<td>
<?php echo help("<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > 부가정보 > INIAPI IV 생성 조회 하여 KEY를 여기에 입력합니다.\n이 항목은 영카트 주문에서 kg이니시스 현금영수증 발급에 필요합니다."); ?>
<input type="text" name="de_inicis_iniapi_iv" value="<?php echo get_sanitize_input($default['de_inicis_iniapi_iv']); ?>" id="de_inicis_iniapi_iv" class="frm_input" size="30" maxlength="30">
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
@@ -848,7 +861,7 @@ if(!$default['de_kakaopay_cancelpwd']){
<a href="http://sir.kr/main/service/samsungpay.php" target="_blank" class="kg_btn">삼성페이 서비스신청하기</a>
</th>
<td>
<?php echo help("KG이니시스와 별도로 <strong>삼성페이 사용 계약을 하신 경우</strong>에만 체크해주세요. (모바일 주문서 결제수단에 삼성페이가 노출됩니다.) <br >실결제시 반드시 결제대행사 KG이니시스 항목에 상점 아이디와 키패스워드를 입력해 주세요.", 50); ?>
<?php echo help("KG이니시스와 별도로 <strong>삼성페이 사용 계약을 하신 경우</strong>에만 체크해주세요. (모바일 주문서 결제수단에 삼성페이가 노출됩니다.) <br >실결제시 반드시 결제대행사 KG이니시스 항목에 상점 아이디와 웹결제 사인키를 입력해 주세요.", 50); ?>
<input type="checkbox" name="de_samsung_pay_use" value="1" id="de_samsung_pay_use"<?php echo $default['de_samsung_pay_use']?' checked':''; ?>> <label for="de_samsung_pay_use">사용</label>
</td>
</tr>
@@ -857,7 +870,7 @@ if(!$default['de_kakaopay_cancelpwd']){
<label for="de_inicis_lpay_use">KG이니시스 L.pay 사용</label>
</th>
<td>
<?php echo help("체크시 KG이니시스 L.pay를 사용합니다. <br >실결제시 반드시 결제대행사 KG이니시스 항목의 상점 정보( 아이디, 키패스워드, 웹결제 사인키 )를 입력해 주세요.", 50); ?>
<?php echo help("체크시 KG이니시스 L.pay를 사용합니다. <br >실결제시 반드시 결제대행사 KG이니시스 항목의 상점 정보( 아이디, 웹결제 사인키 )를 입력해 주세요.", 50); ?>
<input type="checkbox" name="de_inicis_lpay_use" value="1" id="de_inicis_lpay_use"<?php echo $default['de_inicis_lpay_use']?' checked':''; ?>> <label for="de_inicis_lpay_use">사용</label>
</td>
</tr>
@@ -866,7 +879,7 @@ if(!$default['de_kakaopay_cancelpwd']){
<label for="de_inicis_kakaopay_use">KG이니시스 카카오페이 사용</label>
</th>
<td>
<?php echo help("체크시 KG이니시스 결제의 카카오페이를 사용합니다. 주문서 결제수단에 카카오페이가 노출됩니다. <br>실결제시 반드시 결제대행사 KG이니시스 항목의 상점 정보( 아이디, 키패스워드, 웹결제 사인키 )를 입력해 주세요.", 50); ?>
<?php echo help("체크시 KG이니시스 결제의 카카오페이를 사용합니다. 주문서 결제수단에 카카오페이가 노출됩니다. <br>실결제시 반드시 결제대행사 KG이니시스 항목의 상점 정보( 아이디, 웹결제 사인키 )를 입력해 주세요.", 50); ?>
<input type="checkbox" name="de_inicis_kakaopay_use" value="1" id="de_inicis_kakaopay_use"<?php echo $default['de_inicis_kakaopay_use']?' checked':''; ?>> <label for="de_inicis_kakaopay_use">사용</label>
</td>
</tr>
@@ -2011,20 +2024,8 @@ if($default['de_iche_use'] || $default['de_vbank_use'] || $default['de_hp_use']
} catch(Exception $e) {
}
if(!is_dir($log_path)) {
echo '<script>'.PHP_EOL;
echo 'alert("'.str_replace(G5_PATH.'/', '', G5_SHOP_PATH).'/inicis 폴더 안에 log 폴더를 생성하신 후 쓰기권한을 부여해 주십시오.\n> mkdir log\n> chmod 707 log");'.PHP_EOL;
echo '</script>'.PHP_EOL;
} else {
if(!is_writable($log_path)) {
echo '<script>'.PHP_EOL;
echo 'alert("'.str_replace(G5_PATH.'/', '',$log_path).' 폴더에 쓰기권한을 부여해 주십시오.\n> chmod 707 log");'.PHP_EOL;
echo '</script>'.PHP_EOL;
} else {
if( function_exists('check_log_folder') && is_writable($log_path) ){
check_log_folder($log_path);
}
}
if( function_exists('check_log_folder') && is_writable($log_path) ){
check_log_folder($log_path);
}
}
+4 -2
View File
@@ -160,7 +160,8 @@ $check_sanitize_keys = array(
'cf_lg_mid', //LG유플러스 상점아이디
'cf_lg_mert_key', //LG유플러스 MERT KEY
'de_inicis_mid', //KG이니시스 상점아이디
'de_inicis_admin_key', //KG이니시스 키패스워드
'de_inicis_iniapi_key', //KG이니시스 INIAPI KEY
'de_inicis_iniapi_iv', //KG이니시스 INIAPI IV
'de_inicis_sign_key', //KG이니시스 웹결제 사인키
'de_samsung_pay_use', //KG이니시스 삼성페이 사용
'de_inicis_lpay_use', //KG이니시스 Lpay 사용
@@ -399,7 +400,8 @@ $sql = " update {$g5['g5_shop_default_table']}
de_kcp_mid = '{$de_kcp_mid}',
de_kcp_site_key = '{$de_kcp_site_key}',
de_inicis_mid = '{$de_inicis_mid}',
de_inicis_admin_key = '{$de_inicis_admin_key}',
de_inicis_iniapi_key = '{$de_inicis_iniapi_key}',
de_inicis_iniapi_iv = '{$de_inicis_iniapi_iv}',
de_inicis_sign_key = '{$de_inicis_sign_key}',
de_iche_use = '{$de_iche_use}',
de_sms_cont1 = '{$_POST['de_sms_cont1']}',
+1 -1
View File
@@ -45,7 +45,7 @@ $qstr1 = 'mb_name='.urlencode($mb_name);
<form name="fmember" method="get">
<div id="scp_list_find">
<label for="mb_name">회원이름</label>
<input type="text" name="mb_name" id="mb_name" value="<?php echo get_text($mb_name); ?>" class="frm_input required" required size="20">
<input type="text" name="mb_name" id="mb_name" value="<?php echo get_text($mb_name); ?>" class="frm_input" size="20">
<input type="submit" value="검색" class="btn_frmline">
</div>
<div class="tbl_head01 tbl_wrap new_win_con">
+62 -60
View File
@@ -112,7 +112,7 @@ function get_max_value($arr)
return array_pop($arr);
}
?>
<?php if (! auth_check_menu($auth, '400400', 'r', true)) { ?>
<div class="sidx">
<section id="anc_sidx_ord">
<h2>주문현황</h2>
@@ -368,6 +368,66 @@ function get_max_value($arr)
</div>
</section>
<script>
jQuery(function($) {
graph_draw();
$("#sidx_graph_area div").hover(
function() {
if($(this).is(":animated"))
return false;
var title = $(this).attr("title");
if(title && $(this).data("title") == undefined)
$(this).data("title", title);
var left = parseInt($(this).css("left")) + 10;
var bottom = $(this).height() + 5;
$(this)
.attr("title", "")
.append("<div id=\"price_tooltip\"><div></div></div>");
$("#price_tooltip")
.find("div")
.html(title)
.end()
// .css({ left: left+"px", bottom: bottom+"px" })
.show(200);
},
function() {
if($(this).is(":animated"))
return false;
$(this).attr("title", $(this).data("title"));
$("#price_tooltip").remove();
}
);
});
function graph_draw()
{
var g_h1 = new Array("<?php echo implode('", "', $h_val['order']); ?>");
var g_h2 = new Array("<?php echo implode('", "', $h_val['cancel']); ?>");
var duration = 600;
var $el = $("#sidx_graph_area li");
var h1, h2;
var $g1, $g2;
$el.each(function(index) {
h1 = g_h1[index];
h2 = g_h2[index];
$g1 = $(this).find(".order");
$g2 = $(this).find(".cancel");
$g1.animate({ height: h1+"px" }, duration);
$g2.animate({ height: h2+"px" }, duration);
});
}
</script>
<?php } //endif ?>
<?php if ($is_admin === 'super') { ?>
<div class="sidx sidx_cs">
<section id="anc_sidx_oneq">
<h2>1:1문의</h2>
@@ -480,64 +540,6 @@ function get_max_value($arr)
</div>
</section>
</div>
<script>
$(function() {
graph_draw();
$("#sidx_graph_area div").hover(
function() {
if($(this).is(":animated"))
return false;
var title = $(this).attr("title");
if(title && $(this).data("title") == undefined)
$(this).data("title", title);
var left = parseInt($(this).css("left")) + 10;
var bottom = $(this).height() + 5;
$(this)
.attr("title", "")
.append("<div id=\"price_tooltip\"><div></div></div>");
$("#price_tooltip")
.find("div")
.html(title)
.end()
// .css({ left: left+"px", bottom: bottom+"px" })
.show(200);
},
function() {
if($(this).is(":animated"))
return false;
$(this).attr("title", $(this).data("title"));
$("#price_tooltip").remove();
}
);
});
function graph_draw()
{
var g_h1 = new Array("<?php echo implode('", "', $h_val['order']); ?>");
var g_h2 = new Array("<?php echo implode('", "', $h_val['cancel']); ?>");
var duration = 600;
var $el = $("#sidx_graph_area li");
var h1, h2;
var $g1, $g2;
$el.each(function(index) {
h1 = g_h1[index];
h2 = g_h2[index];
$g1 = $(this).find(".order");
$g2 = $(this).find(".cancel");
$g1.animate({ height: h1+"px" }, duration);
$g2.animate({ height: h2+"px" }, duration);
});
}
</script>
<?php
} //end if
include_once (G5_ADMIN_PATH.'/admin.tail.php');
+2
View File
@@ -32,6 +32,8 @@ include_once(G5_PATH.'/head.sub.php');
<script>
// <![CDATA[
var g5_admin_csrf_token_key = "<?php echo (function_exists('admin_csrf_token_key')) ? admin_csrf_token_key() : ''; ?>";
function _copy(link)
{
var new_it_id = document.getElementById('new_it_id').value;
+34
View File
@@ -53,6 +53,7 @@ $opt_sql = " insert ignore into {$g5['g5_shop_item_option_table']} ( io_id, io_t
sql_query($opt_sql);
// html 에디터로 첨부된 이미지 파일 복사
$copied_editor_images = array();
if($cp['it_explan']) {
$matchs = get_editor_image($cp['it_explan'], false);
$count_matchs = (isset($matchs[1]) && is_array($matchs[1])) ? count($matchs[1]) : 0;
@@ -73,7 +74,13 @@ if($cp['it_explan']) {
$newfile = preg_replace("/\.([^\.]+)$/", "_".$new_it_id.".\\1", $matchs[1][$i]);
$cp['it_explan'] = str_replace($matchs[1][$i], $newfile, $cp['it_explan']);
$copied_editor_images[] = array(
'original' => $srcfile,
'new' => $dstfile
);
}
}
$sql = " update {$g5['g5_shop_item_table']} set it_explan = '".addslashes($cp['it_explan'])."' where it_id = '$new_it_id' ";
@@ -100,6 +107,11 @@ if($cp['it_mobile_explan']) {
$newfile = preg_replace("/\.([^\.]+)$/", "_".$new_it_id.".\\1", $matchs[1][$i]);
$cp['it_mobile_explan'] = str_replace($matchs[1][$i], $newfile, $cp['it_mobile_explan']);
$copied_editor_images[] = array(
'original' => $srcfile,
'new' => $dstfile
);
}
}
@@ -140,6 +152,7 @@ function copy_directory($src_dir, $dest_dir)
}
// 파일복사
$copied_item_files = array();
$dest_path = G5_DATA_PATH.'/item/'.$new_it_id;
@mkdir($dest_path, G5_DIR_PERMISSION);
@chmod($dest_path, G5_DIR_PERMISSION);
@@ -155,6 +168,11 @@ for($i=1; $i<=10; $i++) {
copy($file, $dstfile);
@chmod($dstfile, G5_FILE_PERMISSION);
$new_img = $new_it_id.'/'.basename($file);
$copied_item_files[] = array(
'original' => $file,
'new' => $dstfile,
);
}
$sql_img .= $comma." it_img{$i} = '$new_img' ";
@@ -166,6 +184,22 @@ $sql = " update {$g5['g5_shop_item_table']}
where it_id = '$new_it_id' ";
sql_query($sql);
/**
* 아이템 복사 처리 후 Event Hook
* @var string $it_id 원본 아이템 ID
* @var string $new_it_id 복사한 새로운 아이템 ID
* @var array $cp 복사한 아이템 정보
* @var array $copied_item_files 복사한 파일 목록
* @var array $copied_editor_images 복사한 에디터 이미지 목록
*/
run_event('shop_admin_itemcopy', array(
'it_id' => (string) $it_id,
'new_it_id' => (string) $new_it_id,
'cp' => $cp,
'copied_item_files' => $copied_item_files,
'copied_editor_images' => $copied_editor_images
));
$qstr = "ca_id=$ca_id&amp;sfl=$sfl&amp;sca=$sca&amp;page=$page&amp;stx=".urlencode($stx);
goto_url("itemlist.php?$qstr");
+3
View File
@@ -75,6 +75,7 @@ if ($w == "")
$sql_common
, ev_id = '$ev_id' ";
sql_query($sql);
run_event('shop_admin_event_created', $ev_id);
}
else if ($w == "u")
{
@@ -82,6 +83,7 @@ else if ($w == "u")
$sql_common
where ev_id = '$ev_id' ";
sql_query($sql);
run_event('shop_admin_event_updated', $ev_id);
}
else if ($w == "d")
{
@@ -92,6 +94,7 @@ else if ($w == "d")
// 이벤트상품삭제
$sql = " delete from {$g5['g5_shop_event_item_table']} where ev_id = '$ev_id' ";
sql_query($sql);
run_event('shop_admin_event_deleted', $ev_id);
$sql = " delete from {$g5['g5_shop_event_table']} where ev_id = '$ev_id' ";
sql_query($sql);
+5 -5
View File
@@ -476,13 +476,13 @@ if ($w == "" || $w == "u")
{
$sql = " insert into {$g5['g5_shop_item_relation_table']}
set it_id = '$it_id',
it_id2 = '$it_id2[$i]',
it_id2 = '".sql_real_escape_string($it_id2[$i])."',
ir_no = '$i' ";
sql_query($sql, false);
// 관련상품의 반대로도 등록
$sql = " insert into {$g5['g5_shop_item_relation_table']}
set it_id = '$it_id2[$i]',
set it_id = '".sql_real_escape_string($it_id2[$i])."',
it_id2 = '$it_id',
ir_no = '$i' ";
sql_query($sql, false);
@@ -496,7 +496,7 @@ if ($w == "" || $w == "u")
if (trim($ev_id[$i]))
{
$sql = " insert into {$g5['g5_shop_event_item_table']}
set ev_id = '$ev_id[$i]',
set ev_id = '".sql_real_escape_string($ev_id[$i])."',
it_id = '$it_id' ";
sql_query($sql, false);
}
@@ -510,7 +510,7 @@ if($option_count) {
( `io_id`, `io_type`, `it_id`, `io_price`, `io_stock_qty`, `io_noti_qty`, `io_use` )
VALUES ";
for($i=0; $i<$option_count; $i++) {
$sql .= $comma . " ( '{$_POST['opt_id'][$i]}', '0', '$it_id', '{$_POST['opt_price'][$i]}', '{$_POST['opt_stock_qty'][$i]}', '{$_POST['opt_noti_qty'][$i]}', '{$_POST['opt_use'][$i]}' )";
$sql .= $comma . " ( '".sql_real_escape_string($_POST['opt_id'][$i])."', '0', '$it_id', '".sql_real_escape_string($_POST['opt_price'][$i])."', '".sql_real_escape_string($_POST['opt_stock_qty'][$i])."', '".sql_real_escape_string($_POST['opt_noti_qty'][$i])."', '".sql_real_escape_string($_POST['opt_use'][$i])."' )";
$comma = ' , ';
}
@@ -524,7 +524,7 @@ if($supply_count) {
( `io_id`, `io_type`, `it_id`, `io_price`, `io_stock_qty`, `io_noti_qty`, `io_use` )
VALUES ";
for($i=0; $i<$supply_count; $i++) {
$sql .= $comma . " ( '{$_POST['spl_id'][$i]}', '1', '$it_id', '{$_POST['spl_price'][$i]}', '{$_POST['spl_stock_qty'][$i]}', '{$_POST['spl_noti_qty'][$i]}', '{$_POST['spl_use'][$i]}' )";
$sql .= $comma . " ( '".sql_real_escape_string($_POST['spl_id'][$i])."', '1', '$it_id', '".sql_real_escape_string($_POST['spl_price'][$i])."', '".sql_real_escape_string($_POST['spl_stock_qty'][$i])."', '".sql_real_escape_string($_POST['spl_noti_qty'][$i])."', '".sql_real_escape_string($_POST['spl_use'][$i])."' )";
$comma = ' , ';
}
+1
View File
@@ -19,6 +19,7 @@ if ($w == "u")
iq_answer = '$iq_answer'
where iq_id = '$iq_id' ";
sql_query($sql);
run_event('shop_admin_item_qa_updated', $iq_id);
if(trim($iq_answer)) {
$sql = " select a.iq_email, a.iq_hp, b.it_name
+1
View File
@@ -23,6 +23,7 @@ if ($_POST['act_button'] == "선택삭제") {
$sql = "delete from {$g5['g5_shop_item_qa_table']} where iq_id = '{$iiq_id}' ";
sql_query($sql);
run_event('shop_admin_item_qa_deleted', $iiq_id);
}
}
+5 -5
View File
@@ -85,7 +85,7 @@ if($ps_run) {
} // for
} else {
for($i=0; $i<$subject_count; $i++) {
$spl_subject = isset($_POST['subject'][$i]) ? preg_replace(G5_OPTION_ID_FILTER, '', trim(stripslashes($_POST['subject'][$i]))) : '';
$spl_subject = isset($_POST['subject'][$i]) ? preg_replace(G5_OPTION_ID_FILTER, '', strip_tags(trim(stripslashes($_POST['subject'][$i])))) : '';
$spl_val = isset($_POST['supply'][$i]) ? explode(',', preg_replace(G5_OPTION_ID_FILTER, '', trim(stripslashes($_POST['supply'][$i])))) : '';
$spl_count = count($spl_val);
@@ -103,7 +103,7 @@ if($ps_run) {
$sql = " select io_price, io_stock_qty, io_noti_qty, io_use
from {$g5['g5_shop_item_option_table']}
where it_id = '{$post_it_id}'
and io_id = '$spl_id'
and io_id = '".sql_real_escape_string($spl_id)."'
