Compare commits

...
216 Commits
Author SHA1 Message Date
thisgun 0b6f081f76 버전 5.6.34 수정 2026-07-24 07:14:18 +00:00
thisgunandClaude Fable 5 adbd9c3acc KG이니시스 PRO 현황 부분취소 전액환불 종결 판정 추가
- 부분취소 합계로 전액 환불되고 주문도 취소된 거래는 일치 상태로 판정
- 현황 목록 필터·KG 대사·관리자 알림에 동일 기준 적용

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 07:11:51 +00:00
thisgunandClaude Fable 5 8fcbd2a9b1 INIpay PRO 주문 전체취소 흐름 개선
- 부분취소 이력이 있는 주문은 잔여 금액을 부분취소로 처리해 전체취소 지원
- 부분취소로 전액 환불된 주문과 KG에서 이미 취소된 주문은 주문 취소만 진행
- PG 승인취소 미선택 시 차단하지 않고 주문만 취소하며 처리 내용을 이력에 기록
- 남은 품목 취소로 주문 전체가 취소되는 경우에도 PG 취소 여부 확인창 표시

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 07:11:51 +00:00
thisgunandClaude Fable 5 f8c06a26cb 관리자 부분취소 팝업 처리 오류 수정
- 팝업에서 admin.js와 토큰키를 로드해 처리 요청이 검증을 통과하도록 수정
- 금액 입력 유효성 검사의 필드명 오타 수정

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 07:11:51 +00:00
thisgunandClaude Fable 5 1fd5ec46ae KG이니시스 PRO 현황 안내 문구 정비
- 안내 문구의 로컬 표현을 영카트로 통일
- PG와 영카트 주문이 모두 취소 상태로 일치하면 조치 불필요 문구 출력

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 06:25:17 +00:00
thisgunandClaude Fable 5 cbd70fbe18 KG이니시스 상점관리자에서 먼저 취소한 INIpay PRO 주문의 전체취소 허용
- 전체취소 전에 KG 거래상태를 조회해 이미 취소된 거래이면 주문 취소만 진행
- 조회 결과와 처리 사유를 결제 현황 이력에 기록

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 06:25:17 +00:00
thisgunandClaude Fable 5 bc07b8383e KG이니시스 INIpay PRO 주문자 이메일 확인 후 전달
- 주문서/개인결제 결제 시작 시 이메일 형식을 확인해 잘못된 경우 안내 후 중단
- 결제창 요청에서는 확인된 이메일만 선택 항목으로 전달해 결제가 막히지 않게 처리

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-24 06:25:17 +00:00
thisgunandClaude Opus 4.8 23c60a8ba1 SMS 아이코드 신청 링크 최신 경로로 교체
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-24 05:28:15 +00:00
thisgunandClaude Opus 4.8 abb777016d 부가서비스 신청 링크 최신화 및 나이스페이먼츠 추가
- 전자결제/본인확인/SMS 신청 링크를 sir.kr 최신 경로로 교체
- 신용카드 전자결제에 나이스페이먼츠 추가(4개 1열 배치, 카드 폭 조정)
- 나이스페이먼츠 신청 버튼 이미지 추가

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-24 05:19:41 +00:00
thisgun e45bd1d9e1 버전 5.6.33 수정 2026-07-24 01:04:31 +00:00
thisgunandClaude Fable 5 acdbcfd8ba KG이니시스 INIpay PRO 결제 연동 및 결제 처리 현황 추가
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 08:03:16 +00:00
thisgun 1f48f6bd80 버전 5.6.32 수정 2026-07-14 02:35:52 +00:00
thisgun 87d86d317e 소셜 로그인 앱 등록 링크 최신화 2026-07-13 08:55:10 +00:00
thisgun 7fa554f396 XSS 취약점 수정 2026-07-13 07:38:27 +00:00
thisgunandClaude Opus 4.8 6bc322c9d6 회원 여분필드 저장 시 입력값 정제 보완
- register_form_update.php에서 mb_1~mb_10을 다른 회원필드(mb_name 등)와
  동일하게 clean_xss_tags 처리하여 저장하도록 보완

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 07:36:19 +00:00
thisgun 43fba4407d [KVE-2025-1533] 미결제내역 임시주문 데이터 출력 시 이스케이프 보완 2026-07-13 07:36:19 +00:00
thisgunandClaude Opus 4.8 3d7fa04569 관리자 상태변경 엔드포인트에 요청 출처 검증 추가
- 상품이벤트/개인결제복사/SMS 번호·그룹·폼·업로드/방문로그 삭제 등
  POST 기반 상태변경 처리에 check_request_origin() 적용 (스킨 수정 불필요)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-13 07:20:32 +00:00
thisgun 82ee3ef438 [KVE-1525] SMS 번호·이모티콘 이동 처리 권한 속성 보완 2026-07-13 07:20:32 +00:00
thisgun 4049c6c164 [KVE-1524] 주문 상태변경 관리자 엔드포인트에 메뉴 권한 검증 추가 2026-07-13 07:15:09 +00:00
thisgun f80ed3946f Fix monthly visit date range end date 2026-07-01 08:41:11 +00:00
thisgunandClaude Opus 4.8 d7d5f26524 [KVE-2026-1233]취약점- 게시글 조회 시 wr_id 정수 처리 보완
- get_write() 진입 시 wr_id를 정수로 캐스팅하여 SQL 조건에 비정상 값이 전달되지 않도록 보완

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-30 02:05:11 +00:00
thisgun e0a42d8f46 버전 5.6.31 수정 2026-06-26 10:50:29 +00:00
thisgun 6c6787ec1f 상품 스킨 디렉토리 검증 보완 2026-06-26 10:40:28 +00:00
thisgunandClaude Opus 4.8 d419f430a9 [KVE-20206-1176]XSS 취약점 - 결제 전 주문 임시데이터 저장 요청 출처 검증 추가
- shop/ajax.orderdatasave.php에 check_request_origin() 적용하여
  외부 사이트발 자동 요청에 의한 임시 주문 데이터 교체 차단

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-24 07:10:24 +00:00
thisgunandClaude Opus 4.8 1a5661a995 접속자검색 접속경로 출력 시 속성값 이스케이프 보완
- vi_referer 디코딩 후 title 속성에 출력할 때 따옴표를 이스케이프하도록 보완

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 00:52:40 +00:00
thisgunandClaude Opus 4.8 8a5767dc70 [KVE-2026-1176]취약점수정 - 관리자 목록 정렬 파라미터 화이트리스트 적용 보완
- member_list·index·couponzonelist·inorderlist·personalpaylist의
  정렬 컬럼/방향 값을 허용 목록으로 제한하여 ORDER BY 절에 임의 값 삽입 차단
- 기존 다른 목록 파일과 동일한 in_array 화이트리스트 패턴 적용

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 00:48:42 +00:00
thisgunandClaude Opus 4.8 935ea84c7c [KVE-2026-1122]취약점 수정 - 주문·관리자·결제·소셜 등 사용자 입력 처리 보완
- 쿠폰/희망배송일/검색어/계정/결제 콜백 등 입력값을 SQL 컨텍스트에 맞게 재처리
- dt_data·PG 응답 등 비-GPC 값과 소셜 provider 입력 정제 보완

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 00:36:35 +00:00
thisgun 1cade844fb chore: allow CRLF in PHP whitespace checks 2026-06-22 08:30:20 +00:00
thisgun dfca17a599 버전 5.6.30 수정 2026-06-16 03:33:14 +00:00
thisgun 5ed691136d 나이스페이 가상계좌 취소금액 보정 2026-06-16 03:26:42 +00:00
thisgun cdda832081 Fix register form member defaults 2026-06-16 03:26:42 +00:00
thisgun 5374fb5f74 NHN KCP 본인확인 v2 설정 안내 보완 2026-06-16 03:17:44 +00:00
thisgun 16a8dca6f7 버전 5.6.29 수정 2026-06-09 02:34:30 +00:00
thisgun b00fc18275 Merge branch 'master' into tmp_install 2026-06-09 02:27:41 +00:00
thisgun 0c6ff731f6 관리권한 부여 목록에서 최고관리자 전용 메뉴 제외 2026-06-09 02:26:01 +00:00
thisgun 77835010df 메일 테스트 발송 안내 개선 2026-06-09 02:26:01 +00:00
thisgunandClaude Opus 4.8 33416852fc 나이스페이 가상계좌 채번 시 od_app_no 누락 수정
가상계좌(4100) 채번 시 od_app_no가 빈 AuthCode로 남아
입금통보 매칭(od_app_no = VbankNum)이 실패하던 문제 수정

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-09 01:34:33 +00:00
thisgun 3a4612420c Improve installer validation and error handling 2026-06-08 02:09:17 +00:00
thisgunandClaude Opus 4.8 6a55f1457d 현재접속자 처리 시 카운트 접근 null 보정 (PHP 8 호환)
html_process 의 접속자 처리에서 count 조회 결과 접근을 empty() 로
보정. 쿼리 실패 등 비정상 상황에서 빈 배열/undefined 키 접근으로
PHP 8.0+ 경고가 나는 경우를 예방. 동작 변화 없음.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 07:32:50 +00:00
thisgunandClaude Opus 4.8 76d83c2bae 게시판 정렬 필드 화이트리스트 검증 추가
게시판 설정의 bo_sort_field 가 허용 목록 검증 없이 저장·사용되어
목록 조회 ORDER BY 절에 임의 표현식이 들어갈 수 있던 문제 수정.
정렬값은 따옴표로 감싸지 않아 escape 로 막히지 않으므로,
게시판 관리 권한 계정이 저장한 값이 비로그인 목록 조회에서
실행될 수 있었음.

get_board_sort_fields() 의 허용 목록(관리자 드롭다운과 동일)으로
저장(adm/board_form_update.php)과 사용(bbs/list.php) 양쪽을 검증.
허용 목록 외 값은 기본 정렬로 무력화하여 이미 저장된 값도 차단.
function_exists 가드로 부분 패치 환경 대비.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 07:20:58 +00:00
thisgunandClaude Opus 4.8 afd8b35423 SMS 회원정보 업데이트 토큰 방식 불일치 수정
member_update.php 가 get_token()(HMAC) 으로 발급한 토큰을
member_update_run.php 가 check_admin_token()(세션) 으로 검증해
항상 불일치 → 오류 HTML 반환으로 AJAX JSON 파싱이 실패하던 문제 수정.

sms_admin 의 다른 _run 들과 동일하게 검증측(check_admin_token)은
유지하고, 실행 시 ajax.token.php 로 세션 토큰을 발급받아 본 요청에
사용하도록 변경. check_admin_token 의 1회용 소거 특성상 재실행에도
견고함.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 08:22:03 +00:00
thisgunandClaude Opus 4.8 e7c89675b6 회원관리/비디오 필터 null 인자 보정 (PHP 8.1 호환)
내장함수에 null 이 전달되어 PHP 8.1+ 에서 경고가 발생하던 것을
isset 삼항 / 문자열 캐스팅으로 보정.

- adm/member_form.php: number_format(mb_point), substr(mb_id) 2곳,
  substr(mp_register_day) — null/미정의 시 0 또는 빈 문자열 처리
- plugin/htmlpurifier/extend.video.php: strstr 인자 (string) 캐스팅

표시·동작 변화 없음. PHP 5.2~8.3 호환 유지(?? 미사용).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-02 07:55:39 +00:00
thisgun 10c6c18857 Fix JavaScript alert string escaping 2026-06-01 10:26:44 +00:00
thisgun 3e002199d5 버전 5.6.28 수정 2026-06-01 03:40:35 +00:00
thisgunandClaude Opus 4.8 7dde02d396 SMS 모듈 Add/Add2 매개변수 기본값 보정 (PHP 8 호환)
기본값 있는 $strDate 뒤에 기본값 없는 $nCount 가 선언되어 PHP 8.0+
에서 경고가 발생하던 것을 $nCount=0 기본값 부여로 해소.

- plugin/sms5/sms5.lib.php: Add(), Add2()
- lib/icode.lms.lib.php: Add() (LMS 부모 클래스 동일 패턴)

LMS 분기 호출부는 $strDate, $nCount 를 항상 함께 전달하므로
동작 변화 없음. PHP 5.2~8.3 호환 유지.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-01 01:02:26 +00:00
thisgunandClaude Opus 4.8 31871ee3e6 [security] 주문자 휴대폰 출력 인코딩 및 리다이렉트 URL 호스트 검증
- adm/shop_admin/orderform.php: 주문상세 hidden 의 od_hp 출력에
  get_text() 적용 (인접한 od_name 과 동일 처리, 누락분 보완)
- bbs/member_cert_refresh_update.php: 본인확인 갱신 후 이동 URL 에
  check_url_host() 적용
- plugin/social/includes/functions.php: 소셜 로그인/연동 후 이동
  URL 2곳에 동일하게 check_url_host() 적용

login_check.php 등 기존 코드와 동일한 호스트 검증 패턴으로,
같은 도메인/상대경로 복귀는 그대로 동작하고 타 도메인 이동만 차단.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-29 09:16:29 +00:00
thisgun ff9a7534ed Restore data htaccess on admin and write upload 2026-05-29 07:22:08 +00:00
thisgunandClaude Opus 4.8 9869be5970 [security] 토스 결제창 customerName 출력 시 get_text 인코딩 적용
토스페이먼츠 결제 요청 폼의 customerName hidden 필드에 주문자명
($od_name)이 인코딩 없이 출력되던 것을 get_text() 적용으로 정리.
직전 주문 필드 인코딩 처리와 동일한 맥락의 마무리.

hidden value 의 엔티티는 결제 SDK 가 값을 읽을 때 브라우저가
디코딩하므로 토스로 전달되는 구매자명에는 영향 없음.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-29 06:30:29 +00:00
thisgunandClaude Opus 4.8 1fa4467cd1 [security] 주문 관련 필드 출력 시 get_text 인코딩 적용
영카트 주문자명/받는분/입금자명(od_name, od_b_name, od_deposit_name)
이 일부 출력 지점에서 인코딩 없이 노출되어, 저장된 값이 HTML/속성
컨텍스트에서 그대로 렌더링되던 문제 수정. 다음 출력에 get_text() 적용:

- adm/shop_admin/orderform.php, sale1today.php (관리자 주문 화면)
- shop/orderinquiryview.php (PC/모바일/테마 주문조회)
- shop/{inicis,kcp,lg,nicepay,toss}/taxsave_form.php (현금영수증 발행 폼)
- shop/mail/orderupdate{1,2,3}.mail.php, ordermail.mail.php (주문 메일)

비회원 주문 시 입력값이 관리자 화면에서 실행될 수 있는 경로를 차단.
폼 value 의 엔티티는 브라우저 제출 시 디코딩되므로 PG 전송값 및
정상 표시에는 영향 없음.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-29 06:25:12 +00:00
thisgun 3e75ccea65 NHN KCP 휴대폰 본인확인(api_v2) 버전 추가 2026-05-29 06:14:21 +00:00
thisgun be9f50f96b Fix RSS warnings for invalid board requests 2026-05-29 01:33:45 +00:00
thisgun 7c217cb41b Restore alert newline handling 2026-05-28 06:23:04 +00:00
thisgun 5fc1c3bc27 버전 5.6.27 수정 2026-05-27 03:35:09 +00:00
thisgunandClaude Opus 4.7 d707c5abac data/ 디렉터리 git 추적 제외 (.htaccess 인덱스 제거)
.gitignore 에는 이미 data/ 가 등록되어 있으나 data/.htaccess
한 파일이 이전부터 트래킹되고 있어 배포본에 함께 포함되던 문제 정리.
디스크 파일은 그대로 두고 인덱스에서만 제거.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-27 02:28:39 +00:00
thisgunandClaude Opus 4.7 eeea46cb69 NHN KCP 가상계좌 발급 응답 코드 V000 허용
KCP 가이드 개정으로 가상계좌 발급 정상 응답이 0000 에서 V000 으로
변경되어, 기존 코드가 발급 성공을 실패로 인식하던 문제를 수정.
결제 hub 의 res_cd 비교 두 곳에서 V000 을 0000 과 동등하게 처리.

가상계좌 입금 완료 처리는 Webhook 입금통보가 담당하므로 본 변경과
무관. 취소/현금영수증/본인인증 경로는 V000 응답 대상이 아니므로
0000 단독 비교 유지.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 11:55:56 +00:00
thisgunandClaude Opus 4.7 669cce7011 주소 jibeon 값 화이트리스트에 'J' 추가
카카오 우편번호 서비스의 oncomplete 콜백이 userSelectedType
으로 'R'(도로명) 또는 'J'(지번)을 반환하는데, 서버 측 정규식이
'N|R' 만 허용해 지번 선택 시 빈 문자열로 저장되던 문제를 수정.
N 은 print_address() 의 도로명 표기 분기를 위한 레거시 값으로
호환을 위해 유지.

적용 위치: 회원가입(bbs/register_form_update.php), PC/모바일
주문(shop/, mobile/shop/ orderformupdate.php), 관리자 미완료
주문(adm/shop_admin/inorderformupdate.php) 의 7곳.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 11:46:36 +00:00
thisgunandClaude Opus 4.7 ee8b57eb13 미완료 주문 목록 PG 표시에 토스페이먼츠/NICEPAY 케이스 추가
dt_pg 값이 'toss' 또는 'nicepay' 인 건이 default 분기로 빠져
일괄 'KCP' 로 잘못 표시되던 문제 수정.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 11:40:18 +00:00
thisgun c927925a05 Fix PHP 5.2 compatibility issues 2026-05-26 09:34:18 +00:00
thisgun d914a7843d Fix PHP legacy array syntax 2026-05-26 08:10:57 +00:00
thisgun c04591e24a NHN_KCP 가상계좌 테스트 url 변경 2026-05-26 07:34:49 +00:00
thisgunandClaude Opus 4.7 a6fbbe6ad2 [security] 엑셀/CSV 다운로드 출력값 안전 처리
lib/common.lib.php 에 csv_safe_cell() 헬퍼 추가 (function_exists
가드 포함). 셀 값이 = + - @ TAB CR 로 시작하면 작은따옴표를 prefix
하여 스프레드시트가 수식으로 해석하지 못하도록 변환.

다음 출력 지점에서 사용자 입력 컬럼에 적용:
- adm/shop_admin/orderprintresult.php (CSV + XLS 두 분기)
- adm/shop_admin/orderdeliveryexcel.php
- adm/member_list_exel_export.php
- adm/sms_admin/num_book_file_download.php

호출부는 function_exists('csv_safe_cell') ? ... : 원본 폴백 형태로
감싸서 lib 미업데이트 환경에서도 fatal error 없이 동작하도록 함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:30:21 +00:00
thisgunandClaude Opus 4.7 4c00c60006 [security]KVE-2026-0882 race condition 잔액 부족 시 결제 취소 처리로 변경
이전 커밋(e53689ac3)의 미수금 처리 방식은 사용자에게 결제 금액과
다른 청구가 발생해 혼란/분쟁을 유발할 수 있어, 동시 주문 race 로
포인트 잔액이 부족하면 결제 자체를 취소하는 방식으로 변경.