and io_type = '1' ";
$row = sql_fetch($sql);
@@ -117,11 +117,11 @@ if($ps_run) {
?>
<tr>
<td class="td_chk">
<input type="hidden" name="spl_id[]" value="<?php echo $spl_id; ?>">
<label for="spl_chk_<?php echo $i; ?>" class="sound_only"><?php echo $spl_subject.' '.$spl; ?></label>
<input type="hidden" name="spl_id[]" value="<?php echo get_text($spl_id); ?>">
<label for="spl_chk_<?php echo $i; ?>" class="sound_only"><?php echo get_text($spl_subject.' '.$spl); ?></label>
<input type="checkbox" name="spl_chk[]" id="spl_chk_<?php echo $i; ?>" value="1">
</td>
<td class="spl-subject-cell"><?php echo $spl_subject; ?></td>
<td class="spl-subject-cell"><?php echo get_text($spl_subject); ?></td>
<td class="spl-cell"><?php echo $spl; ?></td>
<td class="td_numsmall">
<label for="spl_price_<?php echo $i; ?>" class="sound_only">상품금액</label>
+1
View File
@@ -34,6 +34,7 @@ if ($w == "u")
is_reply_name = '".$member['mb_nick']."'
where is_id = '".$posts['is_id']."'";
sql_query($sql);
run_event('shop_admin_item_use_updated', $posts['is_id']);
if( isset($_POST['it_id']) ) {
update_use_cnt($_POST['it_id']);
+1
View File
@@ -40,6 +40,7 @@ for ($i=0; $i<$count_post_chk; $i++)
{
$sql = "delete from {$g5['g5_shop_item_use_table']} where is_id = '{$iis_id}' ";
sql_query($sql);
run_event('shop_admin_item_use_deleted', $iis_id);
}
if($iit_id){
+18 -37
View File
@@ -222,46 +222,27 @@ if (in_array($_POST['ct_status'], $status_cancel)) {
break;
case 'inicis':
include_once(G5_SHOP_PATH.'/settle_inicis.inc.php');
$cancel_msg = iconv_euckr('쇼핑몰 운영자 승인 취소');
$cancel_msg = '쇼핑몰 운영자 승인 취소';
$args = array(
'paymethod' => get_type_inicis_paymethod($od['od_settle_case']),
'tid' => $od['od_tno'],
'msg' => $cancel_msg
);
/*********************
* 3. 취소 정보 설정 *
*********************/
$inipay->SetField("type", "cancel"); // 고정 (절대 수정 불가)
$inipay->SetField("mid", $default['de_inicis_mid']); // 상점아이디
/**************************************************************************************************
* admin 은 키패스워드 변수명입니다. 수정하시면 안됩니다. 1111의 부분만 수정해서 사용하시기 바랍니다.
* 키패스워드는 상점관리자 페이지(https://iniweb.inicis.com)의 비밀번호가 아닙니다. 주의해 주시기 바랍니다.
* 키패스워드는 숫자 4자리로만 구성됩니다. 이 값은 키파일 발급시 결정됩니다.
* 키패스워드 값을 확인하시려면 상점측에 발급된 키파일 안의 readme.txt 파일을 참조해 주십시오.
**************************************************************************************************/
$inipay->SetField("admin", $default['de_inicis_admin_key']); //비대칭 사용키 키패스워드
$inipay->SetField("tid", $od['od_tno']); // 취소할 거래의 거래아이디
$inipay->SetField("cancelmsg", $cancel_msg); // 취소사유
$response = inicis_tid_cancel($args);
$result = json_decode($response, true);
/****************
* 4. 취소 요청 *
****************/
$inipay->startAction();
/****************************************************************
* 5. 취소 결과 *
* *
* 결과코드 : $inipay->getResult('ResultCode') ("00"이면 취소 성공) *
* 결과내용 : $inipay->getResult('ResultMsg') (취소결과에 대한 설명) *
* 취소날짜 : $inipay->getResult('CancelDate') (YYYYMMDD) *
* 취소시각 : $inipay->getResult('CancelTime') (HHMMSS) *
* 현금영수증 취소 승인번호 : $inipay->getResult('CSHR_CancelNum') *
* (현금영수증 발급 취소시에만 리턴됨) *
****************************************************************/
$res_cd = $inipay->getResult('ResultCode');
$res_msg = $inipay->getResult('ResultMsg');
if($res_cd != '00') {
$pg_res_cd = $res_cd;
$pg_res_msg = iconv_utf8($res_msg);
if (isset($result['resultCode'])) {
if ($result['resultCode'] != '00') {
$pg_res_cd = $result['resultCode'];
$pg_res_msg = $result['resultMsg'];
}
} else {
$pg_res_cd = '';
$pg_res_msg = 'curl 로 데이터를 받지 못했습니다.';
}
break;
case 'KAKAOPAY':
include_once(G5_SHOP_PATH.'/settle_kakaopay.inc.php');
+2 -2
View File
@@ -21,7 +21,7 @@ $fr_date = (isset($_GET['fr_date']) && preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0
$to_date = (isset($_GET['to_date']) && preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $_GET['to_date'])) ? $_GET['to_date'] : '';
$od_misu = isset($_GET['od_misu']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_misu']) : '';
$od_cancel_price = isset($_GET['od_cancel_price']) ? preg_replace('/[^0-9a-z]/', '', $_GET['od_cancel_price']) : '';
$od_cancel_price = isset($_GET['od_cancel_price']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_cancel_price']) : '';
$od_refund_price = isset($_GET['od_refund_price']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_refund_price']) : '';
$od_receipt_point = isset($_GET['od_receipt_point']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_receipt_point']) : '';
$od_coupon = isset($_GET['od_coupon']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_coupon']) : '';
@@ -222,7 +222,7 @@ if( function_exists('pg_setting_check') ){
<input type="radio" name="od_settle_case" value="신용카드" id="od_settle_case06" <?php echo get_checked($od_settle_case, '신용카드'); ?>>
<label for="od_settle_case06">신용카드</label>
<input type="radio" name="od_settle_case" value="간편결제" id="od_settle_case07" <?php echo get_checked($od_settle_case, '간편결제'); ?>>
<label for="od_settle_case07" data-tooltip-text="NHN_KCP 간편결제 : PAYCO, 네이버페이, 카카오페이(NHN_KCP) &#xa;LG유플러스 간편결제 : PAYNOW &#xa;KG 이니시스 간편결제 : KPAY, 삼성페이, LPAY, 카카오페이(KG이니시스)">PG간편결제</label>
<label for="od_settle_case07" data-tooltip-text="NHN_KCP 간편결제 : PAYCO, 네이버페이, 카카오페이(NHN_KCP), 애플페이(NHN_KCP) &#xa;LG유플러스 간편결제 : PAYNOW &#xa;KG 이니시스 간편결제 : KPAY, 삼성페이, LPAY, 카카오페이(KG이니시스)">PG간편결제</label>
<input type="radio" name="od_settle_case" value="KAKAOPAY" id="od_settle_case08" <?php echo get_checked($od_settle_case, 'KAKAOPAY'); ?>>
<label for="od_settle_case08">KAKAOPAY</label>
</div>
+1 -1
View File
@@ -227,7 +227,7 @@ if(!sql_query(" select pp_cash from {$g5['g5_shop_personalpay_table']} limit 1 "
<?php } ?>
<tr>
<th scope="row"><label for="pp_shop_memo">상점메모</label></th>
<td><textarea name="pp_shop_memo" id="pp_shop_memo" rows="8"><?php echo $pp['pp_shop_memo']; ?></textarea></td>
<td><textarea name="pp_shop_memo" id="pp_shop_memo" rows="8"><?php echo html_purifier($pp['pp_shop_memo']); ?></textarea></td>
</tr>
<tr>
<th scope="row"><label for="pp_use">사용</label></th>
+2
View File
@@ -66,6 +66,8 @@ while($res = sql_fetch_array($qry))
$group_name = '미분류';
else
$group_name = $tmp['fg_name'];
$res['fo_content'] = html_purifier($res['fo_content']);
$list_text .="
<li class=\"screen_list sms5_box\">
<span class=\"box_ico\"></span>
+1 -1
View File
@@ -174,7 +174,7 @@ function multi_update(sel)
<input type="checkbox" name="fo_no[]" value="<?php echo $res['fo_no']?>" id="fo_no_<?php echo $i; ?>">
</div>
<div class="li_preview">
<textarea readonly class="box_txt box_square"><?php echo $res['fo_content']?></textarea>
<textarea readonly class="box_txt box_square"><?php echo html_purifier($res['fo_content']); ?></textarea>
</div>
<div class="li_info">
<span class="sound_only">그룹 </span><b><?php echo $group_name?></b><br>
+1 -1
View File
@@ -67,7 +67,7 @@ include_once(G5_ADMIN_PATH.'/admin.head.php');
<div class="sms5_box write_wrap">
<span class="box_ico"></span>
<label for="sms_contents" id="wr_message_lbl">내용</label>
<textarea name="fo_content" id="sms_contents" class="box_txt box_square" onkeyup="byte_check('sms_contents', 'sms_bytes');" accesskey="m"><?php echo $write['fo_content']?></textarea>
<textarea name="fo_content" id="sms_contents" class="box_txt box_square" onkeyup="byte_check('sms_contents', 'sms_bytes');" accesskey="m"><?php echo html_purifier($write['fo_content']); ?></textarea>
<div id="sms_byte"><span id="sms_bytes">0</span> / 80 byte</div>
+1 -1
View File
@@ -109,7 +109,7 @@ function all_send()
<div id="con_sms" class="sms5_box">
<span class="box_ico"></span>
<textarea class="box_txt is_overview" readonly><?php echo $write['wr_message'];?></textarea>
<textarea class="box_txt is_overview" readonly><?php echo html_purifier($write['wr_message']); ?></textarea>
</div>
<?php if ($write['wr_re_total'] && !$wr_renum) { ?>
+10 -1
View File
@@ -33,7 +33,16 @@ if ($w == 'u' && is_numeric($bk_no)) {
$g5['title'] .= '수정';
}
else {
$write = array('bg_no' => (int) $bg_no);
$write = array(
'bg_no' => (int) $bg_no,
'bk_no' => 0,
'mb_id' => '',
'bk_name' => '',
'bk_hp' => '',
'bk_memo' => '',
'bk_receipt' => 1,
'bk_datetime' => ''
);
$g5['title'] .= '추가';
}
+7 -9
View File
@@ -21,7 +21,7 @@ for ($kk=0;$row = sql_fetch_array($result);$kk++)
$bk_no = $row['bk_no'];
for ($i=0; $i<count($post_chk_bg_no); $i++)
{
$bg_no = $post_chk_bg_no[$i];
$bg_no = (int) $post_chk_bg_no[$i];
if( !$bg_no ) continue;
$sql = " insert into {$g5['sms5_book_table']}
@@ -71,18 +71,16 @@ if( count($save_group) ){ //그룹테이블 업데이트
$msg = '해당 번호를 선택한 그룹으로 '.$act.' 하였습니다.';
$opener_href = './num_book.php?page='.$page;
echo <<<HEREDOC
?>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
<script>
alert("$msg");
opener.document.location.href = "$opener_href";
alert("<?php echo $msg; ?>");
opener.document.location.href = "<?php echo $opener_href; ?>";
window.close();
</script>
<noscript>
<p>
"$msg"
<?php echo $msg; ?>
</p>
<a href="$opener_href">돌아가기</a>
</noscript>
HEREDOC;
<a href="<?php echo $opener_href; ?>">돌아가기</a>
</noscript>
+3 -3
View File
@@ -16,13 +16,13 @@ if( ! $is_admin ){
}
}
run_event('admin_request_handler_'.$call, $arr_query, $token);
$sub_menu = admin_menu_find_by($call, 'sub_menu');
$g5['title'] = admin_menu_find_by($call, 'title');
run_event('admin_request_handler_'.$call, $arr_query, $token);
include_once ('./admin.head.php');
run_event('admin_get_page_'.$call, $arr_query, $token);
include_once ('./admin.tail.php');
include_once ('./admin.tail.php');
+11 -1
View File
@@ -17,7 +17,17 @@ if($error) {
<script>
alert("<?php echo $msg; ?>");
window.close();
try {
window.close();
} catch(error) {
history.back();
}
setTimeout(function() {
if (window.history.length) {
window.history.back();
}
}, 500);
</script>
<noscript>
+2 -2
View File
@@ -5,7 +5,7 @@ if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가
if (G5_IS_MOBILE) {
// 모바일의 경우 설정을 따르지 않는다.
include_once(G5_BBS_PATH.'/_head.php');
echo html_purifier(stripslashes($board['bo_mobile_content_head']));
echo run_replace('board_mobile_content_head', html_purifier(stripslashes($board['bo_mobile_content_head'])), $board);
} else {
// 상단 파일 경로를 입력하지 않았다면 기본 상단 파일도 include 하지 않음
if (trim($board['bo_include_head'])) {
@@ -15,5 +15,5 @@ if (G5_IS_MOBILE) {
include_once(G5_BBS_PATH.'/_head.php');
}
}
echo html_purifier(stripslashes($board['bo_content_head']));
echo run_replace('board_content_head', html_purifier(stripslashes($board['bo_content_head'])), $board);
}
+2 -2
View File
@@ -3,11 +3,11 @@ if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가
// 게시판 관리의 하단 파일 경로
if (G5_IS_MOBILE) {
echo html_purifier(stripslashes($board['bo_mobile_content_tail']));
echo run_replace('board_mobile_content_tail', html_purifier(stripslashes($board['bo_mobile_content_tail'])), $board);
// 모바일의 경우 설정을 따르지 않는다.
include_once(G5_BBS_PATH.'/_tail.php');
} else {
echo html_purifier(stripslashes($board['bo_content_tail']));
echo run_replace('board_content_tail', html_purifier(stripslashes($board['bo_content_tail'])), $board);
// 하단 파일 경로를 입력하지 않았다면 기본 하단 파일도 include 하지 않음
if (trim($board['bo_include_tail'])) {
if (is_include_path_check($board['bo_include_tail'])) { //파일경로 체크
+3 -3
View File
@@ -81,20 +81,20 @@ $content_skin_url = get_skin_url('content', $co['co_skin']);
$skin_file = $content_skin_path.'/content.skin.php';
if ($is_admin)
echo '<div class="ctt_admin"><a href="'.G5_ADMIN_URL.'/contentform.php?w=u&amp;co_id='.$co_id.'" class="btn_admin btn"><span class="sound_only">내용 수정</span><i class="fa fa-cog fa-spin fa-fw"></i></a></div>';
echo run_replace('content_admin_button_html', '<div class="ctt_admin"><a href="'.G5_ADMIN_URL.'/contentform.php?w=u&amp;co_id='.$co_id.'" class="btn_admin btn"><span class="sound_only">내용 수정</span><i class="fa fa-cog fa-spin fa-fw"></i></a></div>', $co);
?>
<?php
if(is_file($skin_file)) {
$himg = G5_DATA_PATH.'/content/'.$co_id.'_h';
if (file_exists($himg)) // 상단 이미지
echo '<div id="ctt_himg" class="ctt_img"><img src="'.G5_DATA_URL.'/content/'.$co_id.'_h" alt=""></div>';
echo run_replace('content_head_image_html', '<div id="ctt_himg" class="ctt_img"><img src="'.G5_DATA_URL.'/content/'.$co_id.'_h" alt=""></div>', $co);
include($skin_file);
$timg = G5_DATA_PATH.'/content/'.$co_id.'_t';
if (file_exists($timg)) // 하단 이미지
echo '<div id="ctt_timg" class="ctt_img"><img src="'.G5_DATA_URL.'/content/'.$co_id.'_t" alt=""></div>';
echo run_replace('content_tail_image_html', '<div id="ctt_timg" class="ctt_img"><img src="'.G5_DATA_URL.'/content/'.$co_id.'_t" alt=""></div>', $co);
} else {
echo '<p>'.str_replace(G5_PATH.'/', '', $skin_file).'이 존재하지 않습니다.</p>';
}
+8
View File
@@ -22,6 +22,14 @@ $file = sql_fetch($sql);
if (!$file['bf_file'])
alert_close('파일 정보가 존재하지 않습니다.');
$nonce = isset($_REQUEST['nonce']) ? preg_replace('/[^0-9a-z\|]/i', '', $_REQUEST['nonce']) : '';
if (function_exists('download_file_nonce_is_valid') && !defined('G5_DOWNLOAD_NONCE_CHECK')){
if(! download_file_nonce_is_valid($nonce, $bo_table, $wr_id)){
alert('토큰 유효시간이 지났거나 토큰이 유효하지 않습니다.\\n브라우저를 새로고침 후 다시 시도해 주세요.', G5_URL);
}
}
// JavaScript 불가일 때
$js = (isset($_GET['js'])) ? $_GET['js'] : '';
if($js != 'on' && $board['bo_download_point'] < 0) {
+5 -2
View File
@@ -17,12 +17,15 @@ while ($row=sql_fetch_array($result))
$faq_master_list[$key] = $row;
}
$fm = array();
if (isset($fm_id) && $fm_id){
$fm_id = (int) $fm_id;
$qstr .= '&amp;fm_id=' . $fm_id; // 마스터faq key_id
$fm = $faq_master_list[$fm_id];
}
$fm = $faq_master_list[$fm_id];
if (!$fm['fm_id'])
if (! (isset($fm['fm_id']) && $fm['fm_id']))
alert('등록된 내용이 없습니다.');
$g5['title'] = $fm['fm_subject'];
+2 -2
View File
@@ -62,7 +62,7 @@ if(isset($_POST['js']) && $_POST['js'] === "on") {
and mb_id = '{$member['mb_id']}'
and bg_flag in ('good', 'nogood') ";
$row = sql_fetch($sql);
if ($row['bg_flag'])
if (isset($row['bg_flag']) && $row['bg_flag'])
{
if ($row['bg_flag'] == 'good')
$status = '추천';
@@ -127,7 +127,7 @@ if(isset($_POST['js']) && $_POST['js'] === "on") {
and mb_id = '{$member['mb_id']}'
and bg_flag in ('good', 'nogood') ";
$row = sql_fetch($sql);
if ($row['bg_flag'])
if (isset($row['bg_flag']) && $row['bg_flag'])
{
if ($row['bg_flag'] == 'good')
$status = '추천';
+14
View File
@@ -104,6 +104,13 @@ if (!$is_search_bbs) {
$list[$i] = get_list($row, $board, $board_skin_url, G5_IS_MOBILE ? $board['bo_mobile_subject_len'] : $board['bo_subject_len']);
$list[$i]['is_notice'] = true;
$list[$i]['list_content'] = $list[$i]['wr_content'];
// 비밀글인 경우 리스트에서 내용이 출력되지 않게 글 내용을 지웁니다.
if (strstr($list[$i]['wr_option'], "secret")) {
$list[$i]['wr_content'] = '';
}
$list[$i]['num'] = 0;
$i++;
$notice_count++;
@@ -197,6 +204,13 @@ if($page_rows > 0) {
$list[$i]['subject'] = search_font($stx, $list[$i]['subject']);
}
$list[$i]['is_notice'] = false;
$list[$i]['list_content'] = $list[$i]['wr_content'];
// 비밀글인 경우 리스트에서 내용이 출력되지 않게 글 내용을 지웁니다.
if (strstr($list[$i]['wr_option'], "secret")) {
$list[$i]['wr_content'] = '';
}
$list_num = $total_count - ($page - 1) * $list_page_rows - $notice_count;
$list[$i]['num'] = $list_num - $k;
+16 -6
View File
@@ -8,7 +8,7 @@ $mb_password = isset($_POST['mb_password']) ? trim($_POST['mb_password']) : '';
run_event('member_login_check_before', $mb_id);
if (!$mb_id || !$mb_password)
if (!$mb_id || run_replace('check_empty_member_login_password', !$mb_password, $mb_id))
alert('회원아이디나 비밀번호가 공백이면 안됩니다.');
$mb = get_member($mb_id);
@@ -27,11 +27,13 @@ if(function_exists('social_is_login_check')){
$is_social_password_check = social_is_login_password_check($mb_id);
}
//소셜 로그인이 맞다면 패스워드를 체크하지 않습니다.
$is_need_not_password = run_replace('login_check_need_not_password', $is_social_password_check, $mb_id, $mb_password, $mb, $is_social_login);
// $is_need_not_password 변수가 true 이면 패스워드를 체크하지 않습니다.
// 가입된 회원이 아니다. 비밀번호가 틀리다. 라는 메세지를 따로 보여주지 않는 이유는
// 회원아이디를 입력해 보고 맞으면 또 비밀번호를 입력해보는 경우를 방지하기 위해서입니다.
// 불법사용자의 경우 회원아이디가 틀린지, 비밀번호가 틀린지를 알기까지는 많은 시간이 소요되기 때문입니다.
if (!$is_social_password_check && (! (isset($mb['mb_id']) && $mb['mb_id']) || !login_password_check($mb, $mb_password, $mb['mb_password'])) ) {
if (!$is_need_not_password && (! (isset($mb['mb_id']) && $mb['mb_id']) || !login_password_check($mb, $mb_password, $mb['mb_password'])) ) {
run_event('password_is_wrong', 'login', $mb);
@@ -60,10 +62,18 @@ run_event('login_session_before', $mb, $is_social_login);
@include_once($member_skin_path.'/login_check.skin.php');
if (! (defined('SKIP_SESSION_REGENERATE_ID') && SKIP_SESSION_REGENERATE_ID)) {
session_regenerate_id(false);
if (function_exists('session_start_samesite')) {
session_start_samesite();
}
}
// 회원아이디 세션 생성
set_session('ss_mb_id', $mb['mb_id']);
// FLASH XSS 공격에 대응하기 위하여 회원의 고유키를 생성해 놓는다. 관리자에서 검사함 - 110106
set_session('ss_mb_key', md5($mb['mb_datetime'] . get_real_client_ip() . $_SERVER['HTTP_USER_AGENT']));
// FLASH XSS 공격에 대응하기 위하여 회원의 고유키를 생성해 놓는다. 관리자에서 검사함
generate_mb_key($mb);
// 회원의 토큰키를 세션에 저장한다. /common.php 에서 해당 회원의 토큰값을 검사한다.
if(function_exists('update_auth_session_token')) update_auth_session_token($mb['mb_datetime']);
@@ -153,7 +163,7 @@ if( is_admin($mb['mb_id']) && is_dir(G5_DATA_PATH.'/tmp/') ){
$tmp_data_check = false;
}
}
@fclose($tmp_data_check);
if (is_resource($tmp_data_check)) @fclose($tmp_data_check);
@unlink($tmp_data_file);
if(! $tmp_data_check){
+2
View File
@@ -77,6 +77,8 @@ if($result){
}
}
run_event('cert_refresh_update_after', $mb_id);
//===============================================================
(empty($url))? goto_url(G5_URL) : goto_url($url);
+2 -1
View File
@@ -17,6 +17,8 @@ if( function_exists('social_member_comfirm_redirect') && (! $url || $url === 're
social_member_comfirm_redirect();
}
$url = run_replace('member_confirm_next_url', $url);
$g5['title'] = '회원 비밀번호 확인';
include_once('./_head.sub.php');
@@ -31,7 +33,6 @@ if($url){
}
}
$url = get_text($url);
include_once($member_skin_path.'/member_confirm.skin.php');
+3 -1
View File
@@ -14,9 +14,11 @@ if (!($post_mb_password && check_password($post_mb_password, $member['mb_passwor
// 회원탈퇴일을 저장
$date = date("Ymd");
$sql = " update {$g5['member_table']} set mb_leave_date = '{$date}', mb_memo = '".date('Ymd', G5_SERVER_TIME)." 탈퇴함\n".sql_real_escape_string($mb['mb_memo'])."', mb_certify = '', mb_adult = 0, mb_dupinfo = '' where mb_id = '{$member['mb_id']}' ";
$sql = " update {$g5['member_table']} set mb_leave_date = '{$date}', mb_memo = '".date('Ymd', G5_SERVER_TIME)." 탈퇴함\n".sql_real_escape_string($member['mb_memo'])."', mb_certify = '', mb_adult = 0, mb_dupinfo = '' where mb_id = '{$member['mb_id']}' ";
sql_query($sql);
run_event('member_leave', $member);
// 3.09 수정 (로그아웃)
unset($_SESSION['ss_mb_id']);
+9 -2
View File
@@ -49,7 +49,9 @@ while ($row = sql_fetch_array($result))
$count_write = 0;
$count_comment = 0;
$next_wr_num = get_next_num($move_write_table);
// get_next_num 함수는 mysql 지연시 중복이 될수 있는 문제로 더 이상 사용하지 않습니다.
// $next_wr_num = get_next_num($move_write_table);
$next_wr_num = 0;
$sql2 = " select * from $write_table where wr_num = '$wr_num' order by wr_parent, wr_is_comment, wr_comment desc, wr_id ";
$result2 = sql_query($sql2);
@@ -78,7 +80,7 @@ while ($row = sql_fetch_array($result))
}
$sql = " insert into $move_write_table
set wr_num = '$next_wr_num',
set wr_num = " . ($next_wr_num ? "'$next_wr_num'" : "(SELECT IFNULL(MIN(wr_num) - 1, -1) FROM $move_write_table sq) ") . ",
wr_reply = '{$row2['wr_reply']}',
wr_is_comment = '{$row2['wr_is_comment']}',
wr_comment = '{$row2['wr_comment']}',
@@ -116,6 +118,11 @@ while ($row = sql_fetch_array($result))
sql_query($sql);
$insert_id = sql_insert_id();
if ($next_wr_num === 0) {
$tmp = sql_fetch("select wr_num from $move_write_table where wr_id = '$insert_id'");
$next_wr_num = $tmp['wr_num'];
}
// 코멘트가 아니라면
if (!$row2['wr_is_comment'])
+2 -1
View File
@@ -4,7 +4,8 @@ include_once('./_common.php');
if ($is_member) { alert("이미 로그인중입니다."); goto_url(G5_URL); }
if(!$_POST['mb_id']) { alert("잘못된 접근입니다."); goto_url(G5_URL); }
$ss_cert_mb_id = isset($_SESSION['ss_cert_mb_id']) ? trim(get_session('ss_cert_mb_id')) : '';
if(!(isset($_POST['mb_id']) && $_POST['mb_id'] === $ss_cert_mb_id)) { alert("잘못된 접근입니다."); goto_url(G5_URL); }
if($config['cf_cert_find'] != 1) alert("본인인증을 이용하여 아이디/비밀번호 찾기를 할 수 없습니다. 관리자에게 문의 하십시오.");
+19 -8
View File
@@ -15,6 +15,7 @@ if (!($token && $delete_token === $token))
alert('토큰 에러로 삭제 불가합니다.');
$tmp_array = array();
$deleted = array();
if ($qa_id) // 건별삭제
$tmp_array[0] = $qa_id;
else // 일괄삭제
@@ -56,21 +57,23 @@ for($i=0; $i<$count; $i++) {
delete_editor_thumbnail($row['qa_content']);
// 답변이 있는 질문글이라면 답변글 삭제
if(!$row['qa_type'] && $row['qa_status']) {
$row2 = sql_fetch(" select qa_content, qa_file1, qa_file2 from {$g5['qa_content_table']} where qa_parent = '$qa_id' ");
if (!$row['qa_type'] && $row['qa_status']) {
$answer = sql_fetch(" SELECT qa_id, qa_content, qa_file1, qa_file2 from {$g5['qa_content_table']} where qa_type = 1 AND qa_parent = {$qa_id} ");
// 첨부파일 삭제
for($k=1; $k<=2; $k++) {
@unlink(G5_DATA_PATH.'/qa/'.clean_relative_paths($row2['qa_file'.$k]));
for ($k = 1; $k <= 2; $k++) {
@unlink(G5_DATA_PATH . '/qa/' . clean_relative_paths($answer['qa_file' . $k]));
// 썸네일삭제
if(preg_match("/\.({$config['cf_image_extension']})$/i", $row2['qa_file'.$k])) {
delete_qa_thumbnail($row2['qa_file'.$k]);
if (preg_match("/\.({$config['cf_image_extension']})$/i", $answer['qa_file' . $k])) {
delete_qa_thumbnail($answer['qa_file' . $k]);
}
}
// 에디터 썸네일 삭제
delete_editor_thumbnail($row2['qa_content']);
delete_editor_thumbnail($answer['qa_content']);
sql_query(" delete from {$g5['qa_content_table']} where qa_type = '1' and qa_parent = '$qa_id' ");
// 답변글 삭제
sql_query(" DELETE from {$g5['qa_content_table']} where qa_type = 1 and qa_parent = {$qa_id} ");
$deleted[] = (int) $answer['qa_id'];
}
// 답변글 삭제시 질문글의 상태변경
@@ -80,6 +83,14 @@ for($i=0; $i<$count; $i++) {
// 글삭제
sql_query(" delete from {$g5['qa_content_table']} where qa_id = '$qa_id' ");
$deleted[] = $qa_id;
}
/**
* QA 글 삭제 후 Event Hook
* @var array $tmp_array 삭제 요청된 qa_id 목록. 소유자 확인, 답변글 존재 여부 등의 이유로 실제로 삭제처리가 안 된 ID가 포함될 수 있으며, 삭제처리 되었더라도 답변글은 이 목록에 포함되지 않음
* @var array $deleted 답변글을 포함한 삭제가 완료된 qa_id 목록
*/
run_event('qa_delete', $tmp_array, $deleted);
goto_url(G5_BBS_URL.'/qalist.php'.preg_replace('/^&amp;/', '?', $qstr));
+2 -2
View File
@@ -7,11 +7,11 @@ $qa_skin_url = get_skin_url('qa', (G5_IS_MOBILE ? $qaconfig['qa_mobile_skin'] :
if (G5_IS_MOBILE) {
// 모바일의 경우 설정을 따르지 않는다.