- PG 결제가 진행된 경우 (\$tno 존재): cancel_pg.inc.php 로 환불 요청
- 장바구니 복구: 기존 line 839 동일 패턴 (od_id = tmp_cart_id, ct_status = '쇼핑')
- 주문 삭제: g5_shop_order_table 에서 od_id 제거
- 사용자에게 die 로 명확한 오류 메시지 표시

lock timeout 케이스도 동일하게 결제 취소 처리 (보수적).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 07:10:53 +00:00
thisgunandClaude Opus 4.7 56b1958d37 [security]KVE-2026-0882 주문 포인트 차감 Race Condition (Double Spend) 수정
shop/orderformupdate.php / mobile/shop/orderformupdate.php 의 포인트
검증과 차감 사이에 TOCTOU race 가 존재하여, 동일 회원이 여러 세션으로
동시에 주문 제출 시 같은 포인트 잔액을 반복 검증 통과 → 다중 차감으로
mb_point 가 음수가 되는 double spend 가 가능했음.

insert_point() 의 기존 named lock 은 (mb_id, rel_table, rel_id, rel_action)
조합 키 기반이라 서로 다른 od_id 주문 간에는 lock 이 다르고, 주문 차감
호출에 rel_* 가 전달되지 않아 lock 미적용 상태였음.

조치: KVE-2026-0687 (쇼핑몰 쿠폰) 와 동일한 회원 단위 MySQL GET_LOCK
패턴을 적용. lock 획득 후 g5_point SUM 으로 잔액을 재조회하여
- 충분하면 정상 차감
- race 로 부족하면 사용 가능한 만큼만 차감 + 부족분은 od_receipt_point
  보정 + od_misu(미수금) 으로 반영하여 매장 손실 방지.

MyISAM 정책상 트랜잭션 금지이므로 named lock 으로 직렬화하는 방식이
가장 적합. 데스크톱·모바일 동일 패턴 적용.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:52:25 +00:00
thisgunandClaude Opus 4.7 6b2f9e094c [security] ORDER BY sst/sod 화이트리스트 누락 Blind SQL Injection 수정
KVE-2026-0876 동일 패턴 추가 발견 5건 일괄 수정.

- shop/itemuselist.php / mobile/shop/itemuselist.php (상품후기 목록)
- shop/itemqalist.php / mobile/shop/itemqalist.php (상품문의 목록)
  → 비회원 접근 가능한 공개 페이지에서 sst/sod 가 ORDER BY 절에
    검증 없이 삽입되어 CASE WHEN/SLEEP 기반 blind SQLi 가능했음.
    sst 는 컬럼 화이트리스트, sod 는 asc/desc 정규식으로 검증.

- bbs/list.php (게시판 목록)
  → sst 는 wr_datetime/wr_hit/wr_good/wr_nogood 화이트리스트 적용
    되어 있으나 sod 가 검증 누락되어 ORDER BY 절에 함수 표현식
    삽입이 가능했음. sod 에 asc/desc 정규식 검증 추가.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 06:32:28 +00:00
thisgun a781b4aef3 [KVE-2026-0876] 모바일 상품 리스트 sort 파라미터 Blind SQL Injection 수정 2026-05-26 06:27:53 +00:00
thisgun 8be4476f56 [KVE-2026-0869] 인스톨러 관리자 입력값 SQL Injection 수정 2026-05-26 05:22:52 +00:00
thisgunandClaude Opus 4.7 59d0b3c19c [security]KVE-2026-0859 KCP CLI Windows 환경 명령 인젝션(RCE) 수정
shop/kcp/pp_cli_hub_lib.php, shop/kcp/pp_ax_hub_lib.php 의
mf_do_tx() Windows 분기가 사용자 입력이 포함된 KCP CLI 인자를
큰따옴표로 감싼 단일 문자열로 만들어 mf_exec() 첫 인자로 전달했고,
mf_exec() 는 첫 인자를 escape 없이 exec() 에 넘겨 Windows cmd.exe
메타문자(`"`, `&` 등)로 인증 없는 OS 명령 실행이 가능했음.

Linux 분기와 동일하게 실행 파일 경로와 콤마 구분 인자 문자열을
분리하여 mf_exec($bin_exe, $args) 형태로 호출하도록 변경.
mf_exec() 의 foreach 가 두 번째 이후 인자에 escapeshellarg() 를
자동 적용하여 cmd.exe 메타문자가 안전하게 wrapping 됨.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:35:51 +00:00
thisgunandClaude Opus 4.7 f4f8c57a74 [security] 관리자 영역 권한 검증 누락 및 CSRF 토큰 누락 수정
- adm/qa_config_update.php / adm/contentformupdate.php :
  qa_include_head/tail, co_include_head/tail 가 super 가드 없이 변경 가능해
  하위 관리자가 임의 PHP 경로를 include 시킬 수 있던 LFI 위험을
  board_form_update.php 와 동일한 패턴(super 외에는 기존 값 유지)으로 차단.

- adm/member_form_update.php / adm/member_list_update.php :
  신규 회원 생성·일괄 수정 시 부여하려는 mb_level 상한 검증이 없어
  하위 관리자가 자기보다 높은 등급을 부여할 수 있던 권한 상승을 차단.

- adm/shop_admin/categorylistupdate.php /
  adm/shop_admin/itemformupdate.php :
  is_include_path_check 호출에서 두 번째 인자(is_input=1) 누락으로
  rar/php/zip wrapper 등 경로 wrapper 차단이 동작하지 않던 부분을
  is_include_path_check($file, 1) 로 강화.

- adm/shop_admin/orderdeliveryupdate.php /
  adm/shop_admin/orderpartcancelupdate.php /
  adm/sendmail_test.php :
  상태 변경 동작에 check_admin_token() 누락으로 발생하던 CSRF 위험을
  토큰 검증 추가로 차단. sendmail_test 폼에는 hidden token 필드 추가.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:35:29 +00:00
thisgunandClaude Opus 4.7 d5619707bc [security] 인스톨러 g5_shop_prefix PHP 코드 인젝션(RCE) 수정
install/install_db.php 의 g5_shop_prefix 가 dbconfig.php 의
define('G5_SHOP_TABLE_PREFIX','...') 문자열에 작은따옴표 escape 없이
삽입되어, 설치 전 노출된 인스톨러를 통해 임의 PHP 코드 주입 후 RCE
가능하던 문제를 수정. table_prefix·admin_id 와 동일하게 [^0-9a-z_]+
정규식 검증을 추가하여 영문자·숫자·언더스코어만 허용하도록 함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:34:55 +00:00
thisgunandClaude Opus 4.7 9e7465319b [security]KVE-2026-0822 댓글 수정 textarea wr_content 미이스케이프 Stored XSS 수정
view_comment.skin.php 8종(skin/, mobile/skin/, theme/basic/ 하위 basic·
gallery)에서 댓글 수정($w == 'cu') 시 \$c_wr_content 가 textarea 내부에
이스케이프 없이 출력되어 </textarea> 페이로드로 탈출 가능하던 문제를
get_text() 적용으로 일괄 수정. 게시글 본문 수정(bbs/write.php) 과
동일한 escape 패턴을 댓글 수정에도 적용함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:32:43 +00:00
thisgunandClaude Opus 4.7 f1f2150c67 [security]KVE-2026-0795 게시물 이동/복사 시 대상 게시판 권한 검증 누락 수정
bbs/move_update.php 가 원본 게시판 기준 $is_admin 만 검사하고 사용자
입력 chk_bo_table[] 의 대상 게시판에 대해서는 존재 여부만 확인하던
문제를 수정. 게시판 관리자(board)·그룹 관리자(group) 권한일 경우
대상 게시판의 bo_admin 또는 그룹의 gr_admin 이 본인인지 재검증하고,
일치하지 않으면 해당 대상 게시판 처리를 건너뛰도록 함. super 관리자는
기존 동작 유지.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:32:18 +00:00
thisgunandClaude Opus 4.7 3de722d3df [security]KVE-2026-0787 alert() JavaScript 이스케이프 누락 Stored XSS 수정
bbs/alert.php, bbs/alert_close.php 가 alert("$msg") 형태로 메시지를
JS 문자열 컨텍스트에 직접 삽입하던 부분을 수정. lib/common.lib.php 에
PHP 5.2 호환 폴백을 갖춘 get_js_safe_string() 헬퍼를 추가하고,
호출부에는 function_exists 가드를 걸어 부분 패치 환경에서도 안전하게
폴백되도록 함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:31:24 +00:00
thisgunandClaude Opus 4.7 7119b4f612 [security]KVE-2026-0711 PG 리턴 처리 POST 키 이름 Reflected XSS 수정
XenoPostToForm::makeInputArray() 에서 POST 값·배열 인덱스는 이스케이프
되지만 최상위 POST 키 이름이 name 속성에 그대로 삽입되던 문제를 수정.
재귀 진입 시점에 htmlspecialchars() 로 키를 이스케이프하여 모든 깊이에서
안전하도록 함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:30:47 +00:00
thisgunandClaude Opus 4.7 efaefbbd0e [security]KVE-2026-0687 쇼핑몰 쿠폰 다운로드 TOCTOU Race Condition 수정
MySQL GET_LOCK 으로 동일 회원·동일 쿠폰 다운로드 요청을 직렬화하여,
동시 요청 시 is_coupon_downloaded() 체크를 중복 통과해 쿠폰이 중복
발급되는 문제를 방지함.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-26 03:30:19 +00:00
thisgun b12bf551ec [security]XSS 취약점 및 token 추가 2026-05-26 03:29:51 +00:00
thisgun 65a419e9cd 버전 5.6.26 수정 2026-04-16 04:38:38 +00:00
thisgunandClaude Opus 4.6 3f32ecd3e6 회원정보 수정 시 약관변경내역 로그가 매번 쌓이는 버그 수정
수신설정 섹션이 폼에 표시되지 않는 경우(cf_use_promotion 미사용, 휴대폰 미사용,
아이코드 미사용 등) _default 변수가 undefined 상태가 되어 비교 시 항상 "변경됨"으로
판단되던 문제를 해결. _default 변수를 명시적으로 초기화하고, 폼에 없는 항목은
기존 DB 값을 유지하도록 수정.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 04:01:37 +00:00
thisgun b5d218d446 인증서 교체로 인한 (구)엘지모듈 토스 결제 안되는 문제 수정 2026-04-16 03:46:30 +00:00
thisgun f2e7dbc5ed [security]그누보드5 XSS, SQL Injection 취약점 수정 2026-04-16 03:46:02 +00:00
thisgunandClaude Opus 4.6 c38de4c94b [security]KVE-2026-0701 .shtml 확장자 필터 누락으로 인한 RCE 수정
- bbs/write_update.php, bbs/qawrite_update.php: 업로드 블랙리스트에 shtml|shtm 추가
- install/install_db.php, data/.htaccess: FilesMatch 정규식에 [Ss]? 추가하여 .shtml 차단

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:39:31 +00:00
thisgunandClaude Opus 4.6 7d8a660642 [security]KVE-2026-0693 비밀번호 재설정 토큰 예측 가능 취약점 수정
rand() 대신 CSPRNG 기반 get_random_token_string() 사용
- mb_nonce: 128비트 CSPRNG 토큰으로 시드 브루트포스 차단
- change_password: CSPRNG 기반 10자리 hex로 변경

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:39:12 +00:00
thisgunandClaude Opus 4.6 5875e8b86b [security]KVE-2026-0690 설문조사 결과 페이지 Local File Inclusion 수정
skin_dir 파라미터에 디렉토리 트래버설 검증이 없어
임의 경로의 PHP 파일을 include할 수 있는 취약점을
clean_relative_paths()로 경로 조작 문자열 제거하여 수정

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:38:41 +00:00
thisgunandClaude Opus 4.6 68a5b9c25a [security]KVE-2026-0689 SNS 공유 스킨 Reflected XSS 수정
$_SERVER['REQUEST_URI']를 JavaScript 문자열에 이스케이프 없이
출력하여 URL을 통한 Reflected XSS가 가능한 취약점을
json_encode()로 안전하게 이스케이프 처리

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:38:21 +00:00
thisgun 2dff49914b [security]KVE-2026-0710 그누보드5 SQL Injection 수정 2026-04-16 03:35:29 +00:00
thisgun 51518e45e4 [security]KVE-2026-0709 그누보드5 SQL Injection 수정 2026-04-16 03:31:35 +00:00
thisgun 7883ff65dc check_token 함수 쓰는곳 없지만 요청사항으로 인해 타임스탬프 추가 수정 2026-04-16 03:30:19 +00:00
thisgunandClaude Opus 4.6 a2608754bd [fix]SMS 직접입력 발송 시 PHP 8.x Undefined array key 경고 수정
case 'h' 직접입력 항목에 bg_no, mb_id, bk_no 키 누락으로 257행에서 Warning 발생

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:24:09 +00:00
thisgunandClaude Opus 4.6 758bb67b7b [security]KVE-2026-0685 소셜 로그인 계정 연결 CSRF 방어
popup.php에서 mylink 진입 시 Referer 검증 및 세션 토큰 설정
functions.php에서 social_user_profile_replace() 호출 전 세션 토큰 검증

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:23:50 +00:00
thisgun 0037f72cce [security]KVE-2026-0678 사용자 영역 CSRF 방어 추가 2026-04-16 03:23:00 +00:00
thisgunandClaude Opus 4.6 df940f8168 [security]KVE-2026-0676 폼메일 발신자 위장 및 Rate Limit 우회 수정
비회원 폼메일 발송 시 From 헤더를 관리자 이메일로 고정하고 사용자 입력은 Reply-To로 설정
formmail_send.php에 세션 기반 발송 횟수 제한 추가 (직접 POST 우회 방지)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 03:18:19 +00:00
thisgunandClaude Opus 4.6 614b040960 [security]KVE-2026-0673 비인증 이메일 변경을 통한 계정 탈취 취약점 수정
register_email_update.php에 로그인 검증·소유권 강제·ckey HMAC 검증·SQL 이스케이프 추가
member_cert_refresh_update.php에 로그인 검증 및 소유권 강제 추가 (연관 IDOR 선제 조치)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-16 02:55:19 +00:00
thisgun dccb50d8a3 [security]회원 ID/이메일 열거 공격 차단 2026-04-16 02:54:05 +00:00
thisgun 5331aa8be5 [security]sql_query() 에러 노출 시 SQL/스키마 정보 차단
sql_query()의 에러 처리가 die()로 SQL 쿼리 전문, MySQL 에러 메시지,
스크립트 파일 경로를 사용자에게 그대로 노출하고 있었음. 기본값
G5_DISPLAY_SQL_ERROR=false 덕분에 일반 호출에서는 트리거되지 않으나,
일부 admin 파일이 명시적으로 sql_query(\$sql, true)로 호출하여
관리자에게 raw SQL을 노출했고, SQLi 공격 시도 중 발생한 에러로 DB
구조(테이블/컬럼명)가 학습되어 정밀 공격에 활용될 수 있었음.

조치:
- 서버 로그(error_log)에는 항상 상세 기록 → 운영자가 디버깅 가능
- \$is_debug 모드(G5_DEBUG=true 또는 super admin)에서만 상세 표시
  + XSS 방지를 위해 htmlspecialchars로 escape
- 그 외 환경에서는 "데이터베이스 처리 중 오류가 발생했습니다." 만 표시
- mysqli/mysql 폴백 분기 둘 다 동일하게 적용

변경:
- lib/common.lib.php:1932 (mysqli 분기)
- lib/common.lib.php:1942 (mysql 분기, 레거시 PHP 5.x 폴백)

PHP 5.2.17 호환 유지 (htmlspecialchars + ENT_QUOTES 모두 PHP 4.0+).
2026-04-16 02:48:31 +00:00
thisgun 79f915988b [security]개인결제 hash 검증을 strict 비교(===)로 강화
shop/personalpayformupdate.php와 lib/shop.lib.php의 ss_personalpay_hash
검증이 loose 비교(==/!=)를 사용하여 PHP type juggling 잠재적 우회 가능성이
있었음. md5 결과 중 "0e..." 형식 hash는 PHP의 loose 비교에서 0e 지수
표기법으로 해석되어 다른 "0e..." 해시와 동등 판정될 수 있음
(소위 magic hash collision 패턴).

실제 익스플로잇 가능성은 낮지만 (md5 출력은 32자 hex 문자열이고 PHP의
문자열 vs 문자열 비교에서는 0e... 패턴이 적용되지 않는 경우가 많음),
defense in depth 차원에서 strict 비교로 변경.

mobile/shop/personalpayformupdate.php는 이미 strict 비교를 사용 중이라
core 두 곳만 동일한 패턴으로 정렬.

- shop/personalpayformupdate.php:35: != / != → !== / !==
- lib/shop.lib.php:2333: == → ===
2026-04-16 02:46:49 +00:00
thisgun 3cfe8b6b84 [security]현금영수증 발급 페이지 IDOR 취약점 수정 2026-04-16 02:43:22 +00:00
thisgun 31ef78e916 [perf]strstr() 불린 검사를 strpos() !== false 로 교체
strstr()은 일치하는 부분 문자열 전체를 반환하므로 존재 여부만 체크할
때는 메모리 할당이 낭비됨. strpos()는 위치(int) 또는 false만 반환하여
메모리 할당 없이 더 빠르게 동일 동작 수행.

적용 파일 (19개, 약 25곳):
- lib/common.lib.php: wr_option html1/html2/secret 검사 3곳
- lib/shop.lib.php: de_taxsave_types 검사 2곳
- lib/latest.lib.php: wr_option secret 검사 1곳
- lib/thumbnail.lib.php: wr_option secret 검사 1곳
- lib/URI/uri.class.php: URI 확장자 검사 1곳
- bbs/view.php: subject/wr_option/content 검사 4곳
- bbs/view_comment.php: wr_option secret 검사 1곳
- bbs/search.php: wr_option/sfl 검사 3곳
- bbs/rss.php: wr_option html 검사 1곳
- bbs/write_update.php: html1/html2 검사 2곳
- bbs/move_update.php: wr_option html 검사 1곳
- adm/admin.lib.php: auth 권한 검사 1곳
- adm/admin.head.php: 메뉴 권한 검사 1곳
- adm/session_file_delete.php: sess_ prefix 검사 1곳
- adm/point_list.php, adm/auth_list.php: sfl mb_id 검사 2곳
- adm/sms_admin/_common.php: install.php 검사 1곳
- adm/shop_admin/configform.php: de_taxsave_types 검사 3곳
- head.sub.php: admin dir 검사 1곳

규칙:
  strstr($a, $b)       → strpos($a, $b) !== false
  !strstr($a, $b)      → strpos($a, $b) === false

제외:
- theme/, skin/, plugin/ (사용자 커스터마이징/서드파티)
- strstr() 반환값을 실제로 사용하는 케이스 (예: lib/common.lib.php:4135
  if( \$freg = strstr(\$ori_params, '#') ), extend/gif2mp4.extend.php)
2026-04-16 02:29:32 +00:00
thisgun a612e69d3e [perf]for 루프 조건의 count() 호출을 루프 밖으로 추출 (핵심 파일)
for ($i=0; $i<count(\$arr); $i++) 패턴은 매 반복마다 count()를 호출하여
불필요한 CPU 오버헤드를 발생시킴. 루프 전에 한 번만 count()를 계산하여
변수에 저장하는 고전적인 최적화.

적용 파일 (19개, 41곳):
- lib/common.lib.php (8)
- common.php (2)
- lib/shop.lib.php (5)
- lib/naverpay.lib.php (1)
- lib/thumbnail.lib.php (2)
- bbs/list.php (1), bbs/search.php (4), bbs/qalist.php (1), bbs/qawrite.php (1)
- bbs/ajax.filter.php (1), bbs/write_update.php (4)
- bbs/write_comment_update.php (1), bbs/memo_form_update.php (2)
- bbs/new_delete.php (1), bbs/move_update.php (4)
- shop/search.php (1), shop/orderform.sub.php (1)
- mobile/shop/search.php (1), mobile/shop/orderform.sub.php (1)

부수 효과:
- lib/shop.lib.php line 2115: 동일 루프 내 strstr($dlcomp, $company)를
  strpos($dlcomp, $company) !== false 로 변경 (strstr 최적화의 일부)

제외:
- theme/, skin/, plugin/ (사용자 커스터마이징/서드파티)
- lib/PHPExcel/ (서드파티 라이브러리)
- adm/ 및 shop/mail/ (관리자/드문 경로, 별도 후속 작업 여지)
- 주석 처리된 코드 (bbs/delete.php:127, bbs/delete_all.php:143)
2026-04-16 02:26:59 +00:00
thisgun 29e55de1fa [perf]url_auto_link() 다중 regex 호출 조건부 실행으로 최적화
기존 구현은 일반 텍스트 게시글(URL/이메일이 전혀 없는 대부분의 경우)
에서도 3개의 preg_replace를 항상 호출하여, 모든 게시글 본문 렌더링
마다 불필요한 regex 컴파일/스캔 오버헤드가 발생.