include_once('./_head.php');
echo conv_content($qaconfig['qa_mobile_content_head'], 1);
echo run_replace('qa_mobile_content_head', conv_content($qaconfig['qa_mobile_content_head'], 1), $qaconfig);
} else {
if($qaconfig['qa_include_head'] && is_include_path_check($qaconfig['qa_include_head']))
@include ($qaconfig['qa_include_head']);
else
include ('./_head.php');
echo conv_content($qaconfig['qa_content_head'], 1);
echo run_replace('qa_content_head', conv_content($qaconfig['qa_content_head'], 1), $qaconfig);
}
+2 -2
View File
@@ -2,11 +2,11 @@
if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가
if (G5_IS_MOBILE) {
echo conv_content($qaconfig['qa_mobile_content_tail'], 1);
echo run_replace('qa_mobile_content_tail', conv_content($qaconfig['qa_mobile_content_tail'], 1), $qaconfig);
// 모바일의 경우 설정을 따르지 않는다.
include_once('./_tail.php');
} else {
echo conv_content($qaconfig['qa_content_tail'], 1);
echo run_replace('qa_content_tail', conv_content($qaconfig['qa_content_tail'], 1), $qaconfig);
if($qaconfig['qa_include_tail'] && is_include_path_check($qaconfig['qa_include_tail']))
@include ($qaconfig['qa_include_tail']);
else
+26
View File
@@ -135,6 +135,32 @@ if(is_file($skin_file)) {
$answer_update_href = G5_BBS_URL.'/qawrite.php?w=u&amp;qa_id='.$answer['qa_id'].$qstr;
$answer_delete_href = G5_BBS_URL.'/qadelete.php?qa_id='.$answer['qa_id'].'&amp;token='.$token.$qstr;
}
$ss_name = 'ss_qa_view_'.$answer['qa_id'];
if(!get_session($ss_name))
set_session($ss_name, TRUE);
// 답변 첨부파일
$answer['img_file'] = array();
$answer['download_href'] = array();
$answer['download_source'] = array();
$answer['img_count'] = 0;
$answer['download_count'] = 0;
for ($i=1; $i<=2; $i++) {
if(preg_match("/\.({$config['cf_image_extension']})$/i", $answer['qa_file'.$i])) {
$attr_href = run_replace('thumb_view_image_href', G5_BBS_URL.'/view_image.php?fn='.urlencode('/'.G5_DATA_DIR.'/qa/'.$answer['qa_file'.$i]), '/'.G5_DATA_DIR.'/qa/'.$answer['qa_file'.$i], '', '', '', '');
$answer['img_file'][] = '<a href="'.$attr_href.'" target="_blank" class="view_image"><img src="'.G5_DATA_URL.'/qa/'.$answer['qa_file'.$i].'"></a>';
$answer['img_count']++;
continue;
}
if ($answer['qa_file'.$i]) {
$answer['download_href'][] = G5_BBS_URL.'/qadownload.php?qa_id='.$answer['qa_id'].'&amp;no='.$i;
$answer['download_source'][] = $answer['qa_source'.$i];
$answer['download_count']++;
}
}
}
$stx = get_text(stripslashes($stx));
+11 -1
View File
@@ -86,6 +86,7 @@ $qa_related = 0;
$qa_email_recv = (isset($_POST['qa_email_recv']) && $_POST['qa_email_recv']) ? 1 : 0;
$qa_sms_recv = (isset($_POST['qa_sms_recv']) && $_POST['qa_sms_recv']) ? 1 : 0;
$qa_status = 0;
$answer_id = null;
for ($i=1; $i<=5; $i++) {
$var = "qa_$i";
@@ -301,6 +302,7 @@ if($w == '' || $w == 'a' || $w == 'r') {
}
if($w == 'a') {
$answer_id = (int) sql_insert_id();
$sql = " update {$g5['qa_content_table']}
set qa_status = '1'
where qa_id = '{$write['qa_parent']}' ";
@@ -339,7 +341,15 @@ if($w == '' || $w == 'a' || $w == 'r') {
sql_query($sql);
}
run_event('qawrite_update', $qa_id, $write, $w, $qaconfig);
/**
* 1:1 문의/답변의 변경 시 Event Hook
* @var int $qa_id 삽입/수정 또는 답글/추가질문 대상 글의 ID
* @var array $write 삽입/수정 또는 답글/추가질문 대상 글의 데이터
* @var string $w 동작 모드 ('': 질문글 작성, 'a': 답변글 작성, 'u': 질문/답변 수정, 'r': 추가(관련) 질문)
* @var array $qaconfig 1:1 문의 설정
* @var ?int $answer_id 답변글 작성($w = 'a') 시 답변글의 ID
*/
run_event('qawrite_update', $qa_id, $write, $w, $qaconfig, ($w === 'a') ? $answer_id : null);
// SMS 알림
if($config['cf_sms_use'] == 'icode' && $qaconfig['qa_use_sms']) {
+11 -6
View File
@@ -17,7 +17,7 @@ if ($w == 'u' && $is_admin == 'super') {
alert('데모 화면에서는 하실(보실) 수 없는 작업입니다.');
}
if (!chk_captcha()) {
if (run_replace('register_member_chk_captcha', !chk_captcha(), $w)) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
@@ -94,10 +94,15 @@ if ($w == '' || $w == 'u') {
alert('닉네임을 올바르게 입력해 주십시오.');
}
if ($w == '' && !$mb_password)
alert('비밀번호가 넘어오지 않았습니다.');
if($w == '' && $mb_password != $mb_password_re)
alert('비밀번호가 일치하지 않습니다.');
// 비밀번호를 체크하는 상태의 기본값은 true이며, 비밀번호를 체크하지 않으려면 hook 을 통해 false 값으로 바꿔야 합니다.
$is_check_password = run_replace('register_member_password_check', true, $mb_id, $mb_nick, $mb_email, $w);
if ($is_check_password){
if ($w == '' && !$mb_password)
alert('비밀번호가 넘어오지 않았습니다.');
if ($w == '' && $mb_password != $mb_password_re)
alert('비밀번호가 일치하지 않습니다.');
}
if ($msg = empty_mb_name($mb_name)) alert($msg, "", true, true);
if ($msg = empty_mb_nick($mb_nick)) alert($msg, "", true, true);
@@ -111,7 +116,7 @@ if ($w == '' || $w == 'u') {
if ($msg = prohibit_mb_email($mb_email))alert($msg, "", true, true);
// 휴대폰 필수입력일 경우 휴대폰번호 유효성 체크
if ($config['cf_use_hp'] || ($config['cf_cert_hp'] || $config['cf_cert_simple']) && $config['cf_req_hp']) {
if (($config['cf_use_hp'] || $config['cf_cert_hp'] || $config['cf_cert_simple']) && $config['cf_req_hp']) {
if ($msg = valid_mb_hp($mb_hp)) alert($msg, "", true, true);
}
+6 -4
View File
@@ -49,9 +49,7 @@ echo '<?xml version="1.0" encoding="utf-8" ?>'."\n";
<channel>
<title><?php echo specialchars_replace($config['cf_title'].' &gt; '.$subj1.' &gt; '.$subj2); ?></title>
<link><?php echo specialchars_replace(get_pretty_url($bo_table)); ?></link>
<description>테스트 버전 0.2 (2004-04-26)</description>
<language>ko</language>
<?php
$sql = " select wr_id, wr_subject, wr_content, wr_name, wr_datetime, wr_option
from {$g5['write_prefix']}$bo_table
@@ -66,6 +64,10 @@ for ($i=0; $row=sql_fetch_array($result); $i++) {
$html = 1;
else
$html = 0;
if ($i === 0) {
echo '<description>'. specialchars_replace($subj2). ' ('. $row['wr_datetime'] .')</description>'.PHP_EOL;
}
?>
<item>
@@ -76,8 +78,8 @@ for ($i=0; $row=sql_fetch_array($result); $i++) {
<?php
$date = $row['wr_datetime'];
// rss 리더 스킨으로 호출하면 날짜가 제대로 표시되지 않음
//$date = substr($date,0,10) . "T" . substr($date,11,8) . "+09:00";
$date = date('r', strtotime($date));
$date = substr($date,0,10) . "T" . substr($date,11,8) . "+09:00";
//$date = date('r', strtotime($date)); // 구글 서치 콘솔에서 오류가 난다
?>
<dc:date><?php echo $date ?></dc:date>
</item>
+1 -1
View File
@@ -25,7 +25,7 @@ if ($stx) {
$sql = " select gr_id, bo_table, bo_read_level from {$g5['board_table']} where bo_use_search = 1 and bo_list_level <= '{$member['mb_level']}' ";
if ($gr_id)
$sql .= " and gr_id = '{$gr_id}' ";
$onetable = isset($onetable) ? $onetable : "";
$onetable = isset($onetable) ? preg_replace('/[^a-z0-9_]/i', '', $onetable) : '';
if ($onetable) // 하나의 게시판만 검색한다면
$sql .= " and bo_table = '{$onetable}' ";
$sql .= " order by bo_order, gr_id, bo_table ";
+12 -4
View File
@@ -252,12 +252,14 @@ if ($w == '' || $w == 'r') {
$wr_num = $write['wr_num'];
$wr_reply = $reply;
} else {
$wr_num = get_next_num($write_table);
// get_next_num 함수는 mysql 지연시 중복이 될수 있는 문제로 더 이상 사용하지 않습니다.
// $wr_num = get_next_num($write_table);
$wr_num = 0;
$wr_reply = '';
}
$sql = " insert into $write_table
set wr_num = '$wr_num',
set wr_num = " . ($w == 'r' ? "'$wr_num'" : "(SELECT IFNULL(MIN(wr_num) - 1, -1) FROM $write_table sq) ") . ",
wr_reply = '$wr_reply',
wr_comment = 0,
ca_name = '$ca_name',
@@ -676,8 +678,14 @@ sql_query(" delete from {$g5['autosave_table']} where as_uid = '{$uid}' ");
//------------------------------------------------------------------------------
// 비밀글이라면 세션에 비밀글의 아이디를 저장한다. 자신의 글은 다시 비밀번호를 묻지 않기 위함
if ($secret)
if ($secret) {
if (! $wr_num) {
$write = get_write($write_table, $wr_id, true);
$wr_num = $write['wr_num'];
}
set_session("ss_secret_{$bo_table}_{$wr_num}", TRUE);
}
// 메일발송 사용 (수정글은 발송하지 않음)
if (!($w == 'u' || $w == 'cu') && $config['cf_email_use'] && $board['bo_use_email']) {
+29 -12
View File
@@ -62,6 +62,11 @@ if(! isset($_SERVER['SERVER_ADDR'])) {
$_SERVER['SERVER_ADDR'] = isset($_SERVER['LOCAL_ADDR']) ? $_SERVER['LOCAL_ADDR'] : '';
}
// Cloudflare 환경을 고려한 https 사용여부
if (isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && $_SERVER['HTTP_X_FORWARDED_PROTO'] === "https") {
$_SERVER['HTTPS'] = 'on';
}
// multi-dimensional array에 사용자지정 함수적용
function array_map_deep($fn, $array)
{
@@ -221,7 +226,12 @@ ini_set("session.gc_maxlifetime", 10800); // session data의 garbage collection
ini_set("session.gc_probability", 1); // session.gc_probability는 session.gc_divisor와 연계하여 gc(쓰레기 수거) 루틴의 시작 확률을 관리합니다. 기본값은 1입니다. 자세한 내용은 session.gc_divisor를 참고하십시오.
ini_set("session.gc_divisor", 100); // session.gc_divisor는 session.gc_probability와 결합하여 각 세션 초기화 시에 gc(쓰레기 수거) 프로세스를 시작할 확률을 정의합니다. 확률은 gc_probability/gc_divisor를 사용하여 계산합니다. 즉, 1/100은 각 요청시에 GC 프로세스를 시작할 확률이 1%입니다. session.gc_divisor의 기본값은 100입니다.
session_set_cookie_params(0, '/');
if (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] != 'off') {
session_set_cookie_params(0, '/', null, true, true);
} else {
session_set_cookie_params(0, '/', null, false, true);
}
ini_set("session.cookie_domain", G5_COOKIE_DOMAIN);
function chrome_domain_session_name(){
@@ -362,7 +372,11 @@ if( $config['cf_cert_use'] || (defined('G5_YOUNGCART_VER') && G5_YOUNGCART_VER)
// IE 브라우저 또는 엣지브라우저 또는 IOS 모바일과 http환경에서는 secure; SameSite=None을 설정하지 않습니다.