개선:
1. Fast bailout: ://, www., @, &, ' 가 하나도 없으면 즉시 반환하여
   forward/reverse str_replace와 3개의 preg_replace를 모두 생략.
2. 조건부 regex 실행: 각 regex 호출 전에 해당 패턴이 실제로 존재하는지
   strpos로 먼저 확인. URL 패턴 없으면 URL regex 생략, 이메일 없으면
   email regex 생략 등.

strpos x5 (~1ms) vs preg_replace x3 (~20ms+) 이므로 일반 텍스트 게시글
에서 10~20배 이상 빠르게 동작. 페이지에 수십~수백 개 게시글을 표시하는
목록/검색 페이지에서 누적 효과가 큼.

의미론적 동등성 유지: 각 marker가 없으면 해당 regex가 원래도 no-op였으므로
조건부 실행은 결과에 영향 없음. Fast path는 모든 marker가 없을 때만
동작하므로 str_replace의 부작용(& entity 디코딩 등)도 발생할 여지가 없음.
2026-04-16 02:25:49 +00:00
thisgun c4db6e7751 [perf]cut_str() 메모리 사용량과 CPU 오버헤드 감소
기존 구현은 preg_split("//u")로 입력 문자열의 모든 문자를 PHP 배열로
분해한 뒤 count/array_slice/join 3단계로 처리하여, 짧은 문자열이든
긴 문자열이든 항상 문자 수만큼 배열 원소를 할당하고 regex를 호출함.

게시글 목록의 제목/내용 표시 등 페이지당 수십~수백 회 호출되는
핫패스에서 불필요한 오버헤드를 발생시킴.

개선:
1. 바이트 길이 빠른 경로: strlen(str) <= len이면 UTF-8 특성상 문자 수도
   보장되므로 즉시 반환. ASCII/짧은 제목은 mb_strlen 호출 없이 종료.
2. mbstring 확장 사용: mb_strlen + mb_substr로 배열 생성 없이 상수
   메모리로 길이 체크/절단 처리.
3. preg_split 기반 기존 로직은 mbstring 미설치 환경 폴백으로 유지.

의미론적 동등성 유지 (잘라낸 결과와 suffix 부착 조건 모두 동일).
2026-04-16 02:25:12 +00:00
thisgun 47a3790c57 [perf]bbs/list.php N+1 쿼리 2건을 IN 쿼리로 배치 조회로 전환
게시판 목록 페이지에서 발생하던 N+1 쿼리 패턴 2건을 제거:

1. 공지 처리 루프 (line 94~120):
   기존에는 bo_notice의 각 wr_id마다 sql_fetch를 따로 호출하여 공지가 N개면
   N개의 쿼리가 발생. 유효한 wr_id를 정수화하여 수집한 뒤 단일 IN 쿼리로
   일괄 조회하고, id 기반 해시맵으로 원래 순서대로 처리.

2. 검색 결과 2차 조회 (line 199~200):
   DISTINCT wr_parent 쿼리로 ID만 받은 뒤, 각 행마다 sql_fetch를 호출하여
   검색 결과가 N건이면 추가로 N개의 쿼리가 발생. 단일 IN 쿼리로 모든 부모
   글을 일괄 조회 후 $rows_to_process 배열에 원래 순서대로 정렬하여 공통
   처리 루프에서 소비. 검색/비검색 분기에서 중복되던 row→list 변환 로직도
   공통화.

효과 (공지 5개 + 검색 결과 20건 기준):
  기존: 1 DISTINCT + 20 fetch + 5 notice fetch = 26 쿼리
  개선: 1 DISTINCT + 1 IN(search) + 1 IN(notice) = 3 쿼리

부수 효과:
- 삭제된 공지/부모글에 대한 에러 처리 개선
  (기존은 empty row를 get_list에 넘겨 잠재적 오류, 개선판은 자동 스킵)
- wr_id 정수화로 SQL injection 방지 계층 추가
2026-04-16 02:23:24 +00:00
thisgun 2894c269ea [security]이메일 인증 페이지 접근 토큰을 HMAC-SHA256으로 강화 2026-04-16 02:21:23 +00:00
thisgun c00c73465a [security]비회원 주문/개인결제 조회 uid를 HMAC-SHA256으로 강화 2026-04-16 02:15:29 +00:00
thisgun 3e0e8be6da [security]쇼핑몰 update 엔드포인트 CSRF 보호 추가 2026-04-16 02:02:26 +00:00
thisgun 92a052fa7a [perf]html_purifier() 메모리 사용량 최적화
한 요청에서 html_purifier()가 N번 호출되면 매번 약 10~15MB의 HTMLPurifier
인스턴스를 새로 생성하여, 게시글 목록처럼 반복 호출되는 페이지에서
수백 MB~GB 단위로 메모리가 낭비되었음.

- HTMLPurifier 인스턴스를 요청 단위로 캐싱 (admin/normal 2개 변형만 유지)
- safeiframe.txt 파일 I/O + 파싱 결과도 요청 단위로 캐싱
- G5_HTMLPURIFIER_NO_CACHE 상수로 캐싱 opt-out 가능
  ($html 내용에 따라 config를 동적 변경하는 플러그인 호환용)

동작 변경:
- html_purifier_config / html_purifier_safeiframes hook은 캐시 미스 시점에만
  실행됨 (요청당 최대 2회). 정적 config를 설정하는 일반적인 hook에는 영향 없음.
- html_purifier_result hook은 매 호출마다 정상 실행됨.

효과 (게시글 목록 30건 + 첨부파일 평균 3개 = 120회 호출 기준):
  기존 ~1.8GB → 개선 후 ~15MB
2026-04-16 01:36:59 +00:00
thisgun 4ebdd8ba30 [fix]포인트 사용/환원 함수의 race condition 수정
insert_use_point, delete_use_point, delete_expire_point 함수의 SELECT-then-UPDATE
패턴이 동시 호출 시 데이터 무결성을 깰 수 있는 race condition을 가지고 있었음.
같은 회원의 포인트 작업이 동시에 발생하면 PHP 단에서 캐시한 잔여량을 기준으로
판단하여 결과적으로 음수/초과 차감 등 포인트가 꼬이는 현상이 발생.

MyISAM은 트랜잭션과 FOR UPDATE를 지원하지 않으므로, 락 없이 무결성을 보장하는
lock-free atomic UPDATE 패턴으로 재구현:

- 매 단계마다 가장 우선 처리할 행 1개를 SELECT (LIMIT 1)
- WHERE 절에 사전 검증 조건(잔여량/상태)을 포함한 원자적 UPDATE
- get_sql_affected_rows()로 성공/실패 판별, 실패 시 재시도
- max_iter=1000 안전장치로 무한루프 방지

특징:
- 단일 행 차감(가장 흔한 케이스)에서 기존과 동일한 쿼리 수
- GET_LOCK 등 추가 락 없음 → 같은 사용자 동시 요청도 throughput 손실 없음
- MyISAM/InnoDB 모두 호환, MySQL 5.0~8.x 모두 동작
2026-04-16 01:35:45 +00:00
thisgun 4d5c597665 [KVE-2026-0610]그누보드5 자동 로그인 취약점 수정 2026-04-16 01:31:19 +00:00
thisgun 7e65a297bf [KVE-2026-0608]그누보드5 Race Condition 취약점 수정
- bbs/poll_update.php: 설문조사 중복 투표 방지 (FIND_IN_SET을 WHERE에 포함한 원자적 UPDATE)
- bbs/good.php: 추천/비추천 카운터 부풀리기 방지 (INSERT IGNORE 우선 후 카운터 증가)
- lib/common.lib.php: insert_point() 포인트 중복 지급 방지 (MySQL named lock GET_LOCK 사용)
2026-04-16 01:07:17 +00:00
thisgun ddcc82d89b .gitignore 에 CLAUDE.local.md 추가 2026-04-16 01:00:28 +00:00
thisgun ad99ea7673 [KVE-2026-0599]그누보드5 XSS 취약점 수정 2026-04-06 06:27:09 +00:00
thisgun b3fa6dc127 [KVE-2026-0595]영카트5 SQL Injection 취약점 수정 2026-04-06 06:26:20 +00:00
thisgun e6780f3b4b 버전 5.6.25 수정 2026-04-06 03:47:15 +00:00
thisgun bededeaf01 .gitignore에 IDE 및 AI 도구 설정 파일 추가 2026-04-06 03:46:41 +00:00
thisgunandClaude Opus 4.6 73b868a444 Cloudflare IPv4 대역 업데이트: 104.16.0.0/12 → 104.16.0.0/13
공식 Cloudflare IP 목록(https://www.cloudflare.com/ips)에 맞게 수정

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 03:29:55 +00:00
thisgun eb249a2aee Merge branch 'master' of github.com:gnuboard/gnuboard5 2026-04-06 03:21:45 +00:00
HanbitGaram(ハンビッガラム)andGitHub 813fdef0c7 다음 우편번호 서비스 네임스페이스 및 서비스 도메인 변경 (#374) 2026-04-06 12:20:42 +09:00
kms0219kmsandGitHub f8561e9398 ✏️ feat: 토스페이먼츠 상점관리자 - ‘테스트모드‘ 추가 반영, NHN KCP 상점관리자 주소 변경 (#368)
* ✏️ feat: 토스페이먼츠 테스트모드 반영, KCP 주소 업데이트

* ✏️ feat: 토스페이먼츠 테스트모드 문구 반영, KCP 주소 업데이트

* ✏️ typo: KCP 테스트환경 주소 변경
2026-04-06 12:19:11 +09:00
thisgun 52590509d5 [KVE-2026-0559]그누보드5 SQL Injection 취약점 수정 2026-04-03 03:59:23 +00:00
thisgun 604cef808e [보안패치]그누보드 영카트 SQL_injection 취약점 수정 2026-03-31 01:21:11 +00:00
thisgun 82574fd4a8 [KVE-2026-0570]그누보드,영카트 SQL Injection 취약점 수정 2026-03-30 12:01:44 +00:00
thisgun c3db9b454e [KVE-2026-0569]그누보드,영카트 SQL Injection 취약점 수정 2026-03-30 11:50:30 +00:00
thisgun bf19cd8bf5 [KVE-2026-0568]영카트 SQL Injection 취약점 수정 2026-03-30 11:03:16 +00:00
thisgun b2c0e1af29 [KVE-2026-0554]그누보드,영카트 SQL Injection 취약점 수정 2026-03-30 09:52:41 +00:00
thisgun 60d37b853b [KVE-2026-0553]그누보드 SQL Injection 취약점 수정 2026-03-30 09:50:38 +00:00
thisgun 919b75a138 [KVE-2026-0340]그누보드_SQL_Injection취약점_수정 2026-03-26 03:38:19 +00:00
thisgun 01fab8136e git commit -am "[KVE-2026-0330]영카트_SQL_Injection취약점_수정"; 2026-03-26 01:32:14 +00:00
thisgun 5054e24631 [KVE-2026-0243]영카트주문시_쿠폰중복사용취약점_수정 2026-03-25 09:18:48 +00:00
thisgun deff7d2079 warning 메시지 수정 2026-03-25 05:06:29 +00:00
thisgun 5e6b4fa668 [KVE-2026-0242]영카트주문취소시_포인트복구취약점_수정 2026-03-25 04:59:56 +00:00
thisgun ef1be317e1 버전 5.6.24 수정 2026-02-03 06:25:50 +00:00
thisgun 137d78ff73 영카트 관리자모드 분류출력 개선 2026-02-03 06:24:34 +00:00
thisgun 0ddcda4b0c toss 모바일결제 포인트 적용시 결제 오류 수정 2026-02-02 09:37:49 +00:00
thisgun bf27af3925 영카트 shop_is_taxsave 에서 볌수 코드 오타 수정 2026-02-02 07:33:36 +00:00
thisgun 607e15424d 토스결제 비회원결제가 안되는 오류 및 모바일 개인결제 취소과정 코드 수정 2026-02-02 07:18:28 +00:00
thisgun 7c490448ec 메일보내기 발신자 위장 방지 및 암호화 키의 안전성 취약점 수정 2026-01-30 05:00:43 +00:00
thisgun d775d2255f [KVE-2026-0029]Stored XSS 취약점 수정 2026-01-27 05:50:34 +00:00
thisgun b94771de92 썸네일 파일 코드 위치변경 2026-01-27 03:34:20 +00:00
thisgun b29e16a198 게시판 관리자가 게시판 수정시 자동등록방지 숫자가 틀렸습니다 라고 나오는 오류 수정 2026-01-26 09:40:43 +00:00
thisgun 0e06b4f9ce 영카트5에서 사용자가 현금영수증 발급버튼이 출력되지 않는 오류 수정 2026-01-26 09:33:19 +00:00
thisgun f2ab751e5f [KVE-2025-0828]영카트 취약점 수정 2025-11-14 07:30:47 +00:00
thisgun 3432497efe 삼성브라우저PC버전 대응 2025-11-14 02:08:02 +00:00
총andGitHub 60bb03049e Merge pull request #61 from gnuboard/fix/admin-member-header
style: 관리자 > 회원관리 > 목록, 광고성 정보 수신 동의에 따른 테이블 폭 조정 처리
2025-09-25 10:07:49 +09:00
whitedot a7541256cb style: 관리자 > 회원관리 > 목록, 광고성 정보 수신 동의에 따른 테이블 폭 조정 처리 2025-09-25 10:02:25 +09:00
thisgun e26fb62f5d 버전 5.6.23 수정 2025-09-22 11:06:20 +09:00
thisgun 887833089b php warning 메시지 코드 수정 2025-09-22 11:05:39 +09:00
thisgun 1438f8d557 충돌수정 2025-09-22 10:39:44 +09:00
총andGitHub 25e359facd Merge pull request #57 from gnuboard/release/toss-version-update-squash
feat: 토스페이먼츠 v2 결제 모듈 연동 작업 완료
2025-09-22 10:04:39 +09:00
chym1217 b98d45615c 회원관리파일 병합연산자 -> 삼항연산자로 수정 2025-09-19 17:54:35 +09:00
chym1217 7e8eff5395 팝빌 알림톡 제거 완료
- 광고성 및 회원관리파일(친구톡 코드만 제거) 제외
2025-09-19 17:53:50 +09:00
chym1217 f4718a71a2 feat: 관리자페이지 토스페이먼츠 명칭 변경 및 테스트결제 안내 추가
- 기존 : 토스페이먼츠 -> 토스페이먼츠(구버전)
- 토스페이먼츠 V2 -> 토스페이먼츠 API
- 기타 css 및 주석 수정
2025-09-17 10:44:40 +09:00
chym1217 46ea2d03b5 토스페이먼츠 v2 결제 모듈 연동 2025-09-16 16:34:15 +09:00
thisgun 1eee11e433 회원관리파일 export 에 권한체크 추가 2025-09-12 14:27:11 +09:00
thisgun a71192a63b 버전 5.6.22 수정 2025-09-12 13:56:31 +09:00
thisgun 633ff46596 전체검색시 페이징 되지 않는 오류 수정 2025-09-12 10:50:08 +09:00
chym1217 8a1f350d67 fix: 회원/게시판 추가 시시 Undefined array key 다수 발생 현상 수정 2025-09-09 09:36:42 +09:00
chym1217 ef364e1430 fix: 재입고 알림 DB 업그레이드 – 영카트 미설치 시 발생 오류 해결 2025-09-08 16:37:03 +09:00
thisgun f6a6a5622d 버전 5.6.21 수정 2025-09-08 09:59:55 +09:00
thisgun 63d6f7c43f Merge branch 'master' of github.com:gnuboard/g5-update 2025-09-08 09:43:00 +09:00
총andGitHub 6e101c4647 Merge pull request #54 from gnuboard/release/popbill-squashed
feat: #23 팝빌 알림톡 기능 추가 작업 완료
2025-09-08 09:42:09 +09:00
thisgun fa792efacb kcaptcha html 에 hook 적용 2025-09-08 09:37:43 +09:00
chym1217 66f6a75a10 팝빌 알림톡 기능 추가 2025-09-04 12:37:12 +09:00
thisgun de2502fad5 버전 5.6.17 수정 2025-09-02 18:29:27 +09:00
thisgun 54171e1903 5.6.16 버전에서 게시판 생성이 안되는 오류 수정 2025-09-02 18:27:55 +09:00
thisgun 44172c1d1f Merge branch 'master' of github.com:gnuboard/g5-update 2025-09-01 11:32:50 +09:00
thisgun 41945c62f8 버전 5.6.16 수정 2025-09-01 11:23:45 +09:00
총andGitHub 37d0dcb48f Merge pull request #47 from gnuboard/fix/sms5-table-prefix
[#42] fix: sms5 TABLE 생성 및 패치 시 G5_TABLE_PREFIX 사용
2025-08-29 17:04:42 +09:00
thisgun 002e43e5fb XSS 취약점 수정 2025-08-28 13:35:14 +09:00
thisgun 9510aa9cf1 Merge branch 'master' of github.com:gnuboard/g5-update 2025-08-27 18:52:02 +09:00
thisgun 6a3c2b1002 [KVE-2025-0464]영카트 XSS 취약점 수정 2025-08-27 17:58:06 +09:00
총 f69b66dced [KVE-2025-0510] Stored XSS (bypass html_purify patch) to RCE 취약점 수정 2025-08-27 11:48:36 +09:00
chym1217 cb1fadba4c fix: #42 SMS5 DB에 G5_TABLE_PREFIX 적용
- 기존 sms5_* 테이블 존재 시 dbupgrade에서 테이블명 변경
2025-08-19 15:31:58 +09:00
thisgun 5da91ab73e 버전 5.6.15 수정 2025-07-31 20:25:39 +09:00
thisgun d5b541724f create_hash 함수에 fclose 코드 추가 2025-07-31 20:23:59 +09:00
thisgun 9758007f91 NHN_KCP 네이버페이 간편결제 카드 또는 머니결제로 분리 2025-07-31 20:21:22 +09:00
thisgun 9d5f8e137f 관리자 로그인시 새글 테이블 OPIMIZE 실행시 딜레이 되는 문제 개선2 2025-07-31 17:12:43 +09:00
thisgun f1da95f055 Open redirect 취약점 수정 2025-07-30 15:03:01 +09:00
thisgun 9602f3c7a7 php warning 메시지 코드 수정 2025-07-21 12:48:53 +09:00
thisgun d357f5a0a4 Merge branch 'master' of github.com:gnuboard/gnuboard5 2025-07-08 11:41:40 +09:00
thisgun a9eab8d86a insert_use_point 함수에 hook 추가 #363 2025-07-08 11:40:47 +09:00
thisgun 9191199ef4 db_table.optimize.php 파일에 hook 추가 #362 2025-07-08 11:16:26 +09:00
thisgun 2556753530 url_auto_link함수에 url_auto_link_before hook 추가 #361 2025-07-08 11:02:34 +09:00
thisgun 57983a6dbc 토스페이먼츠 머트키 확인방법 설명문 수정 2025-07-08 10:45:10 +09:00
restarea92andGitHub 327e7ba7ba feat: add list.php theme override (#358)
* feat: add theme override in shop/list.php