if (isset($_SERVER['HTTP_USER_AGENT'])) {
if( preg_match('/Edge/i', $_SERVER['HTTP_USER_AGENT']) || preg_match('/(iPhone|iPod|iPad).*AppleWebKit.*Safari/i', $_SERVER['HTTP_USER_AGENT']) || preg_match('~MSIE|Internet Explorer~i', $_SERVER['HTTP_USER_AGENT']) || preg_match('~Trident/7.0(; Touch)?; rv:11.0~',$_SERVER['HTTP_USER_AGENT']) || ! (isset($_SERVER['HTTPS']) && $_SERVER['HTTPS']=='on') ){
if (preg_match('/Edge/i', $_SERVER['HTTP_USER_AGENT'])
|| preg_match('/(iPhone|iPod|iPad).*AppleWebKit.*Safari/i', $_SERVER['HTTP_USER_AGENT'])
|| preg_match('~MSIE|Internet Explorer~i', $_SERVER['HTTP_USER_AGENT'])
|| preg_match('~Trident/7.0(; Touch)?; rv:11.0~',$_SERVER['HTTP_USER_AGENT'])
|| !(isset($_SERVER['HTTPS']) && $_SERVER['HTTPS']=='on')) {
return $res;
}
}
@@ -372,7 +386,7 @@ if( $config['cf_cert_use'] || (defined('G5_YOUNGCART_VER') && G5_YOUNGCART_VER)
$cookie_session_name = method_exists('XenoPostToForm', 'g5_session_name') ? XenoPostToForm::g5_session_name() : 'PHPSESSID';
foreach ($headers as $header) {
if (!preg_match('~^Set-Cookie: '.$cookie_session_name.'=~', $header)) continue;
$header = preg_replace('~; secure(; HttpOnly)?$~', '', $header) . '; secure; SameSite=None';
$header = preg_replace('~(; secure; HttpOnly)?$~', '; secure; HttpOnly; SameSite=None', $header);
header($header, false);
$g5['session_cookie_samesite'] = 'none';
break;
@@ -475,6 +489,7 @@ if (isset($_REQUEST['w'])) {
$w = '';
}
/** @var int $wr_id 게시판 글의 ID */
if (isset($_REQUEST['wr_id'])) {
$wr_id = (int)$_REQUEST['wr_id'];
} else {
@@ -497,7 +512,8 @@ if (isset($_REQUEST['url'])) {
$urlencode = urlencode($_SERVER['REQUEST_URI']);
if (G5_DOMAIN) {
$p = @parse_url(G5_DOMAIN);
$urlencode = G5_DOMAIN.urldecode(preg_replace("/^".urlencode($p['path'])."/", "", $urlencode));
$p['path'] = isset($p['path']) ? $p['path'] : '/';
$urlencode = rtrim(G5_DOMAIN, '%2F').'%2F'.ltrim(urldecode(preg_replace("/^".urlencode($p['path'])."/", "", $urlencode)), '%2F');
}
}
@@ -571,27 +587,30 @@ if (isset($_SESSION['ss_mb_id']) && $_SESSION['ss_mb_id']) { // 로그인중이
}
/** @var array $write 글 데이터 */
$write = array();
/** @var string $write_table 게시판 테이블 전체이름 */
$write_table = '';
if ($bo_table) {
$board = get_board_db($bo_table, true);
if (isset($board['bo_table']) && $board['bo_table']) {
set_cookie("ck_bo_table", $board['bo_table'], 86400 * 1);
$gr_id = $board['gr_id'];
$write_table = $g5['write_prefix'] . $bo_table; // 게시판 테이블 전체이름
// 게시판 테이블 전체이름
$write_table = $g5['write_prefix'] . $bo_table;
if (isset($wr_id) && $wr_id) {
$write = get_write($write_table, $wr_id);
} else if (isset($wr_seo_title) && $wr_seo_title) {
$write = get_content_by_field($write_table, 'bbs', 'wr_seo_title', generate_seo_title($wr_seo_title));
if( isset($write['wr_id']) ){
$wr_id = $write['wr_id'];
if (isset($write['wr_id'])) {
$wr_id = (int) $write['wr_id'];
}
}
}
// 게시판에서
if (isset($board['bo_select_editor']) && $board['bo_select_editor']){
// 게시판에서 사용하는 에디터를 설정
if (isset($board['bo_select_editor']) && $board['bo_select_editor']) {
$config['cf_editor'] = $board['bo_select_editor'];
}
}
@@ -836,5 +855,3 @@ header('Cache-Control: pre-check=0, post-check=0, max-age=0'); // HTTP/1.1
header('Pragma: no-cache'); // HTTP/1.0
run_event('common_header');
$html_process = new html_process();
+3 -6
View File
@@ -28,6 +28,7 @@ define('G5_HTTPS_DOMAIN', '');
// 그누보드 디버그바 설정입니다, 실제 서버운영시 false 로 설정해 주세요.
define('G5_DEBUG', false);
define('G5_COLLECT_QUERY', false);
// Set Database table default engine is Database default_storage_engine, If you want to use MyISAM or InnoDB, change to MyISAM or InnoDB.
// DB에 테이블 생성 시 테이블의 기본 스토리지 엔진을 설정할 수 있습니다.
@@ -233,9 +234,5 @@ define('G5_VISIT_BROWSCAP_USE', false);
*/
define('G5_IP_DISPLAY', '\\1.♡.\\3.\\4');
if ((isset($_SERVER['HTTPS']) && $_SERVER['HTTPS']=='on') ||
(isset($_SERVER['HTTP_X_FORWARDED_PROTO']) && $_SERVER['HTTP_X_FORWARDED_PROTO']==='https')) { //https 통신일때 daum 주소 js
define('G5_POSTCODE_JS', '<script src="https://spi.maps.daum.net/imap/map_js_init/postcode.v2.js"></script>');
} else { //http 통신일때 daum 주소 js
define('G5_POSTCODE_JS', '<script src="http://dmaps.daum.net/map_js_init/postcode.v2.js"></script>');
}
// KAKAO 우편번호 서비스 CDN
define('G5_POSTCODE_JS', '<script src="//t1.daumcdn.net/mapjsapi/bundle/postcode/prod/postcode.v2.js" async></script>');
+2 -1
View File
@@ -799,7 +799,7 @@ box-shadow: 1px 2px 2px #eee;}
#od_tot_price strong{font-size:1.5em;color:#ff006c}
#sod_frm #sod_frm_pt_alert {margin:5px 0;color:#38b2bb }
#od_pay_sl h3{font-size:1.167em;margin:20px 0 5px}
#od_pay_sl input[type="radio"]{position:absolute;width:0;height:0;overflow:hidden;visibility:hidden;text-indent:-999px;left: 0;z-index: -1px;}
#od_pay_sl input[type="radio"]{position:absolute;width:0;height:0;overflow:hidden;visibility:hidden;text-indent:-999px;left: 0;z-index: -1;}
#od_pay_sl .lb_icon {display: inline-block;float:left;width:50%;background:#fff;border:1px solid #eceff4;margin:-1px 0 0 -1px;cursor: pointer;height:60px;position:relative;padding-left:65px;padding-top:20px;z-index:1}
#od_pay_sl input[type="radio"]:checked+.lb_icon {border:1px solid #ff006c;z-index:3}
#sod_frm_paysel {}
@@ -1148,6 +1148,7 @@ box-shadow: 1px 2px 2px #eee;}
.sod_frm_mobile #m_sod_frm_paysel .inicis_lpay{background:url(../img/lpay_logo.png) no-repeat;width:35px;height:12px;overflow:hidden;text-indent:-999px;display:inline-block;background-size:100%}
.sod_frm_mobile #m_sod_frm_paysel .inicis_kakaopay{background:url(../img/kakao.png) no-repeat 50% 50% #f4dc34;border-radius:30px;height:22px;width:74px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:35px auto}
.sod_frm_mobile #m_sod_frm_paysel .kakaopay_icon{background:url(../img/kakao.png) no-repeat 50% 50% #f4dc34;border-radius:30px;height:22px;width:74px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:35px auto}
.sod_frm_mobile #m_sod_frm_paysel .applepay_icon{background:url(../img/ico-mobile-applepay.png) no-repeat 50% 50% #fff;border-radius:30px;height:23px;width:50px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:35px auto}
.sod_frm_mobile #m_sod_frm_paysel .samsung_pay{margin-left:-23px;background:url(../img/samsungpay.png) no-repeat 24px 3px;height:25px;width:106px;display:inline-block;overflow:hidden;text-indent:-999px}
.sod_frm_mobile #sod_frm_pay{border-top:1px solid #f3f3f3}
.sod_frm_mobile #sod_frm_pay h2{margin:10px 0;font-size:1.25em}
+14 -13
View File
@@ -83,9 +83,9 @@ input[type=radio] {-webkit-appearance: radio}
/*카테고리*/
.menu {display:none;position:fixed;top:0;height:100%;z-index:99999;-webkit-backface-visibility:hidden;width:100%;background:#efefef}
.menu .menu_wr{;width:100%;height:100%;overflow-y:auto;background:#eee;position:relative;z-index:199919;
-webkit-box-shadow: 0 0 5px rgba(55,55,5,0.4));
-moz-box-shadow: 0 0 5px rgba(55,55,5,0.4));
.menu .menu_wr{width:100%;height:100%;overflow-y:auto;background:#eee;position:relative;z-index:199919;
-webkit-box-shadow: 0 0 5px rgba(55,55,5,0.4);
-moz-box-shadow: 0 0 5px rgba(55,55,5,0.4);
box-shadow: 0 0 5px rgba(55,55,5,0.4);}
.menu .menu_close {position:absolute;top:50%;right:0px;width:40px;height:40px;background:none;color:#fff;font-size:20px;margin-top:-20px;border:0;z-index:199999}
@@ -220,14 +220,15 @@ box-shadow: 0 0 6px rgba(0,0,0,0.2);}
#m_sod_frm_paysel h3{background:#fff;padding:15px 10px ;border:1px solid #e3e5e8;border-bottom:0}
#m_sod_frm_paysel ul {margin:0 0 ;background:#fff;padding:10px;border:1px solid #e3e5e8}
#m_sod_frm_paysel ul:after {display:block;visibility:hidden;clear:both;content:""}
#m_sod_frm_paysel li {float:left;padding:5px ;width:46%;height:25px}
#m_sod_frm_paysel li {float:left;padding:5px;width:46%;height:35px}
#m_sod_frm_paysel .KPAY{background:url('../img/kpay.png') no-repeat;width:37px;height:15px;overflow:hidden;text-indent:-999px;display:inline-block;background-size:100%}
#m_sod_frm_paysel .PAYNOW{background:url('../img/paynow.png') no-repeat;width:46px;height:15px;overflow:hidden;text-indent:-999px;display:inline-block;background-size:100%;}
#m_sod_frm_paysel .PAYCO{background:url('../img/payco.png') no-repeat 1px;width:46px;height:15px;overflow:hidden;text-indent:-999px;display:inline-block;background-size:100%;}
#m_sod_frm_paysel .PAYCO{background:url('../img/payco.png') no-repeat 1px;width:50px;height:15px;overflow:hidden;text-indent:-999px;display:inline-block;background-size:100%}
#m_sod_frm_paysel .inicis_lpay{background:url('../img/lpay_logo.png') no-repeat;width:35px;height:12px;overflow:hidden;text-indent:-999px;display:inline-block;background-size:100%;}
#m_sod_frm_paysel .inicis_kakaopay{background:url('../img/kakao.png') no-repeat 50% 50% #ffeb00;border-radius:30px;height:22px;width:74px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:35px auto}
#m_sod_frm_paysel .kakaopay_icon{background:url('../img/ico-mobile-kakaopay.png') no-repeat #fff;height:15px;width:43px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:35px auto}
#m_sod_frm_paysel .naverpay_icon{background:url('../img/ico-mobile-naverpay.png') no-repeat #fff;height:15px;width:40px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:35px auto}
#m_sod_frm_paysel .inicis_kakaopay{background:url('../img/kakao.png') no-repeat 50% 50% #ffeb00;border-radius:30px;height:26px;width:74px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:36px auto}
#m_sod_frm_paysel .kakaopay_icon{background:url('../img/ico-mobile-kakaopay.png') no-repeat #fff;height:23px;width:63px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:45px auto;background-position: 10% 40%}
#m_sod_frm_paysel .naverpay_icon{background:url('../img/ico-mobile-naverpay.png') no-repeat #fff;height:23px;width:60px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:45px auto;background-position: 0% 30%}
#m_sod_frm_paysel .applepay_icon{background:url('../img/ico-mobile-applepay.png') no-repeat #fff;height:30px;width:60px;display:inline-block;overflow:hidden;text-indent:-999px;background-size:43px auto}
#m_sod_frm_paysel .samsung_pay{margin-left:-23px;background:url('../img/samsungpay.png') no-repeat 24px 3px;height:25px;width:106px;display:inline-block;overflow:hidden;text-indent:-999px}
#sod_frm_pay{padding:10px;;border-top:1px solid #f3f3f3}
@@ -318,7 +319,7 @@ box-shadow: inset 0 1px 1px rgba(0, 0, 0, .075);
}
#sod_frm .sod_ta_wr{background: #fff}
#sod_frm .btn_confirm{;margin:0 10px 10px}
#sod_frm .btn_confirm{margin:0 10px 10px}
#sod_frm .btn_submit{width:100%;height:45px;font-size: 1.167em;font-weight: bold;margin:5px 0;border-radius:4px}
#sod_frm .btn_cancel,#sod_frm .btn01{width:100%;height:45px;line-height:43px;font-size:1.167em;font-weight: bold;padding:0;border-radius:4px}
@@ -358,7 +359,7 @@ box-shadow: inset 0 1px 1px rgba(0, 0, 0, .075);
#sod_addr .addr_btn:after {display:block;visibility:hidden;clear:both;content:""}
#sod_addr .sel_address {width:32%;float:left;margin-right:1%;height:30px;background:none;border:1px solid #333;color:#333;padding:0 5px}
#sod_addr .del_address {display:block;width:32%;text-align:center;float:left;margin-right:1%;border:1px solid #aaa;background:none;color:#888;padding:0 5px;height:30px;line-height:28px;vertical-align:middle}
#sod_addr input[type="radio"] {position:absolute;width:0;height:0;overflow:hidden;visibility:hidden;text-indent:-999px;left:0;z-index:-1px}
#sod_addr input[type="radio"] {position:absolute;width:0;height:0;overflow:hidden;visibility:hidden;text-indent:-999px;left:0;z-index:-1}
#sod_addr .add_lb {display:inline-block;float:left;width:32%;text-align:center;border:1px solid #4162ff;color:#4162ff;height:30px;line-height:28px}
#sod_addr input[type="radio"]:checked+.add_lb {z-index:3;background:#4162ff;color:#fff}
@@ -578,7 +579,7 @@ a.btn02 {display:inline-block;padding:8px 7px 7px;border:1px solid #3b3c3f;backg
a.btn02:focus, .btn02:hover {text-decoration:none}
button.btn02 {display:inline-block;margin:0;padding:7px;border:1px solid #3b3c3f;background:#4b545e;color:#fff;text-decoration:none}
.btn_confirm {text-align:center} /* 서식단계 진행 */
.btn_submit {padding:0 5px;border:0;background:#3a8afd;border:1px solid #1c70e9;color:#fff;letter-spacing:-0.1em;border-radius:3px}}
.btn_submit {padding:0 5px;border:0;background:#3a8afd;border:1px solid #1c70e9;color:#fff;letter-spacing:-0.1em;border-radius:3px}
fieldset .btn_submit {padding:0 7px;height:24px;line-height:1em}
a.btn_cancel {display:inline-block;padding:8px 7px 7px;border:1px solid #ccc;background:#fff;color:#000;text-decoration:none;vertical-align:middle}
button.btn_cancel {display:inline-block;padding:7px;border:1px solid #ccc;background:#fafafa;color:#000;vertical-align:top;text-decoration:none}
@@ -820,7 +821,7 @@ box-shadow:0 0 8px rgba(65,98,255,0.8)}
.sod_right #sod_bsk_tot{margin:10px}
#sod_frm_taker textarea{width:100%;height:80px}
#od_pay_sl input[type="radio"] {position:absolute;width:0;height:0;overflow:hidden;visibility:hidden;text-indent:-999px;left:0;z-index:-1px}
#od_pay_sl input[type="radio"] {position:absolute;width:0;height:0;overflow:hidden;visibility:hidden;text-indent:-999px;left:0;z-index:-1}
#od_pay_sl .lb_icon {display:inline-block;float:left;width:150px;background:#fff;border:1px solid #eceff4;margin:-1px 0 0 -1px;cursor:pointer;height:60px;position:relative;padding-left:65px;padding-top:20px;z-index:1}
#od_pay_sl input[type="radio"]:checked+.lb_icon {border:1px solid #ff006c;z-index:3}
@@ -899,7 +900,7 @@ box-shadow:0 0 8px rgba(65,98,255,0.8)}
#od_tot_price span{float:left;font-weight:bold}
#od_tot_price strong{font-size:1.5em;color:#ff006c}
#od_pay_sl h3{font-size:1.167em;margin:20px 0 5px}
#od_pay_sl input[type="radio"]{position:absolute;width:0;height:0;overflow:hidden;visibility:hidden;text-indent:-999px;left: 0;z-index: -1px;}
#od_pay_sl input[type="radio"]{position:absolute;width:0;height:0;overflow:hidden;visibility:hidden;text-indent:-999px;left: 0;z-index: -1;}
#od_pay_sl .lb_icon {display: inline-block;float:left;width:50%;background:#fff;border:1px solid #eceff4;margin:-1px 0 0 -1px;cursor: pointer;height:60px;position:relative;padding-left:65px;padding-top:20px;z-index:1}
#od_pay_sl input[type="radio"]:checked+.lb_icon {border:1px solid #ff006c;z-index:3}
#sod_frm_paysel {}
+5 -5
View File
@@ -9,19 +9,19 @@ if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) return;
*/
define('G5_DELIVERY_COMPANY',
'(경동택배^https://kdexp.com/basicNewDelivery.kd?barcode=^080-873-2178)'
.'(대신택배^http://home.daesinlogistics.co.kr/daesin/jsp/d_freight_chase/d_general_process2.jsp?billno1=^043-222-4582)'
.'(대신택배^https://www.ds3211.co.kr/freight/internalFreightSearch.ht?billno=^043-222-4582)'
.'(동부택배^http://www.dongbups.com/delivery/delivery_search_view.jsp?item_no=^1588-8848)'
.'(로젠택배^https://www.ilogen.com/m/personal/trace.pop/^1588-9988)'
.'(우체국^http://service.epost.go.kr/trace.RetrieveRegiPrclDeliv.postal?sid1=^1588-1300)'
.'(우체국^https://m.epost.go.kr/postal/mobile/mobile.trace.RetrieveDomRigiTraceList.comm?ems_gubun=E&sid1=^1588-1300)'
.'(이노지스택배^http://www.innogis.co.kr/tracking_view.asp?invoice=^1566-4082)'
.'(한진택배^http://www.hanjin.co.kr/Delivery_html/inquiry/result_waybill.jsp?wbl_num=^1588-0011)'
.'(한진택배^https://www.hanjin.co.kr/kor/CMS/DeliveryMgr/WaybillResult.do?mCode=MN038&schLang=KR&wblnumText2=^1588-0011)'
.'(롯데택배^https://www.lotteglogis.com/open/tracking?invno=^1588-2121)'
.'(CJ대한통운^https://www.doortodoor.co.kr/parcel/doortodoor.do?fsp_action=PARC_ACT_002&fsp_cmd=retrieveInvNoACT&invc_no=^1588-1255)'
.'(CVSnet편의점택배^http://was.cvsnet.co.kr/_ver2/board/ctod_status.jsp?invoice_no=^1577-1287)'
.'(CVSnet편의점택배^https://www.cvsnet.co.kr/invoice/tracking.do?invoice_no=^1577-1287)'
.'(KG옐로우캡택배^http://www.yellowcap.co.kr/custom/inquiry_result.asp?invoice_no=^1588-0123)'
.'(KGB택배^http://www.kgbls.co.kr/sub5/trace.asp?f_slipno=^1577-4577)'
.'(KG로지스^http://www.kglogis.co.kr/contents/waybill.jsp?item_no=^1588-8848)'
.'(건영택배^http://www.kunyoung.com/goods/goods_01.php?mulno=^031-460-2700)'
.'(건영택배^https://www.kunyoung.com/goods/goods_01.php?mulno=^031-460-2700)'
.'(호남택배^http://www.honamlogis.co.kr/04estimate/songjang_list.php?c_search1=^031-376-6070)'
);
-2
View File
@@ -1,2 +0,0 @@
<?php
if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가;
+4 -4
View File
@@ -2,7 +2,7 @@
if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가
// 자바스크립트와 CSS 파일을 새로 다운로드 하도록 파일의 끝에 년월일 지정
// 예) https://도메인/css/default.css?ver=210618
// 예) https://도메인/js/common.js?ver=210618
define('G5_CSS_VER', '210618');
define('G5_JS_VER', '210618');
// 예) https://도메인/css/default.css?ver=220620
// 예) https://도메인/js/common.js?ver=220620
define('G5_CSS_VER', '2303229');
define('G5_JS_VER', '2304171');
+5 -3
View File
@@ -71,7 +71,8 @@ include_once(G5_LIB_PATH.'/popular.lib.php');
<script>
function fsearchbox_submit(f)
{
if (f.stx.value.length < 2) {
var stx = f.stx.value.trim();
if (stx.length < 2) {
alert("검색어는 두글자 이상 입력하십시오.");
f.stx.select();
f.stx.focus();
@@ -80,8 +81,8 @@ include_once(G5_LIB_PATH.'/popular.lib.php');
// 검색에 많은 부하가 걸리는 경우 이 주석을 제거하세요.
var cnt = 0;
for (var i=0; i<f.stx.value.length; i++) {
if (f.stx.value.charAt(i) == ' ')
for (var i = 0; i < stx.length; i++) {
if (stx.charAt(i) == ' ')
cnt++;
}
@@ -91,6 +92,7 @@ include_once(G5_LIB_PATH.'/popular.lib.php');
f.stx.focus();
return false;
}
f.stx.value = stx;
return true;
}
Binary file not shown.

After

Width:  |  Height:  |  Size: 2.0 KiB

+2 -1
View File
@@ -7,7 +7,7 @@
DROP TABLE IF EXISTS `g5_auth`;
CREATE TABLE IF NOT EXISTS `g5_auth` (
`mb_id` varchar(20) NOT NULL default '',
`au_menu` varchar(20) NOT NULL default '',
`au_menu` varchar(50) NOT NULL default '',
`au_auth` set('r','w','d') NOT NULL default '',
PRIMARY KEY (`mb_id`,`au_menu`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
@@ -617,6 +617,7 @@ CREATE TABLE IF NOT EXISTS `g5_poll` (
`po_date` date NOT NULL default '0000-00-00',
`po_ips` mediumtext NOT NULL,
`mb_ids` text NOT NULL,
`po_use` tinyint(4) NOT NULL default '0',
PRIMARY KEY (`po_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
+2 -1
View File
@@ -349,7 +349,8 @@ CREATE TABLE IF NOT EXISTS `g5_shop_default` (
`de_kcp_mid` varchar(255) NOT NULL DEFAULT '',
`de_kcp_site_key` varchar(255) NOT NULL DEFAULT '',
`de_inicis_mid` varchar(255) NOT NULL DEFAULT '',
`de_inicis_admin_key` varchar(255) NOT NULL DEFAULT '',
`de_inicis_iniapi_key` varchar(30) NOT NULL DEFAULT '',
`de_inicis_iniapi_iv` varchar(30) NOT NULL DEFAULT '',
`de_inicis_sign_key` varchar(255) NOT NULL DEFAULT '',
`de_iche_use` tinyint(4) NOT NULL DEFAULT '0',
`de_easy_pay_use` tinyint(4) NOT NULL DEFAULT '0',
+16 -4
View File
@@ -268,6 +268,18 @@ if ($g5_install || $is_install === false) {
$bo_skin = ($tmp_bo_table[$i] === 'gallery') ? 'gallery' : 'basic';
if (in_array($tmp_bo_table[$i], array('gallery', 'qa'))) {
$read_bo_point = -1;
$write_bo_point = 5;
$comment_bo_point = 1;
$download_bo_point = -20;
} else {
$read_bo_point = $read_point;
$write_bo_point = $write_point;
$comment_bo_point = $comment_point;
$download_bo_point = $download_point;
}
$sql = " insert into `{$table_prefix}board`
set bo_table = '$tmp_bo_table[$i]',
gr_id = '$tmp_gr_id',
@@ -285,10 +297,10 @@ if ($g5_install || $is_install === false) {
bo_count_delete = '1',
bo_upload_level = '1',
bo_download_level = '1',
bo_read_point = '-1',
bo_write_point = '5',
bo_comment_point = '1',
bo_download_point = '-20',
bo_read_point = '$read_bo_point',
bo_write_point = '$write_bo_point',
bo_comment_point = '$comment_bo_point',
bo_download_point = '$download_bo_point',
bo_use_category = '0',
bo_category_list = '',
bo_use_sideview = '0',
+10 -2
View File
@@ -19,9 +19,17 @@ function certify_win_open(type, url, event) {
if($("input[name=veri_up_hash]").length < 1)
$("input[name=cert_no]").after('<input type="hidden" name="veri_up_hash" value="">');
if( navigator.userAgent.indexOf("Android") > - 1 || navigator.userAgent.indexOf("iPhone") > - 1 )
// iframe에서 세션공유 문제가 있어서 더 이상 iframe 을 사용하지 않습니다.
var use_iframe = false;
if(use_iframe && (navigator.userAgent.indexOf("Android") > - 1 || navigator.userAgent.indexOf("iPhone") > - 1))
{
var $frm = $(event.target.form);
if($frm.length < 1){
$frm = $(event.target).parent();
}
if($("#kcp_cert").length < 1) {
$frm.wrap('<div id="cert_info"></div>');
@@ -31,7 +39,7 @@ function certify_win_open(type, url, event) {
}
$("#cert_info")
.after('<iframe id="kcp_cert" name="kcp_cert" width="100%" height="700" frameborder="0" scrolling="no" style="display:none"></iframe>');
.after('<iframe id="kcp_cert" name="kcp_cert" width="100%" height="700" frameborder="0" scrolling="yes" style="display:none"></iframe>');
var temp_form = document.form_temp;
temp_form.target = "kcp_cert";
+3 -3
View File
@@ -355,8 +355,8 @@ var win_homepage = function(href) {
* 우편번호 창
**/
var win_zip = function(frm_name, frm_zip, frm_addr1, frm_addr2, frm_addr3, frm_jibeon) {
if(typeof daum === 'undefined'){
alert("다음 우편번호 postcode.v2.js 파일이 로드되지 않았습니다.");
if(typeof daum === "undefined"){
alert("KAKAO 우편번호 서비스 postcode.v2.js 파일이 로드되지 않았습니다.");
return false;
}
@@ -423,7 +423,7 @@ var win_zip = function(frm_name, frm_zip, frm_addr1, frm_addr2, frm_addr3, frm_j
element_wrap = document.createElement("div");
element_wrap.setAttribute("id", daum_pape_id);
element_wrap.style.cssText = 'display:none;border:1px solid;left:0;width:100%;height:300px;margin:5px 0;position:relative;-webkit-overflow-scrolling:touch;';
element_wrap.innerHTML = '<img src="//i1.daumcdn.net/localimg/localimages/07/postcode/320/close.png" id="btnFoldWrap" style="cursor:pointer;position:absolute;right:0px;top:-21px;z-index:1" class="close_daum_juso" alt="접기 버튼">';
element_wrap.innerHTML = '<img src="//t1.daumcdn.net/postcode/resource/images/close.png" id="btnFoldWrap" style="cursor:pointer;position:absolute;right:0px;top:-21px;z-index:1" class="close_daum_juso" alt="접기 버튼">';
jQuery('form[name="'+frm_name+'"]').find('input[name="'+frm_addr1+'"]').before(element_wrap);
jQuery("#"+daum_pape_id).off("click", ".close_daum_juso").on("click", ".close_daum_juso", function(e){
e.preventDefault();
Binary file not shown.

After

Width:  |  Height:  |  Size: 4.9 KiB

+2 -2
View File
@@ -40,7 +40,7 @@ $(function() {
});
if(isAndroid) {
$(document).on("touchend", "select.it_option", function() {
$(document).on("touchend mouseup", "select.it_option", function() {
option_add = true;
});
} else {
@@ -151,7 +151,7 @@ $(function() {
});
if(isAndroid) {
$(document).on("touchend", "select.it_supply", function() {
$(document).on("touchend mouseup", "select.it_supply", function() {
supply_add = true;
});
} else {
-5
View File
@@ -8,9 +8,4 @@ $(function() {
window.open($(this).attr("href"), "win_twitter", "menubar=1,resizable=1,width=600,height=350");
return false;
});
$(".share-googleplus").click(function() {
window.open($(this).attr("href"), "win_googleplus", "menubar=1,resizable=1,width=600,height=600");
return false;
});
});
+19 -10
View File
@@ -61,29 +61,38 @@ Class G5_object_cache {
$this->contents[$group][$key] = $data;
break;
default :
$datas = $this->etcs[$group][$key] = $data;
$this->etcs[$group][$key] = $data;
break;
}
}
/**
* cache 데이터 제거
* @param string $type
* @param string $key
* @param string $group
* @return bool
*/
function delete($type, $key, $group = 'default')
{
if (!$this->exists($type, $key, $group)) {
return false;
}
function delete($key, $group='default') {
switch ($key) {
switch ($type) {
case 'bbs':
$datas = $this->writes;
$datas = &$this->writes;
break;
case 'content':
$datas = $this->contents;
$datas = &$this->contents;
break;
default :
$datas = $this->etcs;
default:
$datas = &$this->etcs;
break;
}
if ( ! $this->exists('bbs', $key, $group) )
return false;
unset($datas[$group][$key]);
unset( $datas[$group][$key] );
return true;
}
+2 -2
View File
@@ -19,7 +19,7 @@ Class GML_Hook extends Hook {
$args = $this->getArguments($argsNumber, $args);
if (! ($class && $method) && function_exists($function)) {
if (! ($class && $method) && is_callable($function)) {
return call_user_func_array($function, $args);
} elseif ($obj = call_user_func(array($class, $this->singleton))) {
if ($obj !== false) {
@@ -161,4 +161,4 @@ Class GML_Hook extends Hook {
}
}
// end Hook Class;
// end Hook Class;
+396 -123
View File
@@ -9,11 +9,14 @@ include_once(dirname(__FILE__) .'/pbkdf2.compat.php');
**
*************************************************************************/
// 마이크로 타임을 얻어 계산 형식으로 만듦
/**
* 마이크로타임을 반환
* @return float
* @deprecated use `microtime(true)`
*/
function get_microtime()
{
list($usec, $sec) = explode(" ",microtime());
return ((float)$usec + (float)$sec);
return microtime(true);
}
@@ -23,6 +26,7 @@ function get_paging($write_pages, $cur_page, $total_page, $url, $add="")
//$url = preg_replace('#&amp;page=[0-9]*(&amp;page=)$#', '$1', $url);
$url = preg_replace('#(&amp;)?page=[0-9]*#', '', $url);
$url .= substr($url, -1) === '?' ? 'page=' : '&amp;page=';
$url = preg_replace('|[^\w\-~+_.?#=!&;,/:%@$\|*\'()\[\]\\x80-\\xff]|i', '', clean_xss_tags($url));
$str = '';
if ($cur_page > 1) {
@@ -96,6 +100,8 @@ function print_r2($var)
// header("location:URL") 을 대체
function goto_url($url)
{
run_event('goto_url', $url);
$url = str_replace("&amp;", "&", $url);
//echo "<script> location.replace('$url'); </script>";
@@ -144,11 +150,17 @@ function get_session($session_name)
// 쿠키변수 생성
function set_cookie($cookie_name, $value, $expire)
function set_cookie($cookie_name, $value, $expire, $path='/', $domain=G5_COOKIE_DOMAIN, $secure=false, $httponly=true)
{
global $g5;
$c = run_replace('set_cookie_params', array('path'=>$path, 'domain'=>$domain, 'secure'=>$secure, 'httponly'=>$httponly), $cookie_name);
if (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] != 'off') {
$c['secure'] = true;
}
setcookie(md5($cookie_name), base64_encode($value), G5_SERVER_TIME + $expire, '/', G5_COOKIE_DOMAIN);
setcookie(md5($cookie_name), base64_encode($value), G5_SERVER_TIME + $expire, $c['path'], $c['domain'], $c['secure'], $c['httponly']);
}
@@ -269,12 +281,12 @@ function url_auto_link($str)
// url에 http:// 를 붙인다
function set_http($url)
function set_http($url, $protocol="http://")
{
if (!trim($url)) return;
if (!preg_match("/^(http|https|ftp|telnet|news|mms)\:\/\//i", $url))
$url = "http://" . $url;
$url = $protocol. $url;
return $url;
}
@@ -295,6 +307,30 @@ function get_filesize($size)
return $size;
}
// 파일다운로드 링크 생성시 nonce 키 추가, 7200은 2시간동안 유효
function download_file_nonce_key($bo_table, $wr_id, $timeoutSeconds=7200)
{
$secret = get_token_encryption_key(sha1($bo_table.session_id().$wr_id));
$salt = get_random_token_string(10);
$maxTime = G5_SERVER_TIME + $timeoutSeconds;
$nonce = $salt . '|' . $maxTime . '|' . sha1($salt . $secret . $maxTime);
return $nonce;
}
// 파일다운로드시 nonce key를 체크한다.