* feat: add theme override in mobile/shop/list.php
2025-06-27 09:35:52 +09:00
thisgun 67415cf8d3 get_uniqid 함수에 hook 추가 2025-06-18 10:53:46 +09:00
thisgun aa88ff68a1 KG이니시스 IDC 센터코드 검증 추가2 2025-06-12 17:34:53 +09:00
thisgun 07a0245f85 버전 5.6.14 수정 2025-06-12 17:17:33 +09:00
thisgun d3de613a8c 관리자 로그인시 새글 테이블 OPIMIZE 실행시 딜레이 되는 문제 개선 2025-06-12 17:05:55 +09:00
thisgun bb1f69e86c KG이니시스 IDC 센터코드 검증 추가 2025-06-05 16:11:20 +09:00
thisgun dc4c2a79d9 XSS 취약점 수정 박재형님 제보 2025-06-05 14:12:55 +09:00
thisgun 38451a7d3d [KVE-2025-0384]XSS lead to RCE 취약점 수정 2025-06-04 17:44:50 +09:00
thisgun 87d11d5c78 변수 초기화 되지 않아 warning 메시지 출려되는 현상 수정 2025-06-04 14:40:18 +09:00
thisgun c1bbce1114 KG이니시스 가상계좌 에스크로 IP 추가 2025-05-28 11:27:59 +09:00
thisgun 61576d3e87 [KVE-2025-0351]ip 검증 취약점 수정 2025-05-28 10:57:33 +09:00
thisgun c9100d2e38 NHN_KCP 본인인증 테스트 오류 수정 2025-05-23 12:19:22 +09:00
thisgun 7714153faf 버전 5.6.13 수정 2025-05-15 15:31:41 +09:00
thisgun 654fd7ba68 방문자 기록 sql 문 수정 2025-05-15 15:30:40 +09:00
thisgun ea9f618de8 KG이니시스 모바일 가상계좌 IP 추가 2025-05-15 15:29:26 +09:00
thisgun eea5a2477b 쇼핑몰관리자 나이스페이신청 URL 링크 수정 2025-05-15 14:23:38 +09:00
thisgun 8cc101b617 접근차단 ip코드 다시 재수정 2025-05-15 14:09:27 +09:00
thisgun 316d3542a9 [KVE-2025-0259]XSS 취약점 수정 2025-05-15 09:53:28 +09:00
thisgun c2da219473 [KVE-2025-0286]XSS 취약점 수정 2025-05-14 12:49:03 +09:00
thisgun 6874e767c2 kcp 모바일 테스트결제 url 변경 2025-05-14 12:00:09 +09:00
thisgun 5a91d37365 php warning 메시지 코드 수정 2025-05-14 11:59:40 +09:00
thisgun f9c972d866 [KVE-2025-0191] Stored XSS (bypass html_purify via Open Redirect) 취약점 수정 2025-04-17 16:04:01 +09:00
thisgun ada8f28aae 버전 5.6.12 수정 2025-04-15 16:33:05 +09:00
thisgun 11afc52b84 접근차단 ip 코드의 위치 다시 재수정 2025-04-15 16:31:27 +09:00
thisgun d9c3f0e66c Merge branch 'master' of github.com:gnuboard/gnuboard5 2025-04-15 12:06:31 +09:00
thisgun 49da5c33df 버전 5.6.11 수정 2025-04-15 11:56:53 +09:00
thisgun 29250f264a 첩근차단 ip코드의 위치 수정 2025-04-15 11:44:40 +09:00
thisgun df00641290 php warning 메시지 코드 수정 2025-04-15 11:20:44 +09:00
thisgun a05a1403f5 Merge branch 'master' of github.com:gnuboard/g5-update 2025-04-15 10:52:11 +09:00
총 c5817594d0 [KVE-2025-0234] 관리자 XSS 취약점 수정 2025-04-15 10:11:31 +09:00
kagla 68a9e45337 Revert "경로 수정 및 불필요한 파일 삭제: CSS 파일 경로를 절대 경로로 변경하고, 사용되지 않는 install.css 및 이미지 파일을 삭제함. 또한, 여러 파일에서 include 경로를 수정하여 일관성을 유지함."
This reverts commit b8da0f0890.
2025-04-11 13:06:43 +09:00
kagla b8da0f0890 경로 수정 및 불필요한 파일 삭제: CSS 파일 경로를 절대 경로로 변경하고, 사용되지 않는 install.css 및 이미지 파일을 삭제함. 또한, 여러 파일에서 include 경로를 수정하여 일관성을 유지함. 2025-04-11 12:56:45 +09:00
thisgun 62ff45b31f php warning 메시지 코드 수정 2025-03-31 15:36:32 +09:00
thisgun 918ad48675 이미지 태그에 loading=lazy 가 있을경우 viewimagereisze 함수에서 width 속성을 추가하지 않도록 수정#355 2025-03-14 16:40:26 +09:00
thisgun e5128bf02e cheditor5 에 지도아이콘 제거 2025-02-20 12:52:39 +09:00
397 changed files with 30522 additions and 12660 deletions
+1
View File
@@ -1,2 +1,3 @@
.gitattributes export-ignore
.gitignore export-ignore
*.php whitespace=blank-at-eol,blank-at-eof,space-before-tab,cr-at-eol
+11
View File
@@ -13,6 +13,17 @@ cheditor5.*/
log/
g5_tree/
.vscode/
.claude/
.cursor/
.windsurf/
.idea/
.playwright-mcp
.mcp.json
.agents
.DS_Store
*.swp
*.swo
CLAUDE.local.md
naver*.html
initests01/
SIRsoft000/
+4
View File
@@ -3,6 +3,10 @@ define('G5_IS_ADMIN', true);
require_once '../common.php';
require_once G5_ADMIN_PATH . '/admin.lib.php';
if (function_exists('g5_check_data_htaccess')) {
g5_check_data_htaccess();
}
if (isset($token)) {
$token = @htmlspecialchars(strip_tags($token), ENT_QUOTES);
}
+1 -1
View File
@@ -42,7 +42,7 @@ function print_menu2($key, $no = '')
continue;
}
if ($is_admin != 'super' && (!array_key_exists($menu[$key][$i][0], $auth) || !strstr($auth[$menu[$key][$i][0]], 'r'))) {
if ($is_admin != 'super' && (!array_key_exists($menu[$key][$i][0], $auth) || strpos($auth[$menu[$key][$i][0]], 'r') === false)) {
continue;
}
+109 -5
View File
@@ -1,11 +1,115 @@
function check_all(f)
{
var chk = document.getElementsByName("chk[]");
/** 공통 UI 모듈 */
window.CommonUI = {
bindTabs(tabSelector, contentSelector, options = {}) {
const tabs = document.querySelectorAll(tabSelector);
const contents = document.querySelectorAll(contentSelector);
for (i=0; i<chk.length; i++)
chk[i].checked = f.chkall.checked;
tabs.forEach(tab => {
tab.addEventListener('click', () => {
const tabName = tab.dataset.tab;
const target = document.getElementById(`tab-${tabName}`);
tabs.forEach(t => t.classList.remove('active'));
tab.classList.add('active');
contents.forEach(c => c.classList.add('is-hidden'));
if (target) target.classList.remove('is-hidden');
options.onChange?.(tabName, target);
});
});
}
};
function setHtml(el, markup) {
if (!el) return;
if (markup == null || markup === '') {
el.textContent = '';
return;
}
const range = document.createRange();
range.selectNodeContents(el);
el.replaceChildren(range.createContextualFragment(markup));
}
/** 팝업 관리 모듈 */
window.PopupManager = {
open(id, options = {}) {
const el = document.getElementById(id);
if (el) {
el.classList.remove('is-hidden');
this.bindOutsideClickClose(id);
if (!options.disableOutsideClose) {
this.bindOutsideClickClose(id);
} else {
this.unbindOutsideClickClose(id);
}
}
},
close(id) {
const el = document.getElementById(id);
if (el) el.classList.add('is-hidden');
},
toggle(id) {
const el = document.getElementById(id);
if (el) el.classList.toggle('is-hidden');
},
bindOutsideClickClose(id) {
const el = document.getElementById(id);
if (!el) return;
el.onclick = () => this.close(id);
},
unbindOutsideClickClose(id) {
const el = document.getElementById(id);
if (!el) return;
el.onclick = null;
},
/**
* 팝업 콘텐츠 렌더링 (타이틀, 바디, 푸터 구성)
* @param {string} title - 팝업 제목
* @param {string} body - 팝업 본문 HTML
* @param {string} [footer] - 푸터 HTML
* @param {object} [options] - 팝업 열기 옵션
*/
render(title, body, footer = '', options = {}) {
const titleEl = document.getElementById('popupTitle');
const bodyEl = document.getElementById('popupBody');
const footerEl = document.getElementById('popupFooter');
if (titleEl) titleEl.textContent = title;
if (bodyEl) setHtml(bodyEl, body);
if (footerEl) setHtml(footerEl, footer);
this.open('popupOverlay', options);
}
};
/** 형식 체크 */
function check_all(target) {
const chkboxes = document.getElementsByName("chk[]");
let chkall;
if (target && target.tagName === "FORM") {
chkall = target.querySelector('input[name="chkall"]');
} else if (target && target.type === "checkbox") {
chkall = target;
}
if (!chkall) return;
for (const checkbox of chkboxes) {
checkbox.checked = chkall.checked;
}
}
function btn_check(f, act)
{
if (act == "update") // 선택수정
+117 -4
View File
@@ -281,7 +281,7 @@ function auth_check($auth, $attr, $return = false)
$attr = strtolower($attr);
if (!strstr($auth, $attr)) {
if (strpos($auth, $attr) === false) {
if ($attr == 'r') {
$msg = '읽을 권한이 없습니다.';
if ($return) {
@@ -389,7 +389,7 @@ function order_select($fld, $sel = '')
// 불법접근을 막도록 토큰을 생성하면서 토큰값을 리턴
function get_admin_token()
{
$token = md5(uniqid(rand(), true));
$token = get_random_token_string(16);
set_session('ss_admin_token', $token);
return $token;
@@ -554,9 +554,18 @@ function admin_check_xss_params($params)
if (is_array($value)) {
admin_check_xss_params($value);
} else if ((preg_match('/<\s?[^\>]*\/?\s?>/i', $value) && (preg_match('/script.*?\/script/ius', $value) || preg_match('/(onload|onerror)=.*/ius', $value))) || preg_match('/^(?=.*token\()(?=.*xmlhttprequest\()(?=.*send\().*$/im', $value) || (preg_match('/(onload|onerror|focus)=.*/ius', $value) && preg_match('/(eval|expression|exec|prompt)(\s*)\((.*)\)/ius', $value))) {
} else if (
(preg_match('/<\s?[^\>]*\/?\s?>/i', $value) && (preg_match('/script.*?\/script/ius', $value) || preg_match('/on[a-z]+=*/ius', $value))) || preg_match('/^(?=.*token\()(?=.*xmlhttprequest\()(?=.*send\().*$/im', $value) ||
(preg_match('/(on[a-z]+|focus)=.*/ius', $value) && preg_match('/(eval|atob|fetch|expression|exec|prompt)(\s*)\((.*)\)/ius', $value))) {
alert('요청 쿼리에 잘못된 스크립트문장이 있습니다.\\nXSS 공격일수도 있습니다.', G5_URL);
die();
} else if (preg_match('/atob\s*\(\s*[\'"]?([a-zA-Z0-9+\/=]+)[\'"]?\s*\)/ius', $value, $matches)) {
$decoded = base64_decode($matches[1], true);
if ($decoded && preg_match('/(eval|fetch|script|alert|settimeout|setinterval)/ius', $decoded)) {
// error_log("Base64 XSS 시도 감지: key=$key, decoded=$decoded, IP=" . $_SERVER['REMOTE_ADDR']);
alert('Base64로 인코딩된 위험한 스크립트가 발견되었습니다.', G5_URL);
die();
}
}
}
@@ -601,6 +610,110 @@ function admin_menu_find_by($call, $search_key)
return '';
}
function admin_menu_local_path($url)
{
$url = (string) $url;
if (!$url) {
return '';
}
$url = preg_replace('/[?#].*$/', '', $url);
$maps = array(
G5_ADMIN_URL => G5_ADMIN_PATH,
);
if (defined('G5_SMS5_ADMIN_URL') && defined('G5_SMS5_ADMIN_PATH')) {
$maps[G5_SMS5_ADMIN_URL] = G5_SMS5_ADMIN_PATH;
}
foreach ($maps as $base_url => $base_path) {
if (strpos($url, $base_url) !== 0) {
continue;
}
$path = $base_path.substr($url, strlen($base_url));
if (substr($path, -1) === '/') {
$path .= 'index.php';
}
return $path;
}
return '';
}
function admin_menu_is_super_only($menu_item)
{
static $cache = array();
$sub_menu = isset($menu_item[0]) ? (string) $menu_item[0] : '';
if (!$sub_menu) {
return false;
}
if (isset($cache[$sub_menu])) {
return $cache[$sub_menu];
}
// 향후 메뉴 정의에서 명시적으로 최고관리자 전용 표시가 필요할 때 사용한다.
if (isset($menu_item[4]) && $menu_item[4] === 'super') {
return $cache[$sub_menu] = true;
}
$path = admin_menu_local_path(isset($menu_item[2]) ? $menu_item[2] : '');
if (!$path || !is_readable($path)) {
return $cache[$sub_menu] = false;
}
$content = file_get_contents($path, false, null, 0, 12000);
if ($content === false) {
return $cache[$sub_menu] = false;
}
$pattern = '/if\s*\([^\)]*\$is_admin\s*(?:!==|!=)\s*[\'"]super[\'"][^\)]*\)\s*\{?[\s\S]{0,250}(?:alert|alert_close|die)\s*\([^\;]*(?:최고관리자만|최고관리자로)/u';
return $cache[$sub_menu] = (bool) preg_match($pattern, $content);
}
function admin_get_assignable_auth_menu()
{
global $menu;
$assignable_auth_menu = array();
if (!isset($menu) || !is_array($menu)) {
return $assignable_auth_menu;
}
foreach ($menu as $menu_group) {
if (!is_array($menu_group)) {
continue;
}
for ($i=1; $i<count($menu_group); $i++) {
if (!isset($menu_group[$i]) || !is_array($menu_group[$i])) {
continue;
}
$sub_menu = isset($menu_group[$i][0]) ? $menu_group[$i][0] : '';
if (!$sub_menu || $sub_menu === '-' || substr($sub_menu, -3) === '000') {
continue;
}
if (admin_menu_is_super_only($menu_group[$i])) {
continue;
}
$assignable_auth_menu[$sub_menu] = isset($menu_group[$i][1]) ? $menu_group[$i][1] : '';
}
}
return $assignable_auth_menu;
}
// 접근 권한 검사
if (!$member['mb_id']) {
alert('로그인 하십시오.', G5_BBS_URL . '/login.php?url=' . urlencode(correct_goto_url(G5_ADMIN_URL)));
@@ -689,4 +802,4 @@ if (run_replace('safe_admin_add_script_boolean', false) === false) {
$config['cf_analytics'] = '';
$config['cf_add_script'] = '';
$config['cf_add_meta'] = '';
}
}
+1
View File
@@ -11,6 +11,7 @@ $menu['menu100'] = array(
array('100900', '캐시파일 일괄삭제', G5_ADMIN_URL . '/cache_file_delete.php', 'cf_cache', 1),
array('100910', '캡챠파일 일괄삭제', G5_ADMIN_URL . '/captcha_file_delete.php', 'cf_captcha', 1),
array('100920', '썸네일파일 일괄삭제', G5_ADMIN_URL . '/thumbnail_file_delete.php', 'cf_thumbnail', 1),
array('100930', '회원관리파일 일괄삭제', G5_ADMIN_URL . '/member_list_file_delete.php', 'cf_memberlist', 1),
array('100500', 'phpinfo()', G5_ADMIN_URL . '/phpinfo.php', 'cf_phpinfo')
);
+1
View File
@@ -2,6 +2,7 @@
$menu['menu200'] = array(
array('200000', '회원관리', G5_ADMIN_URL . '/member_list.php', 'member'),
array('200100', '회원관리', G5_ADMIN_URL . '/member_list.php', 'mb_list'),
array('200400', '회원관리파일', G5_ADMIN_URL . '/member_list_exel.php', 'mb_list'),
array('200300', '회원메일발송', G5_ADMIN_URL . '/mail_list.php', 'mb_mail'),
array('200800', '접속자집계', G5_ADMIN_URL . '/visit_list.php', 'mb_visit', 1),
array('200810', '접속자검색', G5_ADMIN_URL . '/visit_search.php', 'mb_search', 1),
+7
View File
@@ -3,6 +3,8 @@ if (!defined('G5_USE_SHOP') || !G5_USE_SHOP) {
return;
}
global $default;
$menu['menu400'] = array(
array('400000', '쇼핑몰관리', G5_ADMIN_URL . '/shop_admin/', 'shop_config'),
array('400010', '쇼핑몰현황', G5_ADMIN_URL . '/shop_admin/', 'shop_index'),
@@ -21,3 +23,8 @@ $menu['menu400'] = array(
array('400750', '추가배송비관리', G5_ADMIN_URL . '/shop_admin/sendcostlist.php', 'scf_sendcost', 1),
array('400410', '미완료주문', G5_ADMIN_URL . '/shop_admin/inorderlist.php', 'scf_inorder', 1),
);
// 결제방식이 KG이니시스이고 INIpay PRO를 사용할 때만 노출한다.
if (isset($default['de_pg_service']) && $default['de_pg_service'] === 'inicis' && !empty($default['de_inicis_pro_use'])) {
$menu['menu400'][] = array('400420', 'KG이니시스 PRO 현황', G5_ADMIN_URL . '/shop_admin/inicisloglist.php', 'scf_inicis_log');
}
+19 -3
View File
@@ -14,16 +14,32 @@ $print_version = ($is_admin == 'super') ? 'Version ' . G5_GNUBOARD_VER : '';
<strong>자바스크립트를 사용하지 않음</strong>으로 설정하신 경우는 수정이나 삭제시 별도의 경고창이 나오지 않으므로 이점 주의하시기 바랍니다.
</p>
</noscript>
</div>
<footer id="ft">
<p>
Copyright &copy; <?php echo $_SERVER['HTTP_HOST']; ?>. All rights reserved. <?php echo $print_version; ?><br>
Copyright &copy; <?php echo htmlspecialchars($_SERVER['HTTP_HOST']); ?>. All rights reserved. <?php echo $print_version; ?><br>
<button type="button" class="scroll_top"><span class="top_img"></span><span class="top_txt">TOP</span></button>
</p>
</footer>
</div>
<!-- 공통 레이어 팝업 컨테이너 -->
<div id="adminPopupContainer">
<div id="popupOverlay" class="popup-overlay is-hidden" onclick="PopupManager.close('popupOverlay')">
<div class="popup-content" onclick="event.stopPropagation()">
<div class="popup-header">
<strong id="popupTitle" class="popup-title"></strong>
<button type="button" class="popup-close-btn" onclick="PopupManager.close('popupOverlay')">
<i class="fa fa-close"></i><span class="sound_only">팝업 닫기</span>
</button>
</div>
<div class="popup-body" id="popupBody">
<!-- 동적으로 내용 주입 -->
</div>
<div class="popup-footer" id="popupFooter">
<!-- 버튼 등 동적으로 -->
</div>
</div>
</div>
</div>
<script>
+10 -5
View File
@@ -23,6 +23,9 @@ if (!$sst) {
$sst = "a.mb_id, au_menu";
$sod = "";
}
$allowed_sst = array('a.mb_id', 'mb_nick', 'au_menu', 'au_auth', 'a.mb_id, au_menu');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'a.mb_id, au_menu';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by $sst $sod ";
$sql = " select count(*) as cnt
@@ -51,6 +54,8 @@ $listall = '<a href="' . $_SERVER['SCRIPT_NAME'] . '" class="ov_listall btn_ov02
$g5['title'] = "관리권한설정";
require_once './admin.head.php';
$assignable_auth_menu = admin_get_assignable_auth_menu();
$colspan = 5;
?>
@@ -102,8 +107,8 @@ $colspan = 5;
$is_continue = true;
}
// 메뉴번호가 바뀌는 경우에 현재 없는 저장된 메뉴는 삭제함
if (!isset($auth_menu[$row['au_menu']])) {
// 메뉴번호가 바뀌거나 권한 부여 대상이 아닌 메뉴는 삭제함
if (!isset($assignable_auth_menu[$row['au_menu']])) {
sql_query(" delete from {$g5['auth_table']} where au_menu = '{$row['au_menu']}' ");
$is_continue = true;
}
@@ -127,7 +132,7 @@ $colspan = 5;
<td class="td_auth_mbnick"><?php echo $mb_nick ?></td>
<td class="td_menu">
<?php echo $row['au_menu'] ?>
<?php echo $auth_menu[$row['au_menu']] ?>
<?php echo $assignable_auth_menu[$row['au_menu']] ?>
</td>
<td class="td_auth"><?php echo $row['au_auth'] ?></td>
</tr>
@@ -151,7 +156,7 @@ $colspan = 5;
//if (isset($stx))
// echo '<script>document.fsearch.sfl.value = "'.$sfl.'";</script>'."\n";
if (strstr($sfl, 'mb_id')) {
if (strpos($sfl, 'mb_id') !== false) {
$mb_id = $stx;
} else {
$mb_id = '';
@@ -202,7 +207,7 @@ echo $pagelist;
<select id="au_menu" name="au_menu" required class="required">
<option value=''>선택하세요</option>
<?php
foreach ($auth_menu as $key => $value) {
foreach ($assignable_auth_menu as $key => $value) {
if (!(substr($key, -3) == '000' || $key == '-' || !$key)) {
echo '<option value="' . $key . '">' . $key . ' ' . $value . '</option>';
}
+6 -1
View File
@@ -13,12 +13,17 @@ if ($is_admin != 'super') {
}
$mb = get_member($mb_id);
if (!$mb['mb_id']) {
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
alert('존재하는 회원아이디가 아닙니다.');
}
check_admin_token();
$assignable_auth_menu = admin_get_assignable_auth_menu();
if (!$au_menu || !isset($assignable_auth_menu[$au_menu])) {
alert('해당 메뉴는 관리권한을 부여할 수 없습니다.');
}
require_once G5_CAPTCHA_PATH . '/captcha.lib.php';
if (!chk_captcha()) {
+1 -1
View File
@@ -12,7 +12,7 @@ $bo_table = isset($_POST['bo_table']) ? substr(preg_replace('/[^a-z0-9_]/i
$target_table = isset($_POST['target_table']) ? trim($_POST['target_table']) : '';
$target_subject = isset($_POST['target_subject']) ? trim($_POST['target_subject']) : '';
$target_subject = strip_tags(clean_xss_attributes($target_subject));
$target_subject = addslashes(strip_tags(clean_xss_attributes(stripslashes($target_subject))));
$file_copy = array();
+10 -6
View File
@@ -1439,7 +1439,7 @@ function frm_check_file(){
return false;
} else {
jQuery("#admin_captcha_box").hide();
// jQuery("#admin_captcha_box").hide();
}
return true;
@@ -1447,12 +1447,12 @@ function frm_check_file(){
jQuery(function($){
if( window.self !== window.top ){ // frame 또는 iframe을 사용할 경우 체크
$("#bo_include_head, #bo_include_tail").on("change paste keyup", function(e) {
frm_check_file();
});
use_captcha_check();
}
$("#bo_include_head, #bo_include_tail").on("change paste keyup", function(e) {
frm_check_file();
});
});
function fboardform_submit(f)
@@ -1487,10 +1487,14 @@ function fboardform_submit(f)
return false;
}
if (frm_check_file() == false) {
jQuery(window).scrollTop($('#bo_include_tail').offset().top - 30);
}
if( captcha_chk ) {
<?php echo isset($captcha_js) ? $captcha_js : ''; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
}
return true;
}
</script>
+37 -10
View File
@@ -12,8 +12,8 @@ check_admin_token();
$gr_id = isset($_POST['gr_id']) ? preg_replace('/[^a-z0-9_]/i', '', (string)$_POST['gr_id']) : '';
$bo_admin = isset($_POST['bo_admin']) ? preg_replace('/[^a-z0-9_\, \|\#]/i', '', $_POST['bo_admin']) : '';
$bo_subject = isset($_POST['bo_subject']) ? strip_tags(clean_xss_attributes($_POST['bo_subject'])) : '';
$bo_mobile_subject = isset($_POST['bo_mobile_subject']) ? strip_tags(clean_xss_attributes($_POST['bo_mobile_subject'])) : '';
$bo_subject = isset($_POST['bo_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bo_subject'])))) : '';
$bo_mobile_subject = isset($_POST['bo_mobile_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bo_mobile_subject'])))) : '';
if (!$gr_id) {
alert('그룹 ID는 반드시 선택하세요.');
@@ -36,10 +36,27 @@ if ($w == '' && in_array($bo_table, get_bo_table_banned_word())) {
$bo_include_head = isset($_POST['bo_include_head']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['bo_include_head'], 0, 255)) : '';
$bo_include_tail = isset($_POST['bo_include_tail']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['bo_include_tail'], 0, 255)) : '';
// 관리자가 자동등록방지를 사용해야 할 경우
if ($board && (isset($board['bo_include_head']) && $board['bo_include_head'] !== $bo_include_head || $board['bo_include_tail'] !== $bo_include_tail) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
$check_captcha = false;
// 관리자가 자동등록방지 CAPTCHA를 사용해야 할 경우
// 최고 관리자인 경우에만 수정가능
if ($is_admin === 'super') {
if ($w === 'u') {
if (isset($board['bo_include_head'], $board['bo_include_tail']) &&
($board['bo_include_head'] !== $bo_include_head || $board['bo_include_tail'] !== $bo_include_tail)) {
$check_captcha = true;
}
} elseif ($w === '') {
if ($bo_include_head !== '_head.php' || $bo_include_tail !== '_tail.php') {
$check_captcha = true;
}
}
}
// 실제 CAPTCHA 검증
if ($check_captcha) {
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
@@ -122,7 +139,7 @@ $bo_hot = isset($_POST['bo_hot']) ? (int) $_POST['bo_hot'] : 0;
$bo_image_width = isset($_POST['bo_image_width']) ? (int) $_POST['bo_image_width'] : 0;
$bo_use_search = isset($_POST['bo_use_search']) ? (int) $_POST['bo_use_search'] : 0;
$bo_use_cert = isset($_POST['bo_use_cert']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['bo_use_cert']) : '';
$bo_device = isset($_POST['bo_device']) ? clean_xss_tags($_POST['bo_device'], 1, 1) : '';
$bo_device = isset($_POST['bo_device']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_device']), 1, 1)) : '';
$bo_list_level = isset($_POST['bo_list_level']) ? (int) $_POST['bo_list_level'] : 0;
$bo_read_level = isset($_POST['bo_read_level']) ? (int) $_POST['bo_read_level'] : 0;
$bo_write_level = isset($_POST['bo_write_level']) ? (int) $_POST['bo_write_level'] : 0;
@@ -138,9 +155,9 @@ $bo_read_point = isset($_POST['bo_read_point']) ? (int) $_POST['bo_read_point']
$bo_write_point = isset($_POST['bo_write_point']) ? (int) $_POST['bo_write_point'] : 0;
$bo_comment_point = isset($_POST['bo_comment_point']) ? (int) $_POST['bo_comment_point'] : 0;
$bo_download_point = isset($_POST['bo_download_point']) ? (int) $_POST['bo_download_point'] : 0;
$bo_select_editor = isset($_POST['bo_select_editor']) ? clean_xss_tags($_POST['bo_select_editor'], 1, 1) : '';
$bo_skin = isset($_POST['bo_skin']) ? clean_xss_tags($_POST['bo_skin'], 1, 1) : '';
$bo_mobile_skin = isset($_POST['bo_mobile_skin']) ? clean_xss_tags($_POST['bo_mobile_skin'], 1, 1) : '';
$bo_select_editor = isset($_POST['bo_select_editor']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_select_editor']), 1, 1)) : '';
$bo_skin = isset($_POST['bo_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_skin']), 1, 1)) : '';
$bo_mobile_skin = isset($_POST['bo_mobile_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_mobile_skin']), 1, 1)) : '';
$bo_content_head = isset($_POST['bo_content_head']) ? $_POST['bo_content_head'] : '';
$bo_content_tail = isset($_POST['bo_content_tail']) ? $_POST['bo_content_tail'] : '';
$bo_mobile_content_head = isset($_POST['bo_mobile_content_head']) ? $_POST['bo_mobile_content_head'] : '';
@@ -159,7 +176,17 @@ $bo_write_min = isset($_POST['bo_write_min']) ? (int) $_POST['bo_write_min'] : 0
$bo_write_max = isset($_POST['bo_write_max']) ? (int) $_POST['bo_write_max'] : 0;
$bo_comment_min = isset($_POST['bo_comment_min']) ? (int) $_POST['bo_comment_min'] : 0;
$bo_comment_max = isset($_POST['bo_comment_max']) ? (int) $_POST['bo_comment_max'] : 0;
$bo_sort_field = isset($_POST['bo_sort_field']) ? clean_xss_tags($_POST['bo_sort_field'], 1, 1) : '';
$bo_sort_field = isset($_POST['bo_sort_field']) ? trim(stripslashes($_POST['bo_sort_field'])) : '';
$bo_allowed_sort_field = array('');
if (function_exists('get_board_sort_fields')) {
foreach (get_board_sort_fields(isset($board) ? $board : array()) as $bo_sort_v) {
$bo_allowed_sort_field[] = $bo_sort_v[0];
}
}
if (!in_array($bo_sort_field, $bo_allowed_sort_field, true)) {
$bo_sort_field = '';
}
$bo_sort_field = addslashes($bo_sort_field);
if (strpbrk($bo_skin.$bo_mobile_skin, "?%*:|\"<>") !== false) {
alert('스킨 디렉토리명 오류!');
+3
View File
@@ -32,6 +32,9 @@ if (!$sst) {
$sst = "a.gr_id, a.bo_table";
$sod = "asc";
}
$allowed_sst = array('a.gr_id', 'bo_table', 'bo_skin', 'bo_mobile_skin', 'bo_subject', 'bo_use_sns', 'bo_use_search', 'bo_order', 'a.gr_id, a.bo_table');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'a.gr_id, a.bo_table';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by $sst $sod ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
+1 -1
View File
@@ -46,7 +46,7 @@ if ($act_button === "선택수정") {
}
}
$p_bo_subject = is_array($_POST['bo_subject']) ? strip_tags(clean_xss_attributes($_POST['bo_subject'][$k])) : '';
$p_bo_subject = is_array($_POST['bo_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bo_subject'][$k])))) : '';
$sql = " update {$g5['board_table']}
set gr_id = '" . sql_real_escape_string($post_gr_id) . "',
+1 -1
View File
@@ -39,7 +39,7 @@ for ($i = 1; $i <= 10; $i++) {
foreach ($check_keys as $key => $value) {
if ($key === 'gr_subject') {
$posts[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
$posts[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
} else {
$posts[$key] = isset($_POST[$key]) ? $_POST[$key] : '';
}
+3
View File
@@ -34,6 +34,9 @@ if ($stx) {
$sql_search .= " ) ";
}
$allowed_sst = array('gr_id', 'gr_subject', 'gr_admin', 'gr_order');
if ($sst && !in_array($sst, $allowed_sst)) $sst = '';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
if ($sst) {
$sql_order = " order by {$sst} {$sod} ";
} else {
+2 -2
View File
@@ -21,7 +21,7 @@ if (!$chk_count) {
for ($i = 0; $i < $chk_count; $i++) {
$k = isset($post_chk[$i]) ? (int) $post_chk[$i] : 0;
$gr_id = preg_replace('/[^a-z0-9_]/i', '', $post_group_id[$k]);
$gr_subject = isset($_POST['gr_subject'][$k]) ? strip_tags(clean_xss_attributes($_POST['gr_subject'][$k])) : '';
$gr_subject = isset($_POST['gr_subject'][$k]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['gr_subject'][$k])))) : '';
$gr_admin = isset($_POST['gr_admin'][$k]) ? strip_tags(clean_xss_attributes($_POST['gr_admin'][$k])) : '';
$gr_device = isset($_POST['gr_device'][$k]) ? clean_xss_tags($_POST['gr_device'][$k], 1, 1, 10) : '';
$gr_use_access = isset($_POST['gr_use_access'][$k]) ? (int) $_POST['gr_use_access'][$k] : 0;
@@ -36,7 +36,7 @@ for ($i = 0; $i < $chk_count; $i++) {
gr_order = '" . $gr_order . "'
where gr_id = '{$gr_id}' ";
if ($is_admin != 'super') {
$sql .= " and gr_admin = '{$gr_admin}' ";
$sql .= " and gr_admin = '" . sql_real_escape_string($gr_admin) . "' ";
}
sql_query($sql);
} elseif ($act_button == '선택삭제') {
+3
View File
@@ -28,6 +28,9 @@ if (!$sst) {
$sst = "gm_datetime";
$sod = "desc";
}
$allowed_sst = array('gm_datetime', 'b.mb_id', 'b.mb_name', 'b.mb_nick', 'b.mb_today_login', 'a.gm_datetime');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'gm_datetime';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
+1 -1
View File
@@ -21,7 +21,7 @@ if (!is_file(G5_DATA_PATH . '/cache/browscap_cache.php')) {
}
require_once G5_PLUGIN_PATH . '/browscap/Browscap.php';
$browscap = new phpbrowscap\Browscap(G5_DATA_PATH . '/cache');
$browscap = new Browscap(G5_DATA_PATH . '/cache');
$browscap->doAutoUpdate = false;
$browscap->cacheFilename = 'browscap_cache.php';
+1 -1
View File
@@ -17,7 +17,7 @@ if ($is_admin != 'super') {
require_once G5_PLUGIN_PATH . '/browscap/Browscap.php';
$browscap = new phpbrowscap\Browscap(G5_DATA_PATH . '/cache');
$browscap = new Browscap(G5_DATA_PATH . '/cache');
$browscap->updateMethod = 'cURL';
$browscap->cacheFilename = 'browscap_cache.php';
$browscap->updateCache();
+148 -13
View File
@@ -415,13 +415,37 @@ if (!isset($config['cf_cert_use_seed'])) {
sql_query($sql, false);
}
if (!isset($config['cf_cert_kcp_enckey'])) {
$sql = "ALTER TABLE `{$g5['config_table']}`
$sql = "ALTER TABLE `{$g5['config_table']}`
ADD COLUMN `cf_cert_kcp_enckey` VARCHAR(100) NOT NULL DEFAULT '' AFTER `cf_cert_kcp_cd`; ";
sql_query($sql, false);
$config['cf_cert_kcp_enckey'] = '';
}
// 광고성 정보 수신 동의 사용 필드 추가
if (!isset($config['cf_use_promotion'])) {
sql_query(
" ALTER TABLE `{$g5['config_table']}`
ADD `cf_use_promotion` tinyint(1) NOT NULL DEFAULT '0' AFTER `cf_privacy` ",
true
);
}
// 광고성 정보 수신 동의 여부 필드 추가 + 메일 / SMS 수신 일자 추가
if (!isset($member['mb_marketing_agree'])) {
sql_query(
" ALTER TABLE `{$g5['member_table']}`
ADD `mb_marketing_agree` tinyint(1) NOT NULL DEFAULT '0' AFTER `mb_scrap_cnt`,
ADD `mb_marketing_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_marketing_agree`,
ADD `mb_thirdparty_agree` tinyint(1) NOT NULL DEFAULT '0' AFTER `mb_marketing_date`,
ADD `mb_thirdparty_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_thirdparty_agree`,
ADD `mb_agree_log` TEXT NOT NULL AFTER `mb_thirdparty_date`,
ADD `mb_mailling_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_mailling`,
ADD `mb_sms_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_sms` ",
true
);
}
if (!$config['cf_faq_skin']) {
$config['cf_faq_skin'] = "basic";
}
@@ -963,6 +987,17 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<th scope="row"><label for="cf_privacy">개인정보처리방침</label></th>
<td colspan="3"><textarea id="cf_privacy" name="cf_privacy" rows="10"><?php echo html_purifier($config['cf_privacy']); ?></textarea></td>
</tr>
<tr>
<th scope="row"><label for="cf_use_promotion">회원가입 약관 동의에<br>광고성 정보 수신 동의 표시 여부</label></th>
<td colspan="3">
<?php echo help('<b>광고성 정보 수신 · 마케팅 목적의 개인정보 수집 및 이용 · 개인정보 제 3자 제공</b> 여부를 설정합니다. <b>SMS 또는 카카오톡</b> 사용 시 <b>개인정보 제3자 제공</b>이 활성화됩니다.'); ?>
<?php echo help('동의한 회원에게 <b>카카오톡(친구톡)·문자</b>로 광고성 메시지를 발송할 수 있습니다.'); ?>
<?php echo help('<b>휴대전화번호</b> 사용을 위해서는 <b>기본환경설정 > 회원가입 > 휴대전화번호 입력</b>을 <b>[보이기]</b> 또는 <b>[필수입력]</b>으로 설정해야 하며, 미설정 시 수집이 불가합니다.'); ?>
<?php echo help('* 「정보통신망이용촉진및정보보호등에관한법률」에 따라 <b>광고성 정보 수신 동의</b>를 매 2년마다 반드시 확인해야 합니다.'); ?>
<input type="checkbox" name="cf_use_promotion" value="1" id="cf_use_promotion" <?php echo $config['cf_use_promotion'] ? 'checked' : ''; ?>>
<label for="cf_use_promotion">사용</label>
</td>
</tr>
</tbody>
</table>
</div>
@@ -1033,7 +1068,24 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<?php echo option_selected("", $config['cf_cert_hp'], "사용안함"); ?>
<?php echo option_selected("kcb", $config['cf_cert_hp'], "코리아크레딧뷰로(KCB) 휴대폰 본인확인"); ?>
<?php echo option_selected("kcp", $config['cf_cert_hp'], "NHN KCP 휴대폰 본인확인"); ?>
<?php echo option_selected("kcp_v2", $config['cf_cert_hp'], "NHN KCP 휴대폰 본인확인(api_v2)"); ?>
</select>
<div id="cf_cert_hp_kcp_v2_notice" style="display:<?php echo ($config['cf_cert_hp'] == 'kcp_v2') ? 'block' : 'none'; ?>; margin-top:8px; padding:10px 12px; background:#fff8e1; border:1px solid #ffd54f; border-radius:4px; color:#5d4037; line-height:1.5;">
<strong>NHN KCP 휴대폰 본인확인(api_v2)</strong> 사용 시,<br>
NHN KCP 상점관리자 &gt; 부가서비스 &gt; 휴대폰본인확인 &gt; 연동방식 설정 에서 <strong>신규 연동방식(V2) 사용여부를 &lsquo;사용&rsquo;</strong> 으로 변경해야 정상 동작합니다.<br>
PHP 7.0 이상 환경에서만 동작하며, PHP 7.0 미만에서는 사용할 수 없습니다.
</div>
<script>
jQuery(function($){
function toggle_kcp_v2_notice() {
var is_kcp_v2 = $('#cf_cert_hp').val() === 'kcp_v2';
$('#cf_cert_hp_kcp_v2_notice').toggle(is_kcp_v2);
}
$('#cf_cert_hp').on('change', toggle_kcp_v2_notice);
toggle_kcp_v2_notice();
});
</script>
</td>
</tr>
<tr>
@@ -1069,16 +1121,22 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<tr>
<th scope="row" class="cf_cert_service"><label for="cf_cert_kcp_cd">NHN KCP 사이트코드</label></th>
<td class="cf_cert_service">
<?php
$cf_cert_kcp_cd = get_sanitize_input($config['cf_cert_kcp_cd']);
if (preg_match('/^SM([A-Z0-9]{3})$/i', $cf_cert_kcp_cd, $matches)) {
$cf_cert_kcp_cd = $matches[1];
}
?>
<?php echo help('SM으로 시작하는 5자리 사이트 코드중 뒤의 3자리만 입력해 주십시오.<br>서비스에 가입되어 있지 않다면, 본인확인 서비스 신청페이지에서 서비스 신청 후 사이트코드를 발급 받으실 수 있습니다.') ?>
<span class="sitecode">SM</span>
<input type="text" name="cf_cert_kcp_cd" value="<?php echo get_sanitize_input($config['cf_cert_kcp_cd']); ?>" id="cf_cert_kcp_cd" class="frm_input" size="3"> <a href="http://sir.kr/main/service/p_cert.php" target="_blank" class="btn_frmline">NHN KCP 휴대폰 본인확인 서비스 신청페이지</a>
<span class="sitecode" id="cf_cert_kcp_cd_prefix">SM</span>
<input type="text" name="cf_cert_kcp_cd" value="<?php echo $cf_cert_kcp_cd; ?>" id="cf_cert_kcp_cd" class="frm_input" size="3" maxlength="3"> <a href="http://sir.kr/main/service/p_cert.php" target="_blank" class="btn_frmline">NHN KCP 휴대폰 본인확인 서비스 신청페이지</a>
</td>
</tr>
<tr>
<th scope="row" class="cf_cert_service"><label for="cf_cert_kcp_enckey">NHN KCP 가맹점 인증키</label></th>
<td class="cf_cert_service">
<?php echo help('(선택사항, 추후 NHN_KCP 상점관리자에서 인증키 발급 메뉴 오픈일정 이후부터 적용되는 내용입니다.)<br>NHN_KCP 상점관리자 > 기술관리센터 > 인증센터 > 가맹점 인증키관리 에서 인증키 발급 후에 인증키 정보를 입력') ?>
<input type="text" name="cf_cert_kcp_enckey" value="<?php echo get_sanitize_input($config['cf_cert_kcp_enckey']); ?>" id="cf_cert_kcp_enckey" class="frm_input" maxlength="100" size="40"> <a href="https://partner.kcp.co.kr" target="_blank" class="btn_frmline">NHN KCP 상점관리자</a>
<?php echo help('NHN KCP 상점관리자 > 기술관리센터 > 인증센터 > 가맹점 인증키관리 에서 인증키를 발급받아 입력해 주십시오.<br>NHN KCP 휴대폰 본인확인(api_v2)도 이 인증키 값을 사용합니다.') ?>
<input type="text" name="cf_cert_kcp_enckey" value="<?php echo get_sanitize_input($config['cf_cert_kcp_enckey']); ?>" id="cf_cert_kcp_enckey" class="frm_input" maxlength="100" size="70"> <a href="https://partner.kcp.co.kr" target="_blank" class="btn_frmline">NHN KCP 상점관리자</a>
</td>
</tr>
<tr>
@@ -1138,6 +1196,7 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<input type="checkbox" name="cf_formmail_is_member" value="1" id="cf_formmail_is_member" <?php echo $config['cf_formmail_is_member'] ? 'checked' : ''; ?>> 회원만 사용
</td>
</tr>
</tbody>
</table>
</div>
</section>
@@ -1350,7 +1409,7 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<tr>
<th scope="row"><label for="cf_twitter_key">트위터 컨슈머 Key</label></th>
<td>
<input type="text" name="cf_twitter_key" value="<?php echo get_sanitize_input($config['cf_twitter_key']); ?>" id="cf_twitter_key" class="frm_input" size="40"> <a href="https://developer.twitter.com/en/apps" target="_blank" class="btn_frmline">앱 등록하기</a>
<input type="text" name="cf_twitter_key" value="<?php echo get_sanitize_input($config['cf_twitter_key']); ?>" id="cf_twitter_key" class="frm_input" size="40"> <a href="https://console.x.com/" target="_blank" class="btn_frmline">앱 등록하기</a>
</td>
<th scope="row"><label for="cf_twitter_secret">트위터 컨슈머 Secret</label></th>
<td>
@@ -1360,7 +1419,7 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<tr>
<th scope="row"><label for="cf_google_clientid">구글 Client ID</label></th>
<td>
<input type="text" name="cf_google_clientid" value="<?php echo get_sanitize_input($config['cf_google_clientid']); ?>" id="cf_google_clientid" class="frm_input" size="40"> <a href="https://console.developers.google.com" target="_blank" class="btn_frmline">앱 등록하기</a>
<input type="text" name="cf_google_clientid" value="<?php echo get_sanitize_input($config['cf_google_clientid']); ?>" id="cf_google_clientid" class="frm_input" size="40"> <a href="https://console.cloud.google.com/auth/clients" target="_blank" class="btn_frmline">앱 등록하기</a>
</td>
<th scope="row"><label for="cf_google_secret">구글 Client Secret</label></th>
<td>
@@ -1376,7 +1435,7 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<tr>
<th scope="row"><label for="cf_kakao_rest_key">카카오 REST API 키</label></th>
<td>
<input type="text" name="cf_kakao_rest_key" value="<?php echo get_sanitize_input($config['cf_kakao_rest_key']); ?>" id="cf_kakao_rest_key" class="frm_input" size="40"> <a href="https://developers.kakao.com/product/kakaoLogin" target="_blank" class="btn_frmline">앱 등록하기</a>
<input type="text" name="cf_kakao_rest_key" value="<?php echo get_sanitize_input($config['cf_kakao_rest_key']); ?>" id="cf_kakao_rest_key" class="frm_input" size="40"> <a href="https://developers.kakao.com/console/app" target="_blank" class="btn_frmline">앱 등록하기</a>
</td>
<th scope="row"><label for="cf_kakao_client_secret">카카오 Client Secret</label></th>
<td>
@@ -1392,7 +1451,7 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<tr>
<th scope="row"><label for="cf_payco_clientid">페이코 Client ID</label></th>
<td>
<input type="text" name="cf_payco_clientid" value="<?php echo get_sanitize_input($config['cf_payco_clientid']); ?>" id="cf_payco_clientid" class="frm_input" size="40"> <a href="https://developers.payco.com/guide" target="_blank" class="btn_frmline">앱 등록하기</a>
<input type="text" name="cf_payco_clientid" value="<?php echo get_sanitize_input($config['cf_payco_clientid']); ?>" id="cf_payco_clientid" class="frm_input" size="40"> <a href="https://developers.payco.com/application/registView" target="_blank" class="btn_frmline">앱 등록하기</a>
</td>
<th scope="row"><label for="cf_payco_secret">페이코 Secret</label></th>
<td>
@@ -1526,7 +1585,6 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
</div>
</section>
<section id="anc_cf_extra">
<h2 class="h2_frm">여분필드 기본 설정</h2>
<?php echo $pg_anchor ?>
@@ -1557,7 +1615,17 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
</table>
</div>
</section>
<div id="config_captcha_wrap" style="display:none">
<h2>캡챠입력</h2>
<?php
require_once G5_CAPTCHA_PATH . '/captcha.lib.php';
$captcha_html = captcha_html();
$captcha_js = chk_captcha_js();
echo $captcha_html;
?>
</div>
<div class="btn_fixed_top btn_confirm">
<input type="submit" value="확인" class="btn_submit btn" accesskey="s">
</div>
@@ -1629,10 +1697,61 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
});
});
// 각 요소의 초기값 저장
var initialValues = {
cf_admin: $('#cf_admin').val(),
cf_analytics: $('#cf_analytics').val(),
cf_add_meta: $('#cf_add_meta').val(),
cf_add_script: $('#cf_add_script').val()
};
function check_config_captcha_open() {
var isChanged = false;
// 현재 값이 있는 경우에만 변경 여부 체크
if ($('#cf_admin').val()) {
isChanged = isChanged || $('#cf_admin').val() !== initialValues.cf_admin;
}
if ($('#cf_analytics').val()) {
isChanged = isChanged || $('#cf_analytics').val() !== initialValues.cf_analytics;
}
if ($('#cf_add_meta').val()) {
isChanged = isChanged || $('#cf_add_meta').val() !== initialValues.cf_add_meta;
}
if ($('#cf_add_script').val()) {
isChanged = isChanged || $('#cf_add_script').val() !== initialValues.cf_add_script;
}
var $wrap = $("#config_captcha_wrap"),
tooptipid = "mp_captcha_tooltip",
$p_text = $("<p>", {id:tooptipid, style:"font-size:0.95em;letter-spacing:-0.1em"}).html("중요정보를 수정할 경우 캡챠를 입력해야 합니다."),