function download_file_nonce_is_valid($nonce, $bo_table, $wr_id)
{
if (! is_string($nonce)) return false;
$secret = get_token_encryption_key(sha1($bo_table.session_id().$wr_id));
$a = explode('|', $nonce);
if (count($a) !== 3) return false;
list($salt, $maxTime, $hash) = $a;
if (sha1($salt . $secret . $maxTime) !== $hash) return false;
if (G5_SERVER_TIME > (int) $maxTime) return false;
return true;
}
// 게시글에 첨부된 파일을 얻는다. (배열로 반환)
function get_file($bo_table, $wr_id)
@@ -304,11 +340,12 @@ function get_file($bo_table, $wr_id)
$file['count'] = 0;
$sql = " select * from {$g5['board_file_table']} where bo_table = '$bo_table' and wr_id = '$wr_id' order by bf_no ";
$result = sql_query($sql);
$nonce = download_file_nonce_key($bo_table, $wr_id);
while ($row = sql_fetch_array($result))
{
$no = (int) $row['bf_no'];
$bf_content = $row['bf_content'] ? html_purifier($row['bf_content']) : '';
$file[$no]['href'] = G5_BBS_URL."/download.php?bo_table=$bo_table&amp;wr_id=$wr_id&amp;no=$no" . $qstr;
$file[$no]['href'] = G5_BBS_URL."/download.php?bo_table=$bo_table&amp;wr_id=$wr_id&amp;no=$no&amp;nonce=$nonce" . $qstr;
$file[$no]['download'] = $row['bf_download'];
// 4.00.11 - 파일 path 추가
$file[$no]['path'] = G5_DATA_URL.'/file/'.$bo_table;
@@ -572,44 +609,70 @@ function check_html_link_nofollow($type=''){
return true;
}
// http://htmlpurifier.org/
// Standards-Compliant HTML Filtering
// Safe : HTML Purifier defeats XSS with an audited whitelist
// Clean : HTML Purifier ensures standards-compliant output
// Open : HTML Purifier is open-source and highly customizable
/**
* HTMLPurifier 필터를 거친 HTML 코드를 반환
*
* http://htmlpurifier.org/
* Standards-Compliant HTML Filtering
* Safe : HTML Purifier defeats XSS with an audited whitelist
* Clean : HTML Purifier ensures standards-compliant output
* Open : HTML Purifier is open-source and highly customizable
*
* @param string $html
* @return string
*/
function html_purifier($html)
{
$f = file(G5_PLUGIN_PATH.'/htmlpurifier/safeiframe.txt');
global $is_admin, $write;
$f = file(G5_PLUGIN_PATH . '/htmlpurifier/safeiframe.txt');
$domains = array();
foreach($f as $domain){
foreach ($f as $domain) {
// 첫행이 # 이면 주석 처리
if (!preg_match("/^#/", $domain)) {
$domain = trim($domain);
if ($domain)
if ($domain) {
array_push($domains, $domain);
}
}
}
// 내 도메인도 추가
array_push($domains, $_SERVER['HTTP_HOST'].'/');
$safeiframe = implode('|', $domains);
// 글쓴이가 관리자인 경우에만 현재 사이트 도메인을 허용
if (isset($write['mb_id']) && $write['mb_id'] && is_admin($write['mb_id'])) {
array_push($domains, $_SERVER['HTTP_HOST'] . '/');
}
$safeiframe = implode('|', run_replace('html_purifier_safeiframes', $domains, $html));
include_once(G5_PLUGIN_PATH . '/htmlpurifier/HTMLPurifier.standalone.php');
include_once(G5_PLUGIN_PATH . '/htmlpurifier/extend.video.php');
include_once(G5_PLUGIN_PATH.'/htmlpurifier/HTMLPurifier.standalone.php');
include_once(G5_PLUGIN_PATH.'/htmlpurifier/extend.video.php');
$config = HTMLPurifier_Config::createDefault();
// data/cache 디렉토리에 CSS, HTML, URI 디렉토리 등을 만든다.
$config->set('Cache.SerializerPath', G5_DATA_PATH.'/cache');
$config->set('Cache.SerializerPath', G5_DATA_PATH . '/cache');
$config->set('HTML.SafeEmbed', false);
$config->set('HTML.SafeObject', false);
$config->set('Output.FlashCompat', false);
$config->set('HTML.SafeIframe', true);
if( (function_exists('check_html_link_nofollow') && check_html_link_nofollow('html_purifier')) ){
$config->set('HTML.Nofollow', true); // rel=nofollow 으로 스팸유입을 줄임
if ((function_exists('check_html_link_nofollow') && check_html_link_nofollow('html_purifier'))) {
$config->set('HTML.Nofollow', true); // rel=nofollow 으로 스팸유입을 줄임
}
$config->set('URI.SafeIframeRegexp','%^(https?:)?//('.$safeiframe.')%');
$config->set('URI.SafeIframeRegexp', '%^(https?:)?//(' . $safeiframe . ')%');
$config->set('Attr.AllowedFrameTargets', array('_blank'));
//유튜브, 비메오 전체화면 가능하게 하기
$config->set('Filter.Custom', array(new HTMLPurifier_Filter_Iframevideo()));
/*
* HTMLPurifier 설정을 변경할 수 있는 Event hook
* 리스너에서는 첫번째 인자($config)로 `HTMLPurifier_Config` 객체를 받을 수 있다
*/
run_event('html_purifier_config', $config, array(
'html' => $html,
'write' => $write,
'is_admin' => $is_admin
)
);
$purifier = new HTMLPurifier($config);
return run_replace('html_purifier_result', $purifier->purify($html), $purifier, $html);
}
@@ -737,7 +800,7 @@ function get_next_num($table)
$sql = " select min(wr_num) as min_wr_num from $table ";
$row = sql_fetch($sql);
// 가장 작은 번호에 1을 빼서 넘겨줌
return (int)($row['min_wr_num'] - 1);
return isset($row['min_wr_num']) ? (int)($row['min_wr_num'] - 1) : -1;
}
@@ -834,7 +897,10 @@ function subject_sort_link($col, $query_string='', $flag='asc')
$arr_query[] = 'page='.$page;
$qstr = implode("&amp;", $arr_query);
return "<a href=\"{$_SERVER['SCRIPT_NAME']}?{$qstr}\">";
parse_str(html_entity_decode($qstr), $qstr_array);
$url = short_url_clean(get_params_merge_url($qstr_array));
return '<a href="'.$url.'">';
}
@@ -1298,87 +1364,138 @@ function get_sideview($mb_id, $name='', $email='', $homepage='')
global $g5;
global $bo_table, $sca, $is_admin, $member;
$email = get_string_encrypt($email);
$homepage = set_http(clean_xss_tags($homepage));
static $cache = array();
$name = get_text($name, 0, true);
$email = get_text($email);
$name = get_text($name, 0, true);
if (isset($cache['id:' . $mb_id]) && $cache['id:' . $mb_id]) {
return $cache['id:' . $mb_id];
} else if (
isset($name)
&& isset($cache['name:' . $name])
&& $cache['name:' . $name]
) {
return $cache['name:' . $name];
}
$email = get_string_encrypt($email);
$email = get_text($email);
$homepage = set_http(clean_xss_tags($homepage));
$homepage = get_text($homepage);
$tmp_name = "";
$en_mb_id = $mb_id;
$name_tag = array();
$menus = array();
if ($mb_id) {
//$tmp_name = "<a href=\"".G5_BBS_URL."/profile.php?mb_id=".$mb_id."\" class=\"sv_member\" title=\"$name 자기소개\" rel="nofollow" target=\"_blank\" onclick=\"return false;\">$name</a>";
$tmp_name = '<a href="'.G5_BBS_URL.'/profile.php?mb_id='.$mb_id.'" class="sv_member" title="'.$name.' 자기소개" target="_blank" rel="nofollow" onclick="return false;">';
// $tmp_name = "<a href=\"".G5_BBS_URL."/profile.php?mb_id=".$mb_id."\" class=\"sv_member\" title=\"$name 자기소개\" rel="nofollow" target=\"_blank\" onclick=\"return false;\">$name</a>";
$name_tag_open = '<a href="' . G5_BBS_URL . '/profile.php?mb_id=' . $mb_id . '" class="sv_member" title="' . $name . ' 자기소개" target="_blank" rel="nofollow" onclick="return false;">';
if ($config['cf_use_member_icon']) {
$mb_dir = substr($mb_id,0,2);
$icon_file = G5_DATA_PATH.'/member/'.$mb_dir.'/'.get_mb_icon_name($mb_id).'.gif';
$mb_dir = substr($mb_id, 0, 2);
$icon_file = G5_DATA_PATH . '/member/' . $mb_dir . '/' . get_mb_icon_name($mb_id) . '.gif';
if (file_exists($icon_file)) {
$icon_filemtile = (defined('G5_USE_MEMBER_IMAGE_FILETIME') && G5_USE_MEMBER_IMAGE_FILETIME) ? '?'.filemtime($icon_file) : '';
$icon_filemtile = (defined('G5_USE_MEMBER_IMAGE_FILETIME') && G5_USE_MEMBER_IMAGE_FILETIME) ? '?' . filemtime($icon_file) : '';
$width = $config['cf_member_icon_width'];
$height = $config['cf_member_icon_height'];
$icon_file_url = G5_DATA_URL.'/member/'.$mb_dir.'/'.get_mb_icon_name($mb_id).'.gif'.$icon_filemtile;
$tmp_name .= '<span class="profile_img"><img src="'.$icon_file_url.'" width="'.$width.'" height="'.$height.'" alt=""></span>';
$icon_file_url = G5_DATA_URL . '/member/' . $mb_dir . '/' . get_mb_icon_name($mb_id) . '.gif' . $icon_filemtile;
$name_tag['profile_image'] = '<span class="profile_img"><img src="' . $icon_file_url . '" width="' . $width . '" height="' . $height . '" alt=""></span>';
if ($config['cf_use_member_icon'] == 2) // 회원아이콘+이름
$tmp_name = $tmp_name.' '.$name;
// 회원아이콘+이름
if ($config['cf_use_member_icon'] == 2) {
$name_tag['name'] = $name;
}
} else {
if( defined('G5_THEME_NO_PROFILE_IMG') ){
$tmp_name .= G5_THEME_NO_PROFILE_IMG;
} else if( defined('G5_NO_PROFILE_IMG') ){
$tmp_name .= G5_NO_PROFILE_IMG;
if (defined('G5_THEME_NO_PROFILE_IMG')) {
$name_tag['profile_image'] = G5_THEME_NO_PROFILE_IMG;
} else if (defined('G5_NO_PROFILE_IMG')) {
$name_tag['profile_image'] = G5_NO_PROFILE_IMG;
}
// 회원아이콘+이름
if ($config['cf_use_member_icon'] == 2) {
$name_tag['name'] = $name;
}
if ($config['cf_use_member_icon'] == 2) // 회원아이콘+이름
$tmp_name = $tmp_name.' '.$name;
}
} else {
$tmp_name = $tmp_name.' '.$name;
$name_tag['name'] = $name;
}
$tmp_name .= '</a>';
$title_mb_id = '['.$mb_id.']';
} else {
if(!$bo_table)
if (!$bo_table) {
return $name;
}
$tmp_name = '<a href="'.get_pretty_url($bo_table, '', 'sca='.$sca.'&amp;sfl=wr_name,1&amp;stx='.$name).'" title="'.$name.' 이름으로 검색" class="sv_guest" rel="nofollow" onclick="return false;">'.$name.'</a>';
$title_mb_id = '[비회원]';
$name_tag_open = '<a href="' . get_pretty_url($bo_table, '', 'sca=' . $sca . '&amp;sfl=wr_name,1&amp;stx=' . $name) . '" title="' . $name . ' 이름으로 검색" class="sv_guest" rel="nofollow" onclick="return false;">';
$name_tag['name'] = $name;
}
$str = "<span class=\"sv_wrap\">\n";
$str .= $tmp_name."\n";
if ($mb_id) {
$menus['memo'] = '<a href="' . G5_BBS_URL . '/memo_form.php?me_recv_mb_id=' . $mb_id . '" rel="nofollow" onclick="win_memo(this.href); return false;">쪽지보내기</a>';
}
$str2 = "<span class=\"sv\">\n";
if($mb_id)
$str2 .= "<a href=\"".G5_BBS_URL."/memo_form.php?me_recv_mb_id=".$mb_id."\" onclick=\"win_memo(this.href); return false;\">쪽지보내기</a>\n";
if($email)
$str2 .= "<a href=\"".G5_BBS_URL."/formmail.php?mb_id=".$mb_id."&amp;name=".urlencode($name)."&amp;email=".$email."\" onclick=\"win_email(this.href); return false;\">메일보내기</a>\n";
if($homepage)
$str2 .= "<a href=\"".$homepage."\" target=\"_blank\">홈페이지</a>\n";
if($mb_id)
$str2 .= "<a href=\"".G5_BBS_URL."/profile.php?mb_id=".$mb_id."\" onclick=\"win_profile(this.href); return false;\">자기소개</a>\n";
if($bo_table) {
if($mb_id) {
$str2 .= "<a href=\"".get_pretty_url($bo_table, '', "sca=".$sca."&amp;sfl=mb_id,1&amp;stx=".$en_mb_id)."\">아이디로 검색</a>\n";
if ($email) {
$menus['email'] = '<a href="' . G5_BBS_URL . '/formmail.php?mb_id=' . $mb_id . '&amp;name=' . urlencode($name) . '&amp;email=' . $email . '" onclick="win_email(this.href); return false;" rel="nofollow">메일보내기</a>';
}
if ($homepage) {
$menus['homepage'] = '<a href="' . $homepage . '" rel="nofollow noopener" target="_blank">홈페이지</a>';
}
if ($mb_id) {
$menus['profile'] = '<a href="' . G5_BBS_URL . '/profile.php?mb_id=' . $mb_id . '" onclick="win_profile(this.href); return false;" rel="nofollow">자기소개</a>';
}
if ($bo_table) {
if ($mb_id) {
$menus['search_id'] = '<a href="' . get_pretty_url($bo_table, '', 'sca=' . $sca . '&amp;sfl=mb_id,1&amp;stx=' . $en_mb_id) . '" rel="nofollow">아이디로 검색</a>';
} else {
$str2 .= "<a href=\"".get_pretty_url($bo_table, '', "sca=".$sca."&amp;sfl=wr_name,1&amp;stx=".$name)."\">이름으로 검색</a>\n";
$menus['search_name'] = '<a href="' . get_pretty_url($bo_table, '', 'sca=' . $sca . '&amp;sfl=wr_name,1&amp;stx=' . $name) . '" rel="nofollow">이름으로 검색</a>';
}
}
if($mb_id)
$str2 .= "<a href=\"".G5_BBS_URL."/new.php?mb_id=".$mb_id."\" class=\"link_new_page\" onclick=\"check_goto_new(this.href, event);\">전체게시물</a>\n";
if($is_admin == "super" && $mb_id) {
$str2 .= "<a href=\"".G5_ADMIN_URL."/member_form.php?w=u&amp;mb_id=".$mb_id."\" target=\"_blank\">회원정보변경</a>\n";
$str2 .= "<a href=\"".G5_ADMIN_URL."/point_list.php?sfl=mb_id&amp;stx=".$mb_id."\" target=\"_blank\">포인트내역</a>\n";
}
$str2 .= "</span>\n";
$str .= $str2;
$str .= "\n<noscript class=\"sv_nojs\">".$str2."</noscript>";
if ($mb_id) {
$menus['search_all'] = '<a href="' . G5_BBS_URL . '/new.php?mb_id=' . $mb_id . '" class="link_new_page" onclick="check_goto_new(this.href, event);" rel="nofollow">전체게시물</a>';
if ($is_admin == 'super') {
$menus['admin_member_modify'] = '<a href="' . G5_ADMIN_URL . '/member_form.php?w=u&amp;mb_id=' . $mb_id . '" target="_blank" rel="nofollow">회원정보변경</a>';
$menus['admin_member_point'] = '<a href="' . G5_ADMIN_URL . '/point_list.php?sfl=mb_id&amp;stx=' . $mb_id . '" target="_blank" rel="nofollow">포인트내역</a>';
}
}
$name_tag_close = '</a>';
$items = run_replace('member_sideview_items', array(
'name_tag_open' => $name_tag_open,
'name_tag_close' => $name_tag_close,
'name_tag' => $name_tag,
'menus' => $menus
), array(
'mb_id' => $mb_id,
'name' => $name,
'bo_table' => $bo_table,
)
);
$str = '<span class="sv_wrap">';
$str .= $items['name_tag_open'] . implode(' ', $items['name_tag']) . $items['name_tag_close'];
$str2 = '<span class="sv">';
$str2 .= implode("\n", $items['menus']);
$str2 .= '</span>';
$str .= $str2;
$str .= '<noscript class="sv_nojs">' . $str2 . '</noscript>';
$str .= "</span>";
if ($mb_id) {
$cache['id:' . $mb_id] = $str;
} else {
$cache['name:' . $name] = $str;
}
return $str;
}
@@ -1577,10 +1694,6 @@ function sql_data_seek($result, $offset=0)
mysql_data_seek($result, $offset);
}
function _callback_sql_show_tables($m){
return "show tables like '".str_replace("`", "", $m[1])."'";
}
// mysqli_query 와 mysqli_error 를 한꺼번에 처리
// mysql connect resource 지정 - 명랑폐인님 제안
function sql_query($sql, $error=G5_DISPLAY_SQL_ERROR, $link=null)
@@ -1598,13 +1711,9 @@ function sql_query($sql, $error=G5_DISPLAY_SQL_ERROR, $link=null)
// `information_schema` DB로의 접근을 허락하지 않습니다.