$children = $wrap.children(':first'),
is_invisible_recaptcha = $("#captcha").hasClass("invisible_recaptcha");
if(isChanged){
$wrap.show();
if(! is_invisible_recaptcha) {
$wrap.css("margin-top","1em");
if(! $("#"+tooptipid).length){ $children.after($p_text) }
}
} else {
$wrap.hide();
if($("#"+tooptipid).length && ! is_invisible_recaptcha){ $children.next("#"+tooptipid).remove(); }
}
return isChanged;
}
function fconfigform_submit(f) {
var current_user_ip = "<?php echo $_SERVER['REMOTE_ADDR']; ?>";
var cf_intercept_ip_val = f.cf_intercept_ip.value;
if (check_config_captcha_open()){
jQuery("html, body").scrollTop(jQuery("#config_captcha_wrap").offset().top);
<?php echo $captcha_js; // 캡챠 사용시 자바스크립트에서 입력된 캡챠를 검사함 ?>
}
if (cf_intercept_ip_val && current_user_ip) {
var cf_intercept_ips = cf_intercept_ip_val.split("\n");
@@ -1653,6 +1772,22 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
f.action = "./config_form_update.php";
return true;
}
jQuery(function($){
$("#captcha_key").prop('required', false).removeAttr("required").removeClass("required");
// 최고관리자 변경시
$(document).on('change', '#cf_admin', check_config_captcha_open);
// 방문자분석 스크립트 변경시
$(document).on('input', '#cf_analytics', check_config_captcha_open);
// 추가 메타태그 변경시
$(document).on('input', '#cf_add_meta', check_config_captcha_open);
// 추가 script, css 변경시
$(document).on('input', '#cf_add_script', check_config_captcha_open);
});
</script>
<?php
+39 -3
View File
@@ -10,8 +10,11 @@ if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
$cf_title = isset($_POST['cf_title']) ? strip_tags(clean_xss_attributes($_POST['cf_title'])) : '';
$cf_admin = isset($_POST['cf_admin']) ? clean_xss_tags($_POST['cf_admin'], 1, 1) : '';
$sql = " select * from {$g5['config_table']} limit 1";
$ori_config = sql_fetch($sql);
$cf_title = isset($_POST['cf_title']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['cf_title'])))) : '';
$cf_admin = isset($_POST['cf_admin']) ? safe_replace_regex($_POST['cf_admin']) : '';
$mb = get_member($cf_admin);
@@ -138,6 +141,7 @@ $check_keys = array(
'cf_visit' => 'char',
'cf_stipulation' => 'text',
'cf_privacy' => 'text',
'cf_use_promotion' => 'int',
'cf_open_modify' => 'int',
'cf_memo_send_point' => 'int',
'cf_mobile_new_skin' => 'char',
@@ -169,7 +173,7 @@ foreach ($check_keys as $k => $v) {
if (in_array($k, array('cf_analytics', 'cf_add_meta', 'cf_add_script', 'cf_stipulation', 'cf_privacy'))) {
$_POST[$k] = isset($_POST[$k]) ? $_POST[$k] : '';
} else {
$_POST[$k] = isset($_POST[$k]) ? strip_tags(clean_xss_attributes($_POST[$k])) : '';
$_POST[$k] = isset($_POST[$k]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$k])))) : '';
}
}
}
@@ -185,6 +189,33 @@ if (!$_POST['cf_cert_use']) {
$_POST['cf_cert_simple'] = '';
}
// 관리자가 자동등록방지를 사용해야 할 경우 ( 기본환경설정에서 최고관리자, 방문자분석 스크립트, 추가 메타태그, 추가 script, css 변경시 )
$check_captcha = 0;
if ($cf_admin && $ori_config['cf_admin'] !== $cf_admin) {
$check_captcha = 1;
}
if ($_POST['cf_analytics'] && $ori_config['cf_analytics'] !== stripslashes($_POST['cf_analytics'])) {
$check_captcha = 1;
}
if ($_POST['cf_add_meta'] && $ori_config['cf_add_meta'] !== stripslashes($_POST['cf_add_meta'])) {
$check_captcha = 1;
}
if ($_POST['cf_add_script'] && $ori_config['cf_add_script'] !== stripslashes($_POST['cf_add_script'])) {
$check_captcha = 1;
}
if ($check_captcha) {
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
if (!chk_captcha()) {
alert('자동등록방지 숫자가 틀렸습니다.');
}
}
$sql = " update {$g5['config_table']}
set cf_title = '{$cf_title}',
cf_admin = '{$cf_admin}',
@@ -270,6 +301,7 @@ $sql = " update {$g5['config_table']}
cf_mobile_page_rows = '{$_POST['cf_mobile_page_rows']}',
cf_stipulation = '{$_POST['cf_stipulation']}',
cf_privacy = '{$_POST['cf_privacy']}',
cf_use_promotion = '{$_POST['cf_use_promotion']}',
cf_open_modify = '{$_POST['cf_open_modify']}',
cf_memo_send_point = '{$_POST['cf_memo_send_point']}',
cf_mobile_new_skin = '{$_POST['cf_mobile_new_skin']}',
@@ -346,6 +378,10 @@ if (isset($_POST['cf_bbs_rewrite'])) {
g5_delete_all_cache();
}
if (function_exists('get_admin_captcha_by')) {
get_admin_captcha_by('remove');
}
run_event('admin_config_form_update');
update_rewrite_rules();
+14 -3
View File
@@ -26,17 +26,28 @@ if ($w == "" || $w == "u") {
}
$co_id = isset($_REQUEST['co_id']) ? preg_replace('/[^a-z0-9_]/i', '', $_REQUEST['co_id']) : '';
$co_subject = isset($_POST['co_subject']) ? strip_tags(clean_xss_attributes($_POST['co_subject'])) : '';
$co_subject = isset($_POST['co_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['co_subject'])))) : '';
$co_include_head = isset($_POST['co_include_head']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_head'], 0, 255)) : '';
$co_include_tail = isset($_POST['co_include_tail']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_tail'], 0, 255)) : '';
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
if ($is_admin !== 'super') {
if ($w == 'u') {
$co_include_head = isset($co_row['co_include_head']) ? $co_row['co_include_head'] : '';
$co_include_tail = isset($co_row['co_include_tail']) ? $co_row['co_include_tail'] : '';
} else {
$co_include_head = '';
$co_include_tail = '';
}
}
$co_tag_filter_use = isset($_POST['co_tag_filter_use']) ? (int) $_POST['co_tag_filter_use'] : 1;
$co_himg_del = (isset($_POST['co_himg_del']) && $_POST['co_himg_del']) ? 1 : 0;
$co_timg_del = (isset($_POST['co_timg_del']) && $_POST['co_timg_del']) ? 1 : 0;
$co_html = isset($_POST['co_html']) ? (int) $_POST['co_html'] : 0;
$co_content = isset($_POST['co_content']) ? $_POST['co_content'] : '';
$co_mobile_content = isset($_POST['co_mobile_content']) ? $_POST['co_mobile_content'] : '';
$co_skin = isset($_POST['co_skin']) ? clean_xss_tags($_POST['co_skin'], 1, 1) : '';
$co_mobile_skin = isset($_POST['co_mobile_skin']) ? clean_xss_tags($_POST['co_mobile_skin'], 1, 1) : '';
$co_skin = isset($_POST['co_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['co_skin']), 1, 1)) : '';
$co_mobile_skin = isset($_POST['co_mobile_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['co_mobile_skin']), 1, 1)) : '';
// 관리자가 자동등록방지를 사용해야 할 경우
if (((isset($co_row['co_include_head']) && $co_row['co_include_head'] !== $co_include_head) || (isset($co_row['co_include_tail']) && $co_row['co_include_tail'] !== $co_include_tail)) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
+98 -14
View File
@@ -28,6 +28,39 @@ box-sizing: border-box;
h2{font-size: 1.083em;font-weight: bold;margin:10px 0}
#wrapper {min-height:480px}
/* admin 공통 */
/* 공통 - display none/block */
.is-hidden { display: none !important; }
.is-visible { display: block !important; }
/* 공통 - 뷰포트 (pc / mobile) 별 display none/block */
.pc-only { display: none; }
@media (min-width: 769px) { .pc-only { display: block !important; }}
.mobile-only { display: block; }
@media (min-width: 769px) { .mobile-only { display: none !important; }}
/* 공통 - 레이어 팝업 */
.popup-overlay { position: fixed; top: 0; left: 0; width: 100%; height: 100%; background: rgba(0,0,0,0.3); backdrop-filter: blur(6px); -webkit-backdrop-filter: blur(6px); z-index: 9999; display: flex; justify-content: center; align-items: center; }
.popup-content { background: #fff; border-radius: 10px; box-shadow: 0 8px 24px rgba(0,0,0,0.15); width: 800px; overflow: hidden; }
.popup-header, .popup-footer { padding: 18px 20px; display: flex; align-items: center; }
.popup-header { justify-content: space-between; border-bottom: 1px solid #e0e0e0; }
.popup-footer { gap: 20px; border-top: 1px solid #e0e0e0;}
.popup-close-btn { background: none; border: none; color: #888; font-size: 20px; cursor: pointer; padding: 4px; display: flex; align-items: center; justify-content: center; transition: color 0.2s ease; }
.popup-close-btn:hover { color: #333; }
.popup-title { font-size: 18px; font-weight: 600; }
.popup-body { padding: 20px; max-height: 400px; overflow-y: auto; color: #333; }
.popup-footer button { background: #3d70ff; color: white; border: 1px solid #3d70ff; padding: 8px 16px; border-radius: 6px; font-weight: 600; cursor: pointer; transition: background 0.2s ease, border-color 0.2s ease; }
.popup-footer button:hover { background: #2b3d9f; border-color: #2b3d9f; }
/* 공통 - tab */
.tab-container { display: flex; flex-direction: column; width: 100%; }
.tab-header { position: relative; bottom: -1px; display: flex; }
.tab-btn { padding: 10px 14px; background: none; border: none; border-bottom: 2px solid transparent; cursor: pointer; color: inherit; font: inherit; }
.tab-btn.active { border-bottom-color: #000; font-weight: bold; }
.tab-body { width: 100%; border-top: 1px solid #ccc; }
.tab-content { padding: 16px 0; }
/* 레이아웃 */
#hd h1 {position:absolute;font-size:0;line-height:0;overflow:hidden}
#hd_top{position:fixed;top:0;left:0;width:100%;height:50px;background:#3f51b5;z-index:1000}
@@ -95,9 +128,11 @@ box-shadow: 2px 0 2px rgba(150,150,150,0.1);}
#container.container-small #container_title{padding-left:70px}
.container_wr{padding:20px}
/* 화면낭독기 사용자용 */
/* 화면낭독기 사용자용 (스크린 리더 대응) */
/* 일반적인 .blind/.sr-only 사용시에 .sound_only 사용 권장 */
#hd_login_msg {position:absolute;top:0;left:0;width:1px;height:1px;overflow:hidden}
.msg_sound_only, .sound_only {display:inline-block !important;position:absolute;top:0;left:0;margin:0 !important;padding:0 !important;width:1px !important;height:1px !important;font-size:0;line-height:0;border:0 !important;overflow:hidden !important}
.sound_only, .msg_sound_only {overflow:hidden;position:absolute;width:1px;height:1px;margin:-1px;padding:0;clip:rect(0,0,0,0)}
/* 본문 바로가기 */
#to_content a {z-index:100000;position:absolute;top:0;left:0;font-size:0;line-height:0;overflow:hidden}
#to_content a:focus, #to_content a:active {width:100%;height:70px;background:#fff;font-size:2em;font-weight:bold;text-align:center;text-decoration:none;line-height:3.1em}
@@ -247,18 +282,14 @@ legend {position:absolute;width:0;height:0;font-size:0;line-height:0;text-indent
.anchor a {display:inline-block;padding:5px 10px;border:1px solid #c8ced1;background:#d6dde1;text-decoration:none}
.anchor .selected{background:#3f51b5}
#sort_mb {width:800px}
#sort_sodr {width:600px}
/* 하단 레이아웃 */
#ft{background:#f3f3f3;padding:0 25px;color:#777;text-align:center}
#ft p{line-height:50px;}
.scroll_top{position:fixed;bottom:10px;right:10px;width:50px;height:50px;border:0;text-align:center;background:#ddd;background:rgba(0,0,0,0.1)}
.scroll_top{position:fixed;bottom:10px;right:10px;width:50px;height:50px;border:0;text-align:center;background:#ddd;background:rgba(0,0,0,0.1);z-index:50;}
.scroll_top span.top_img{display:inline-block;width: 0; height: 0; border-left: 5px solid transparent;border-right: 5px solid transparent;
border-bottom: 5px solid black;}
.scroll_top span.top_txt{display:block}
@@ -281,9 +312,59 @@ border-bottom: 5px solid black;}
.local_sch03 button{height:30px;padding:0 5px;border:0;background:#9eacc6;color:#fff;}
.local_sch03 .btn_submit{height:30px;padding:0 5px;border:0;color:#fff;}
.local_sch03 .frm_input{height:30px;border:1px solid #dcdcdc;padding:0 5px;}
/* 회원 관리 데이터 필터링 */
.member_list_data { display: flex; flex-direction: column; padding: 20px; margin: 20px 0 40px; background: #f9f9f9; border: 1px solid #f2f2f2; color: #333; }
.sch_table { display: flex; flex-direction: column; gap: 10px; font-size: 11.5px; color: #333; }
.member_list_data .sch_row { display: flex; align-items: center; gap: 12px; min-height: 30px; }
.label { min-width: 120px; font-weight: 500; white-space: nowrap; display: flex; align-items: center; }
.label label {display: flex; gap: 10px;}
.field { flex: 1; display: flex; flex-wrap: wrap; align-items: center; gap: 8px; }
.field input[type="text"], .field input[type="number"], .field input[type="date"], .field select { height: 30px; min-width: 100px; padding: 0 10px; font-size: 11.5px; border: 1px solid #ddd; border-radius: 8px; background: #fff; transition: border-color 0.2s ease, box-shadow 0.2s ease; }
.field input[type="text"]:focus, .field input[type="number"]:focus, .field input[type="date"]:focus, .field select:focus { border-color: #6f809a; box-shadow: 0 0 0 2px rgba(63,81,181,0.1); outline: none; }
.field input::placeholder { color: #aaa; }
.field input[type="checkbox"], .field input[type="radio"] { width: 14px; height: 14px; accent-color: #536177; }
.radio_group { display: flex; gap: 15px; align-items: center; padding: 0 10px;}
.radio_group label {display: flex; align-items: center; gap: 5px;}
.ad_range_wrap {flex: 1; padding-left: 20px;}
.ad_range_box {display: flex;}
.ad_range_box .label {width: 109px;}
.sch_notice { font-size: 11px; color: #999; }
.sch_btn { display: flex; gap: 20px; justify-content: center; margin-top: 40px; }
.sch_btn { display: flex; gap: 10px; }
.btn_reset { display: flex; align-items: center; gap: 6px; padding: 0 20px; height: 40px; background: #9eacc6; color: #fff; font-weight: 600; border: none; border-radius: 8px; cursor: pointer; transition: background 0.2s ease, transform 0.15s ease; }
.btn_reset:hover { background: #5f6e89; }
.sch_btn button:not(.btn_reset) { padding: 0 20px; height: 40px; border: 1px solid #ccd1d8; background-color: #fff; color: #444; font-weight: 600; border-radius: 8px; cursor: pointer; user-select: none; transition: border-color 0.2s ease, box-shadow 0.2s ease; box-shadow: 0 1px 2px rgba(0,0,0,0.03); }
.sch_btn button:not(.btn_reset):hover { border-color: #6f809a; box-shadow: 0 2px 4px rgba(111, 128, 154, 0.15); }
.sch_btn button:not(.btn_reset):active { box-shadow: inset 0 1px 2px rgba(0,0,0,0.1); }
/* 회원 관리 다운로드 진행 팝업 */
.excel-download-progress p { color: #374151; }
.excel-download-progress .progress-desc { padding: 40px 0 32px; text-align: center; }
.excel-download-progress .progress-summary { margin-bottom: 6px; font-size: 16px; font-weight: 500; color: #111827; }
.excel-download-progress .progress-message { font-size: 20px; font-weight: 600; color: #3b82f6; }
.excel-download-progress .progress-error { color:red; }
.progress-spinner { display: flex; flex-direction: column; align-items: center; gap: 45px; padding: 24px 0; transition: all 0.2s ease; }
.spinner { width: 48px; height: 48px; border: 5px solid #3b82f6; border-top: 5px solid #fff; border-radius: 50%; animation: spin 0.8s linear infinite; }
@keyframes spin { to { transform: rotate(360deg); } }
.loading-message { text-align: center; font-size: 14px; color: #374151; }
.excel-download-progress .progress-download-box { margin-top: 24px; background: #f9fafb; padding: 20px; border-radius: 8px; box-shadow: 0 1px 2px rgba(0,0,0,0.03); }
.excel-download-progress .progress-download-box a { display: block; width: 100%; height: auto; text-align: center; margin-top: 8px; font-weight: 600; font-size: 14px; padding: 10px 20px; background: #fff; border: 1px solid #ccd1d8; border-radius: 8px; color: #444; cursor: pointer; transition: border-color 0.2s ease, box-shadow 0.2s ease; box-shadow: 0 1px 2px rgba(0,0,0,0.03); }
.excel-download-progress .progress-download-box a:hover { border-color: #6f809a; box-shadow: 0 2px 4px rgba(111, 128, 154, 0.15); }
.excel-download-progress .progress-download-box a:active { box-shadow: inset 0 1px 2px rgba(0,0,0,0.1); }
.field-select-form { display: grid; grid-template-columns: repeat(2, minmax(0, 1fr)); margin-top: 15px; gap: 0px 10px; padding: 10px; background-color: #f9fafb; border: 1px solid #e5e7eb; border-radius: 8px; color: #374151; }
.field-select-form label { display: flex; align-items: center; cursor: pointer; padding: 6px 10px; border-radius: 4px; }
.field-select-form label:hover { background-color: #f3f4f6; }
.field-select-form input[type="checkbox"] { margin-right: 8px; transform: scale(1.2); }
.field-separator { grid-column: 1 / -1; border-top: 1px solid #d1d5db; margin: 8px 0; }
.selected-fields-preview { padding: 8px; background-color: #eef2f7; border: 1px solid #d1d5db; border-radius: 6px; margin: 10px 0px; color: #1f2937; display: flex; align-items: center; flex-wrap: wrap; gap: 8px; }
.selected-fields-preview strong { padding: 4px 8px; }
.selected-fields-preview .field-tag { background-color: #dbeafe; color: #1e40af; padding: 4px 8px; border-radius: 4px; }
/* 페이지 내 실행 */
.local_cmd {min-width:960px}
.local_cmd01 {margin:0 0 10px;padding:0 }
.local_cmd01 .cmd_tit {font-weight:bold}
.local_cmd01 .btn_submit {padding:3px 5px;border:1px solid #ff3061;color:#fff;font-size:0.95em;vertical-align:middle}
@@ -298,7 +379,7 @@ border-bottom: 5px solid black;}
.local_desc01 {margin:10px 0 10px ;padding:10px 20px;border:1px solid #f2f2f2;background:#f9f9f9}
.local_desc01 strong {color:#ff3061}
.local_desc01 a {text-decoration:underline}
.local_desc01 a {text-decoration:underline;text-underline-offset:2px;}
.local_desc02 {margin:10px 0 ;min-width:960px} /* 주로 온라인 서식 관련 안내 내용에 사용 */
.local_desc02 p {padding:0;line-height:1.8em}
@@ -401,6 +482,7 @@ tfoot th {}
.mb_leave_msg {color:#b6b6b6}
.mb_intercept_msg {color:#ff0000}
#point_mng {margin-top:50px}
.ad_agree_log {max-height: 150px !important;}
/* 게시판추가/수정 */
#anc_bo_extra .td_grpset label {width:auto}
@@ -504,6 +586,7 @@ td.td_grpset {width:160px;border-left:1px solid #e9ecee;text-align:center}
.td_time{text-align:center;width:130px}
.td_center{text-align:center;}
.td_type{width:120px}
.td_consent{min-width:70px;max-width:200px}
.td_mng_s{width:60px}
.td_mng_m{width:100px}
@@ -656,14 +739,15 @@ a.nicepay_btn{display:inline-block;margin:5px 0 0;padding:5px 10px;background:#0
ul.de_pg_tab{margin:0;padding:0;zoom:1}
ul.de_pg_tab:after{display:block;visibility:hidden;clear:both;content:"";}
ul.de_pg_tab li{position:relative;display:inline-block;float:left;text-align:center;margin:0;padding:0;width:120px}
ul.de_pg_tab li a{margin:0 2px;display:block;overflow:hidden;text-overflow:ellipsis;white-space:nowrap;line-height:2.5;background-color:#f7f7f7;color:#74777b;font-weight:bold;font-size:1.2em;text-decoration:none}
ul.de_pg_tab li{position:relative;display:inline-block;float:left;text-align:center;margin:0;padding:0;min-width:130px}
ul.de_pg_tab li a{margin:0 2px;display:block;overflow:hidden;text-overflow:ellipsis;white-space:nowrap;line-height:2.5;background-color:#f7f7f7;color:#74777b;font-weight:bold;font-size:1.2em;text-decoration:none; padding:0px 10px;}
ul.de_pg_tab li a:hover{text-decoration:none}
ul.de_pg_tab li.tab-current a{background:#2CC185;color:#fff}
.pg_info_fld{position:relative}
.kcp_info_fld th{background-color:#F6FCFF}
.lg_info_fld th{background-color:#FFF4FA}
.lg_info_fld_v2 th{background-color:#ffe8f5}
.inicis_info_fld th{background-color:#F6F1FF}
.kakao_info_fld th{background-color:#FFFCED}
.naver_info_fld th{background-color:#F3FFF3}
@@ -999,8 +1083,8 @@ box-shadow: 2px 2px 3px 0px rgba(0,0,0,0.2);}
.sevice_1 h4{width:100%;padding:0; margin:0;border-top:1px solid #ebe8e8;}
.sevice_1 h4 a{display:inline-block;height:75px;padding:10px 0 0;width:100%}
.svc_card{background:url('../img/service_img1.jpg') no-repeat top center;margin-right:13px;}
.svc_card ul li{width:33%;}
.svc_card{background:url('../img/service_img1.jpg') no-repeat top center;margin-right:13px;width:520px;}
.svc_card ul li{width:25%;box-sizing:border-box;}
.svc_phone {background:url('../img/service_img2.jpg') no-repeat top center;margin-right:13px;}
.svc_phone ul li{width:50%;}
.svc_ipin {background:url('../img/service_img3.jpg') no-repeat top center;}
@@ -1133,4 +1217,4 @@ input[type="text"]{max-width:200px}
@media only screen and (max-device-width : 480px) and (orientation : portrait){
/* Styles */
input[type="text"]{max-width:200px}
}
}
+363 -1
View File
@@ -269,6 +269,368 @@ while ($row = sql_fetch_array($result)){
}
}
// SMS5 테이블 G5_TABLE_PREFIX 적용
if($g5['sms5_prefix'] != 'sms5_' && sql_num_rows(sql_query("show tables like 'sms5_config'")))
{
$tables = array('config','write','history','book','book_group','form','form_group');
foreach($tables as $name){
$old_table = 'sms5_' . $name;
$new_table = $g5['sms5_prefix'] . $name;
// 기존 테이블이 있고, G5_TABLE_PREFIX 적용 테이블이 없을 경우 → 테이블명 변경
if(sql_num_rows(sql_query("SHOW TABLES LIKE '{$old_table}' "))){
if(!sql_num_rows(sql_query("SHOW TABLES LIKE '{$new_table}' "))){
sql_query("RENAME TABLE {$old_table} TO {$new_table}", false);
}
}
}
$is_check = true;
}
// 광고성 정보 수신 동의 사용 필드 추가
if (!isset($config['cf_use_promotion'])) {
sql_query(
" ALTER TABLE `{$g5['config_table']}`
ADD `cf_use_promotion` tinyint(1) NOT NULL DEFAULT '0' AFTER `cf_privacy` ",
true
);
$is_check = true;
}
// 광고성 정보 수신 동의 여부 필드 추가 + 메일 / SMS 수신 일자 추가
if (!isset($member['mb_marketing_agree'])) {
sql_query(
" ALTER TABLE `{$g5['member_table']}`
ADD `mb_marketing_agree` tinyint(1) NOT NULL DEFAULT '0' AFTER `mb_scrap_cnt`,
ADD `mb_marketing_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_marketing_agree`,
ADD `mb_thirdparty_agree` tinyint(1) NOT NULL DEFAULT '0' AFTER `mb_marketing_date`,
ADD `mb_thirdparty_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_thirdparty_agree`,
ADD `mb_agree_log` TEXT NOT NULL AFTER `mb_thirdparty_date`,
ADD `mb_mailling_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_mailling`,
ADD `mb_sms_date` datetime NOT NULL DEFAULT '0000-00-00 00:00:00' AFTER `mb_sms` ",
true
);
$is_check = true;
}
// 쿠폰 로그 테이블에 UNIQUE 인덱스 추가 (쿠폰 이중사용 방지)
if (defined('G5_USE_SHOP') && G5_USE_SHOP) {
$result = sql_query("SHOW INDEX FROM `{$g5['g5_shop_coupon_log_table']}` WHERE Key_name = 'idx_coupon_use'", false);
if (!$result || !sql_num_rows($result)) {
// 기존에 동일 쿠폰이 중복 사용된 데이터가 있으면 UNIQUE 인덱스 생성 실패하므로 중복 데이터 정리
$dup_sql = " SELECT cp_id, mb_id, MIN(cl_id) as keep_id
FROM `{$g5['g5_shop_coupon_log_table']}`
GROUP BY cp_id, mb_id
HAVING COUNT(*) > 1 ";
$dup_result = sql_query($dup_sql, false);
if ($dup_result && sql_num_rows($dup_result)) {
while ($dup_row = sql_fetch_array($dup_result)) {
echo $dup_row['cp_id']." 의 동일 쿠폰이 중복 사용된 데이터가 있으므로 인덱스 생성이 불가합니다. <br>";
$sql = " DELETE FROM `{$g5['g5_shop_coupon_log_table']}`
WHERE cp_id = '{$dup_row['cp_id']}'
AND mb_id = '{$dup_row['mb_id']}'
AND cl_id != '{$dup_row['keep_id']}' ";
if ($is_admin === 'super') {
echo "데이터베이스에서 검토후에 이 쿼리문을 실행해 주세요.<br>$sql<br>";
}
// sql_query($sql);
}
}
// MyISAM + utf8mb4 환경에서 키 길이 초과 방지: cp_id varchar(100), mb_id varchar(100)으로 조정
sql_query("ALTER TABLE `{$g5['g5_shop_coupon_log_table']}` MODIFY `cp_id` varchar(100) NOT NULL DEFAULT '', MODIFY `mb_id` varchar(100) NOT NULL DEFAULT ''", false);
sql_query("ALTER TABLE `{$g5['g5_shop_coupon_log_table']}` ADD UNIQUE KEY `idx_coupon_use` (`cp_id`, `mb_id`)", false);
$is_check = true;
}
}
// 자동 로그인 토큰 테이블 생성 (KVE-2026-0610: 추측 가능한 자동 로그인 쿠키 위조 방지)
// 다중 디바이스 지원을 위해 회원당 여러 토큰을 별도 테이블로 관리
if (!isset($g5['member_auto_login_table'])) {
$g5['member_auto_login_table'] = G5_TABLE_PREFIX.'member_auto_login';
}
if (!sql_query(" DESC `{$g5['member_auto_login_table']}` ", false)) {
sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['member_auto_login_table']}` (
`al_id` int(11) NOT NULL auto_increment,
`mb_id` varchar(20) NOT NULL default '',
`al_token` varchar(64) NOT NULL default '',
`al_user_agent` varchar(255) NOT NULL default '',
`al_ip` varchar(45) NOT NULL default '',
`al_created` datetime DEFAULT NULL,
`al_last_used` datetime DEFAULT NULL,
`al_expire` datetime DEFAULT NULL,
PRIMARY KEY (`al_id`),
UNIQUE KEY `al_token` (`al_token`),
KEY `mb_id` (`mb_id`),
KEY `al_expire` (`al_expire`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8 ", true);
$is_check = true;
}
// KG이니시스 결제 처리 현황 및 단계별 이력 테이블
if (defined('G5_USE_SHOP') && G5_USE_SHOP) {
$inicis_pro_config_columns = array(
'de_inicis_pro_alert_use' => "ADD COLUMN `de_inicis_pro_alert_use` tinyint(4) NOT NULL DEFAULT '1'",
'de_inicis_pro_reconcile_use' => "ADD COLUMN `de_inicis_pro_reconcile_use` tinyint(4) NOT NULL DEFAULT '0'",
'de_inicis_pro_log_days' => "ADD COLUMN `de_inicis_pro_log_days` int(11) NOT NULL DEFAULT '365'",
'de_inicis_pro_summary_days' => "ADD COLUMN `de_inicis_pro_summary_days` int(11) NOT NULL DEFAULT '1825'",
'de_inicis_pro_monitor_at' => "ADD COLUMN `de_inicis_pro_monitor_at` datetime DEFAULT NULL",
'de_inicis_pro_monitor_message' => "ADD COLUMN `de_inicis_pro_monitor_message` varchar(255) NOT NULL DEFAULT ''"
);
$inicis_pro_config_alter = array();
foreach ($inicis_pro_config_columns as $column => $alter) {
$column_result = sql_query(" SHOW COLUMNS FROM `{$g5['g5_shop_default_table']}` LIKE '$column' ", false);
if (!$column_result || sql_num_rows($column_result) === 0)
$inicis_pro_config_alter[] = $alter;
}
if (count($inicis_pro_config_alter)) {
sql_query(" ALTER TABLE `{$g5['g5_shop_default_table']}` ".implode(', ', $inicis_pro_config_alter), true);
$is_check = true;
}
if (!isset($g5['g5_shop_inicis_pay_table']))
$g5['g5_shop_inicis_pay_table'] = G5_SHOP_TABLE_PREFIX.'inicis_pay';
if (!isset($g5['g5_shop_inicis_pay_event_table']))
$g5['g5_shop_inicis_pay_event_table'] = G5_SHOP_TABLE_PREFIX.'inicis_pay_event';
if (!sql_query(" DESC `{$g5['g5_shop_inicis_pay_table']}` ", false)) {
sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['g5_shop_inicis_pay_table']}` (
`ip_id` int(11) NOT NULL AUTO_INCREMENT,
`ip_oid` varchar(64) NOT NULL DEFAULT '',
`ip_tid` varchar(80) NOT NULL DEFAULT '',
`ip_auth_tid` varchar(80) NOT NULL DEFAULT '',
`ip_mid` varchar(80) NOT NULL DEFAULT '',
`ip_environment` varchar(10) NOT NULL DEFAULT '',
`mb_id` varchar(20) NOT NULL DEFAULT '',
`ip_amount` int(11) NOT NULL DEFAULT '0',
`ip_pay_type` varchar(20) NOT NULL DEFAULT '',
`ip_easy_pay` varchar(20) NOT NULL DEFAULT '',
`ip_device` varchar(10) NOT NULL DEFAULT '',
`ip_order_type` varchar(10) NOT NULL DEFAULT '',
`ip_status` varchar(30) NOT NULL DEFAULT '',
`ip_result_code` varchar(30) NOT NULL DEFAULT '',
`ip_result_message` varchar(255) NOT NULL DEFAULT '',
`ip_noti_status` varchar(30) NOT NULL DEFAULT '',
`ip_noti_code` varchar(30) NOT NULL DEFAULT '',
`ip_noti_message` varchar(255) NOT NULL DEFAULT '',
`ip_noti_failed_count` int(11) NOT NULL DEFAULT '0',
`ip_noti_at` datetime DEFAULT NULL,
`ip_cancel_status` varchar(30) NOT NULL DEFAULT '',
`ip_cancel_code` varchar(30) NOT NULL DEFAULT '',
`ip_cancel_message` varchar(255) NOT NULL DEFAULT '',
`ip_cancel_checked_at` datetime DEFAULT NULL,
`ip_refund_required` tinyint(4) NOT NULL DEFAULT '0',
`ip_vbank_due_at` datetime DEFAULT NULL,
`ip_expired_at` datetime DEFAULT NULL,
`ip_order_exists` tinyint(4) NOT NULL DEFAULT '0',
`ip_approved_at` datetime DEFAULT NULL,
`ip_ordered_at` datetime DEFAULT NULL,
`ip_notified_at` datetime DEFAULT NULL,
`ip_canceled_at` datetime DEFAULT NULL,
`ip_created_at` datetime DEFAULT NULL,
`ip_updated_at` datetime DEFAULT NULL,
`ip_ip` varchar(45) NOT NULL DEFAULT '',
`ip_event_count` int(11) NOT NULL DEFAULT '0',
`ip_audit_error` tinyint(4) NOT NULL DEFAULT '0',
`ip_alerted_at` datetime DEFAULT NULL,
`ip_alert_key` varchar(64) NOT NULL DEFAULT '',
`ip_pg_status` varchar(30) NOT NULL DEFAULT '',
`ip_pg_amount` int(11) NOT NULL DEFAULT '0',
`ip_pg_tid` varchar(80) NOT NULL DEFAULT '',
`ip_pg_result_code` varchar(30) NOT NULL DEFAULT '',
`ip_pg_message` varchar(255) NOT NULL DEFAULT '',
`ip_pg_checked_at` datetime DEFAULT NULL,
PRIMARY KEY (`ip_id`),
UNIQUE KEY `ip_oid` (`ip_oid`),
KEY `ip_tid` (`ip_tid`),
KEY `ip_auth_tid` (`ip_auth_tid`),
KEY `ip_status` (`ip_status`),
KEY `ip_noti_status` (`ip_noti_status`),
KEY `ip_cancel_status` (`ip_cancel_status`),
KEY `ip_refund_required` (`ip_refund_required`),
KEY `ip_updated_at` (`ip_updated_at`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8 ", true);
$is_check = true;
}
if (sql_query(" DESC `{$g5['g5_shop_inicis_pay_table']}` ", false)) {
$inicis_pay_columns = array(
'ip_environment' => "ADD COLUMN `ip_environment` varchar(10) NOT NULL DEFAULT '' AFTER `ip_mid`",
'ip_easy_pay' => "ADD COLUMN `ip_easy_pay` varchar(20) NOT NULL DEFAULT '' AFTER `ip_pay_type`",
'ip_noti_status' => "ADD COLUMN `ip_noti_status` varchar(30) NOT NULL DEFAULT '' AFTER `ip_result_message`",
'ip_noti_code' => "ADD COLUMN `ip_noti_code` varchar(30) NOT NULL DEFAULT '' AFTER `ip_noti_status`",
'ip_noti_message' => "ADD COLUMN `ip_noti_message` varchar(255) NOT NULL DEFAULT '' AFTER `ip_noti_code`",
'ip_noti_failed_count' => "ADD COLUMN `ip_noti_failed_count` int(11) NOT NULL DEFAULT '0' AFTER `ip_noti_message`",
'ip_noti_at' => "ADD COLUMN `ip_noti_at` datetime DEFAULT NULL AFTER `ip_noti_failed_count`",
'ip_cancel_status' => "ADD COLUMN `ip_cancel_status` varchar(30) NOT NULL DEFAULT '' AFTER `ip_noti_at`",
'ip_cancel_code' => "ADD COLUMN `ip_cancel_code` varchar(30) NOT NULL DEFAULT '' AFTER `ip_cancel_status`",
'ip_cancel_message' => "ADD COLUMN `ip_cancel_message` varchar(255) NOT NULL DEFAULT '' AFTER `ip_cancel_code`",
'ip_cancel_checked_at' => "ADD COLUMN `ip_cancel_checked_at` datetime DEFAULT NULL AFTER `ip_cancel_message`",
'ip_refund_required' => "ADD COLUMN `ip_refund_required` tinyint(4) NOT NULL DEFAULT '0' AFTER `ip_cancel_checked_at`",
'ip_vbank_due_at' => "ADD COLUMN `ip_vbank_due_at` datetime DEFAULT NULL AFTER `ip_refund_required`",
'ip_expired_at' => "ADD COLUMN `ip_expired_at` datetime DEFAULT NULL AFTER `ip_vbank_due_at`",
'ip_audit_error' => "ADD COLUMN `ip_audit_error` tinyint(4) NOT NULL DEFAULT '0'",
'ip_alerted_at' => "ADD COLUMN `ip_alerted_at` datetime DEFAULT NULL",
'ip_alert_key' => "ADD COLUMN `ip_alert_key` varchar(64) NOT NULL DEFAULT ''",
'ip_pg_status' => "ADD COLUMN `ip_pg_status` varchar(30) NOT NULL DEFAULT ''",
'ip_pg_amount' => "ADD COLUMN `ip_pg_amount` int(11) NOT NULL DEFAULT '0'",
'ip_pg_tid' => "ADD COLUMN `ip_pg_tid` varchar(80) NOT NULL DEFAULT ''",
'ip_pg_result_code' => "ADD COLUMN `ip_pg_result_code` varchar(30) NOT NULL DEFAULT ''",
'ip_pg_message' => "ADD COLUMN `ip_pg_message` varchar(255) NOT NULL DEFAULT ''",
'ip_pg_checked_at' => "ADD COLUMN `ip_pg_checked_at` datetime DEFAULT NULL"
);
$inicis_pay_alter = array();
foreach ($inicis_pay_columns as $column => $alter) {
$column_result = sql_query(" SHOW COLUMNS FROM `{$g5['g5_shop_inicis_pay_table']}` LIKE '$column' ", false);
if (!$column_result || sql_num_rows($column_result) === 0)
$inicis_pay_alter[] = $alter;
}
if (count($inicis_pay_alter)) {
sql_query(" ALTER TABLE `{$g5['g5_shop_inicis_pay_table']}` ".implode(', ', $inicis_pay_alter), true);
$is_check = true;
}
if (count($inicis_pay_alter)) {
$environment = !empty($default['de_card_test']) ? 'test' : 'live';
sql_query(" insert ignore into `{$g5['g5_shop_inicis_pay_table']}`
(ip_oid, ip_environment, ip_status, ip_noti_status, ip_noti_code, ip_noti_message,
ip_noti_failed_count, ip_noti_at, ip_created_at, ip_updated_at, ip_event_count)
select e.ip_oid, '$environment', e.pe_status, e.pe_status, e.pe_code, e.pe_message,
sum(if(e.pe_status = 'notification_failed', 1, 0)), max(e.pe_created_at),
min(e.pe_created_at), max(e.pe_created_at), count(*)
from `{$g5['g5_shop_inicis_pay_event_table']}` e
left join `{$g5['g5_shop_inicis_pay_table']}` p on p.ip_oid = e.ip_oid
where p.ip_id is null
and e.pe_stage = 'notification'
group by e.ip_oid ", false);
sql_query(" update `{$g5['g5_shop_inicis_pay_table']}`
set ip_environment = case
when lower(ip_mid) in ('inipaytest','iniescrow0') then 'test'
when ip_mid <> '' then 'live'
else '$environment'
end
where ip_environment = '' ", false);
sql_query(" update `{$g5['g5_shop_inicis_pay_table']}` p
inner join (
select ip_oid, max(pe_id) as pe_id,
sum(if(pe_status = 'notification_failed', 1, 0)) as fail_count
from `{$g5['g5_shop_inicis_pay_event_table']}`
where pe_stage = 'notification'
group by ip_oid
) x on x.ip_oid = p.ip_oid
inner join `{$g5['g5_shop_inicis_pay_event_table']}` e on e.pe_id = x.pe_id
set p.ip_noti_status = e.pe_status,
p.ip_noti_code = e.pe_code,
p.ip_noti_message = e.pe_message,
p.ip_noti_failed_count = x.fail_count,
p.ip_noti_at = e.pe_created_at ", false);
sql_query(" update `{$g5['g5_shop_inicis_pay_table']}` p
inner join (
select ip_oid, max(pe_id) as pe_id
from `{$g5['g5_shop_inicis_pay_event_table']}`
where pe_stage = 'cancel'
group by ip_oid
) x on x.ip_oid = p.ip_oid
inner join `{$g5['g5_shop_inicis_pay_event_table']}` e on e.pe_id = x.pe_id
set p.ip_cancel_status = e.pe_status,
p.ip_cancel_code = e.pe_code,
p.ip_cancel_message = e.pe_message,
p.ip_cancel_checked_at = e.pe_created_at ", false);
sql_query(" update `{$g5['g5_shop_inicis_pay_table']}` p
inner join `{$g5['g5_shop_inicis_pay_event_table']}` e on e.ip_oid = p.ip_oid and e.pe_stage = 'request'
set p.ip_easy_pay = case
when e.pe_message like '삼성페이%' then 'SAMSUNGPAY'
when e.pe_message like 'lpay%' then 'LPAY'
when e.pe_message like 'inicis_kakaopay%' then 'KAKAOPAY'
when e.pe_message like '간편결제%' then 'EASYPAY'
else p.ip_easy_pay
end
where p.ip_easy_pay = '' ", false);
sql_query(" update `{$g5['g5_shop_inicis_pay_table']}`
set ip_noti_status = case
when ip_status = 'paid' then 'paid'
when ip_status = 'vbank_issued' then 'vbank_issued'
when ip_status = 'notification_received' then 'notification_received'
else ip_noti_status
end,
ip_cancel_status = case
when ip_status in ('canceled','cancel_failed','partial_canceled','partial_cancel_failed') then ip_status
else ip_cancel_status
end ", false);
sql_query(" update `{$g5['g5_shop_inicis_pay_table']}` p
inner join {$g5['g5_shop_order_table']} o on o.od_id = p.ip_oid
set p.ip_status = 'paid_after_cancel',
p.ip_refund_required = '1',
p.ip_noti_status = 'paid_after_cancel',
p.ip_noti_message = '취소 주문에 가상계좌 입금 확인'
where p.ip_pay_type = 'VBANK'
and p.ip_status = 'paid'
and o.od_status = '취소'
and o.od_receipt_price > 0 ", false);
$inicis_pro_migrated_at = G5_TIME_YMDHIS;
$inicis_pro_migrated_message = '기존 결제·주문 이력 대조에서 취소 후 입금 확인';
sql_query(" insert into `{$g5['g5_shop_inicis_pay_event_table']}`
(ip_oid, ip_tid, pe_stage, pe_status, pe_code, pe_message, pe_source, pe_ip, pe_created_at)
select p.ip_oid, p.ip_tid, 'reconcile', 'paid_after_cancel', '',
'".sql_escape_string($inicis_pro_migrated_message)."', 'system', '', '$inicis_pro_migrated_at'
from `{$g5['g5_shop_inicis_pay_table']}` p
left join `{$g5['g5_shop_inicis_pay_event_table']}` e
on e.ip_oid = p.ip_oid and e.pe_status = 'paid_after_cancel'
where p.ip_status = 'paid_after_cancel'
and p.ip_refund_required = '1'
and e.pe_id is null ", false);
sql_query(" update `{$g5['g5_shop_inicis_pay_table']}` p
inner join `{$g5['g5_shop_inicis_pay_event_table']}` e
on e.ip_oid = p.ip_oid
and e.pe_status = 'paid_after_cancel'
and e.pe_message = '".sql_escape_string($inicis_pro_migrated_message)."'
and e.pe_created_at = '$inicis_pro_migrated_at'
set p.ip_event_count = p.ip_event_count + 1 ", false);
}
$inicis_pay_indexes = array(
'ip_noti_status' => "ADD KEY `ip_noti_status` (`ip_noti_status`)",
'ip_cancel_status' => "ADD KEY `ip_cancel_status` (`ip_cancel_status`)",
'ip_refund_required' => "ADD KEY `ip_refund_required` (`ip_refund_required`)"
);
foreach ($inicis_pay_indexes as $index_name => $index_sql) {
$index_result = sql_query(" SHOW INDEX FROM `{$g5['g5_shop_inicis_pay_table']}` WHERE Key_name = '$index_name' ", false);
if (!$index_result || sql_num_rows($index_result) === 0) {
sql_query(" ALTER TABLE `{$g5['g5_shop_inicis_pay_table']}` $index_sql ", true);
$is_check = true;
}
}
}
if (!sql_query(" DESC `{$g5['g5_shop_inicis_pay_event_table']}` ", false)) {
sql_query(" CREATE TABLE IF NOT EXISTS `{$g5['g5_shop_inicis_pay_event_table']}` (
`pe_id` int(11) NOT NULL AUTO_INCREMENT,
`ip_oid` varchar(64) NOT NULL DEFAULT '',
`ip_tid` varchar(80) NOT NULL DEFAULT '',
`pe_stage` varchar(30) NOT NULL DEFAULT '',
`pe_status` varchar(30) NOT NULL DEFAULT '',
`pe_code` varchar(30) NOT NULL DEFAULT '',
`pe_message` varchar(255) NOT NULL DEFAULT '',
`pe_source` varchar(10) NOT NULL DEFAULT '',
`pe_ip` varchar(45) NOT NULL DEFAULT '',
`pe_created_at` datetime DEFAULT NULL,
PRIMARY KEY (`pe_id`),
KEY `ip_oid` (`ip_oid`),
KEY `ip_tid` (`ip_tid`),
KEY `pe_status` (`pe_status`),
KEY `pe_created_at` (`pe_created_at`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8 ", true);
$is_check = true;
}
}
$is_check = run_replace('admin_dbupgrade', $is_check);
$db_upgrade_msg = $is_check ? 'DB 업그레이드가 완료되었습니다.' : '더 이상 업그레이드 할 내용이 없습니다.<br>현재 DB 업그레이드가 완료된 상태입니다.';
@@ -281,4 +643,4 @@ $db_upgrade_msg = $is_check ? 'DB 업그레이드가 완료되었습니다.' : '
</div>
<?php
include_once ('./admin.tail.php');
include_once ('./admin.tail.php');
+1 -1
View File
@@ -20,7 +20,7 @@ check_admin_token();
$fm_id = isset($_REQUEST['fm_id']) ? (int) $_REQUEST['fm_id'] : 0;
$fm_himg_del = isset($_POST['fm_himg_del']) ? (int) $_POST['fm_himg_del'] : 0;
$fm_timg_del = isset($_POST['fm_timg_del']) ? (int) $_POST['fm_timg_del'] : 0;
$fm_subject = isset($_POST['fm_subject']) ? strip_tags(clean_xss_attributes($_POST['fm_subject'])) : '';
$fm_subject = isset($_POST['fm_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['fm_subject'])))) : '';
$fm_head_html = isset($_POST['fm_head_html']) ? $_POST['fm_head_html'] : '';
$fm_tail_html = isset($_POST['fm_tail_html']) ? $_POST['fm_tail_html'] : '';
$fm_mobile_head_html = isset($_POST['fm_mobile_head_html']) ? $_POST['fm_mobile_head_html'] : '';
Binary file not shown.