$sql = preg_replace("#^select.*from.*where.*`?information_schema`?.*#i", "select 1", $sql);
if (preg_match("#^desc(?:ribe)?\s+(.*)#i", $sql)) {
$sql = preg_replace_callback("#^desc(?:ribe)?\s+(.*)#i", '_callback_sql_show_tables', trim($sql));
}
$is_debug = get_permission_debug_show();
$start_time = $is_debug ? get_microtime() : 0;
$start_time = ($is_debug || G5_COLLECT_QUERY) ? get_microtime() : 0;
if(function_exists('mysqli_query') && G5_MYSQLI_USE) {
if ($error) {
@@ -1624,18 +1733,68 @@ function sql_query($sql, $error=G5_DISPLAY_SQL_ERROR, $link=null)
}
}
$end_time = $is_debug ? get_microtime() : 0;
$end_time = ($is_debug || G5_COLLECT_QUERY) ? get_microtime() : 0;
$error = null;
$source = array();
if ($is_debug || G5_COLLECT_QUERY) {
if(function_exists('mysqli_error') && G5_MYSQLI_USE) {
$error = array(
'error_code' => mysqli_errno($link),
'error_message' => mysqli_error($link),
);
} else {
$error = array(
'error_code' => mysql_errno($link),
'error_message' => mysql_error($link),
);
}
$stack = debug_backtrace(DEBUG_BACKTRACE_IGNORE_ARGS);
$found = false;
foreach ($stack as $index => $trace) {
if ($trace['function'] === 'sql_query') {
$found = true;
}
if (isset($stack[$index + 1]) && $stack[$index + 1]['function'] === 'sql_fetch') {
continue;
}
if ($found) {
$trace['file'] = str_replace($_SERVER['DOCUMENT_ROOT'], '', $trace['file']);
$source['file'] = $trace['file'];
$source['line'] = $trace['line'];
$parent = (isset($stack[$index + 1])) ? $stack[$index + 1] : array();
if (isset($parent['function'])) {
if (in_array($trace['function'], array('sql_query', 'sql_fetch')) && (isset($parent['function']) && !in_array($parent['function'], array('sql_fetch', 'include', 'include_once', 'require', 'require_once')))) {
if (isset($parent['class']) && $parent['class']) {
$source['class'] = $parent['class'];
$source['function'] = $parent['function'];
$source['type'] = $parent['type'];
} else {
$source['function'] = $parent['function'];
}
}
}
break;
}
}
if($result && $is_debug) {
// 여기에 실행한 sql문을 화면에 표시하는 로직 넣기
$g5_debug['sql'][] = array(
'sql' => $sql,
'result' => $result,
'success' => !!$result,
'source' => $source,
'error_code' => $error['error_code'],
'error_message' => $error['error_message'],
'start_time' => $start_time,
'end_time' => $end_time,
);
);
}
run_event('sql_query_after', $result, $sql, $start_time, $end_time);
run_event('sql_query_after', $result, $sql, $start_time, $end_time, $error, $source);
return $result;
}
@@ -1688,11 +1847,22 @@ function sql_free_result($result)
}
/**
* MySQL PASSWORD() 함수로 생성된 비밀번호의 hash 값을 반환
*
* MySQL 버전에 따라 결과가 다르게 나올 수 있음.
* MySQL 8.0.11 버전 이상에서는 오류 발생(PASSWORD 함수가 제거됨)으로 사용할 수 없음.
*
* @deprecated 이 함수는 안전하지 않으므로 사용하지 않는 것을 권장 함
* @see get_encrypt_string() and check_password()
* @param string $value
* @return string
*/
function sql_password($value)
{
// mysql 4.0x 이하 버전에서는 password() 함수의 결과가 16bytes
// mysql 4.1x 이상 버전에서는 password() 함수의 결과가 41bytes
$row = sql_fetch(" select password('$value') as pass ");
$row = sql_fetch(" SELECT password('{$value}') as pass ");
return $row['pass'];
}
@@ -2100,6 +2270,53 @@ function check_token()
return true;
}
/**
* 브라우저 검증을 위한 세션 반환 및 재생성
* @param array $member 로그인 된 회원의 정보. 가입일시(mb_datetime)를 반드시 포함해야 한다.
* @param bool $regenerate true 이면 재생성
* @return string
*/
function ss_mb_key($member, $regenerate = false)
{
$client_key = ($regenerate) ? null : get_cookie('mb_client_key');
if (!$client_key) {
$client_key = get_random_token_string(16);
set_cookie('mb_client_key', $client_key, G5_SERVER_TIME * -1);
}
$mb_key = md5($member['mb_datetime'] . $client_key) . run_replace('ss_mb_key_user_agent', md5($_SERVER['HTTP_USER_AGENT']));
return $mb_key;
}
/**
* 회원의 클라이언트 검증
* @param array $member 로그인 된 회원의 정보. 가입일시(mb_datetime)를 반드시 포함해야 한다.
* @return bool
*/
function verify_mb_key($member)
{
$mb_key = ss_mb_key($member);
$verified = get_session('ss_mb_key') === $mb_key;
if (!$verified) {
ss_mb_key($member, true);
}
return $verified;
}
/**
* 회원의 클라이언트 검증 키 생성
* 클라이언트 키를 다시 생성하여 생성된 키는 `ss_mb_key` 세션에 저장됨
* @param array $member 로그인 된 회원의 정보. 가입일시(mb_datetime)를 반드시 포함해야 한다.
*/
function generate_mb_key($member)
{
$mb_key = ss_mb_key($member, true);
set_session('ss_mb_key', $mb_key);
}
// 문자열에 utf8 문자가 들어 있는지 검사하는 함수
// 코드 : http://in2.php.net/manual/en/function.mb-check-encoding.php#95289
@@ -2309,14 +2526,19 @@ function check_device($device)
}
// 게시판 최신글 캐시 파일 삭제
/**
* 게시판 최신글 캐시 파일 삭제
* @param string $bo_table 게시판 ID
*/
function delete_cache_latest($bo_table)
{
if (!preg_match("/^([A-Za-z0-9_]{1,20})$/", $bo_table)) {
return;
}
g5_delete_cache_by_prefix('latest-'.$bo_table.'-');
run_event('delete_cache_latest', $bo_table);
g5_delete_cache_by_prefix('latest-' . $bo_table . '-');
}
// 게시판 첨부파일 썸네일 삭제
@@ -2492,37 +2714,61 @@ function get_skin_javascript($skin_path, $dir='')
return $str;
}
if (!function_exists('get_called_class')) {
function get_called_class() {
$bt = debug_backtrace();
$lines = file($bt[1]['file']);
preg_match(
'/([a-zA-Z0-9\_]+)::'.$bt[1]['function'].'/',
$lines[$bt[1]['line']-1],
$matches
);
return $matches[1];
}
}
function get_html_process_cls() {
return html_process::getInstance();
}
// HTML 마지막 처리
function html_end()
{
global $html_process;
return $html_process->run();
return get_html_process_cls()->run();
}
function add_stylesheet($stylesheet, $order=0)
{
global $html_process;
if(trim($stylesheet) && method_exists($html_process, 'merge_stylesheet') )
$html_process->merge_stylesheet($stylesheet, $order);
if(trim($stylesheet))
get_html_process_cls()->merge_stylesheet($stylesheet, $order);
}
function add_javascript($javascript, $order=0)
{
global $html_process;
if(trim($javascript) && method_exists($html_process, 'merge_javascript') )
$html_process->merge_javascript($javascript, $order);
if(trim($javascript))
get_html_process_cls()->merge_javascript($javascript, $order);
}
class html_process {
protected $css = array();
protected $js = array();
protected static $id = '0';
private static $instances = array();
protected static $is_end = '0';
protected static $css = array();
protected static $js = array();
function merge_stylesheet($stylesheet, $order)
public static function getInstance($id = '0')
{
$links = $this->css;
self::$id = $id;
if (isset(self::$instances[self::$id])) {
return self::$instances[self::$id];
}
$calledClass = get_called_class();
return self::$instances[self::$id] = new $calledClass;
}
public static function merge_stylesheet($stylesheet, $order)
{
$links = self::$css;
$is_merge = true;
foreach($links as $link) {
@@ -2533,12 +2779,12 @@ class html_process {
}
if($is_merge)
$this->css[] = array($order, $stylesheet);
self::$css[] = array($order, $stylesheet);
}
function merge_javascript($javascript, $order)
public static function merge_javascript($javascript, $order)
{
$scripts = $this->js;
$scripts = self::$js;
$is_merge = true;
foreach($scripts as $script) {
@@ -2549,13 +2795,17 @@ class html_process {
}
if($is_merge)
$this->js[] = array($order, $javascript);
self::$js[] = array($order, $javascript);
}
function run()
public static function run()
{
global $config, $g5, $member;
if (self::$is_end) return; // 여러번 호출해도 한번만 실행되게 합니다.
self::$is_end = 1;
// 현재접속자 처리
$tmp_sql = " select count(*) as cnt from {$g5['login_table']} where lo_ip = '{$_SERVER['REMOTE_ADDR']}' ";
$tmp_row = sql_fetch($tmp_sql);
@@ -2580,7 +2830,7 @@ class html_process {
ob_end_clean();
$stylesheet = '';
$links = $this->css;
$links = self::$css;
if(!empty($links)) {
foreach ($links as $key => $row) {
@@ -2604,7 +2854,7 @@ class html_process {
}
$javascript = '';
$scripts = $this->js;
$scripts = self::$js;
$php_eol = '';
unset($order);
@@ -2638,7 +2888,12 @@ class html_process {
<link rel="stylesheet" href="default.css">
밑으로 스킨의 스타일시트가 위치하도록 하게 한다.
*/
$buffer = preg_replace('#(</title>[^<]*<link[^>]+>)#', "$1$stylesheet", $buffer);
$title_find_pattern = '#(</title>[^<]*<link[^>]+>)#';
if (preg_match($title_find_pattern, $buffer)) {
$buffer = preg_replace($title_find_pattern, "$1$stylesheet", $buffer);
} else { // 패턴이 없다면 자바스크립트 코드 위에 위치하게 합니다.
$javascript = $stylesheet. PHP_EOL. $javascript;
}
/*
</head>
@@ -2661,6 +2916,8 @@ class html_process {
$buffer = preg_replace('#(<title[^>]*>.*?</title>)#', "$meta_tag{$nl}$1", $buffer);
}
$buffer = run_replace('html_process_buffer', $buffer);
return $buffer;
}
}
@@ -3343,12 +3600,18 @@ function check_url_host($url, $msg='', $return_url=G5_URL, $is_redirect=false)
if(!$msg)
$msg = 'url에 타 도메인을 지정할 수 없습니다.';
if(run_replace('check_url_host_before', '', $url, $msg, $return_url, $is_redirect) === 'is_checked'){
return;
}
// KVE-2021-1277 Open Redirect 취약점 해결
if (preg_match('#\\\0#', $url)) {
alert('url 에 올바르지 않은 값이 포함되어 있습니다.');
}
$url = urldecode($url);
while ( ( $replace_url = preg_replace(array('/\/{2,}/', '/\\@/'), array('//', ''), urldecode($url)) ) != $url ) {
$url = $replace_url;
}
$p = @parse_url(trim($url));
$host = preg_replace('/:[0-9]+$/', '', $_SERVER['HTTP_HOST']);
$is_host_check = false;
@@ -3393,7 +3656,7 @@ function check_url_host($url, $msg='', $return_url=G5_URL, $is_redirect=false)
if ((isset($p['scheme']) && $p['scheme']) || (isset($p['host']) && $p['host']) || $is_host_check) {
//if ($p['host'].(isset($p['port']) ? ':'.$p['port'] : '') != $_SERVER['HTTP_HOST']) {
if ( ($p['host'] != $host) || $is_host_check ) {
if (run_replace('check_same_url_host', (($p['host'] != $host) || $is_host_check), $p, $host, $is_host_check, $return_url, $is_redirect)) {
echo '<script>'.PHP_EOL;
echo 'alert("url에 타 도메인을 지정할 수 없습니다.");'.PHP_EOL;
echo 'document.location.href = "'.$return_url.'";'.PHP_EOL;
@@ -3608,7 +3871,7 @@ function check_vaild_callback($callback){
class str_encrypt
{
var $salt;
var $lenght;
var $length;
function __construct($salt='')
{
@@ -3927,6 +4190,16 @@ function is_include_path_check($path='', $is_input='')
return true;
}
function is_inicis_url_return($url){
$url_data = parse_url($url);
// KG 이니시스 url이 맞는지 체크하여 맞으면 url을 리턴하고 틀리면 '' 빈값을 리턴합니다.
if (isset($url_data['host']) && preg_match('#\.inicis\.com$#i', $url_data['host'])) {
return $url;
}
return '';
}
function check_auth_session_token($str=''){
if (get_session('ss_mb_token_key') === get_token_encryption_key($str)) {
return true;
@@ -3951,13 +4224,13 @@ function get_random_token_string($length=6)
}
$characters = '0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz';
$output = substr(str_shuffle($characters), 0, $length); // jihan001 님 제안코드로 수정
$output = substr(str_shuffle($characters), 0, $length);
return bin2hex($output);
}
function filter_input_include_path($path){
return str_replace('//', '/', $path);
return str_replace('//', '/', strip_tags($path));
}
function option_array_checked($option, $arr=array()){
+2 -2
View File
@@ -65,7 +65,7 @@ function run_event($tag, $arg = ''){
}
}
function add_replace($tag, $func, $priority=G5_HOOK_DEFAULT_PRIORITY, $args=0){
function add_replace($tag, $func, $priority=G5_HOOK_DEFAULT_PRIORITY, $args=1){
if( $hook = get_hook_class() ){
return $hook->addFilter($tag, $func, $priority, $args);
@@ -130,4 +130,4 @@ function get_hook_datas($type='', $is_callback=''){
}
return null;
}
}

Some files were not shown because too many files have changed in this diff Show More