After

Width:  |  Height:  |  Size: 4.7 KiB

+13 -4
View File
@@ -35,6 +35,10 @@ if (!auth_check_menu($auth, '200100', 'r', true)) {
$sod = "desc";
}
$allowed_sst = array('mb_datetime');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'mb_datetime';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
@@ -284,14 +288,19 @@ if (!auth_check_menu($auth, '200200', 'r', true)) {
</thead>
<tbody>
<?php
$row2['mb_id'] = '';
$row2 = array('mb_id'=>'');
for ($i = 0; $row = sql_fetch_array($result); $i++) {
if ($row2['mb_id'] != $row['mb_id']) {
if (empty($row2) || $row2['mb_id'] != $row['mb_id']) {
$sql2 = " SELECT mb_id, mb_name, mb_nick, mb_email, mb_homepage, mb_point from {$g5['member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
}
$mb_nick = get_sideview($row['mb_id'], $row2['mb_nick'], $row2['mb_email'], $row2['mb_homepage']);
$mb_nick = get_sideview(
$row['mb_id'],
isset($row2['mb_nick']) ? $row2['mb_nick'] : '',
isset($row2['mb_email']) ? $row2['mb_email'] : '',
isset($row2['mb_homepage']) ? $row2['mb_homepage'] : ''
);
$link1 = $link2 = "";
if (!preg_match("/^\@/", $row['po_rel_table']) && $row['po_rel_table']) {
@@ -302,7 +311,7 @@ if (!auth_check_menu($auth, '200200', 'r', true)) {
<tr>
<td class="td_mbid"><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
<td class="td_mbname"><?php echo get_text($row2['mb_name']); ?></td>
<td class="td_mbname"><?php echo isset($row2['mb_name']) ? get_text($row2['mb_name']) : ''; ?></td>
<td class="td_name sv_use">
<div><?php echo $mb_nick ?></div>
</td>
+1 -1
View File
@@ -80,7 +80,7 @@ require_once './admin.head.php';
<tr>
<th scope="row"><label for="mb_email">E-mail</label></th>
<td>
<?php echo help("메일 주소에 단어 포함 (예 : @" . preg_replace('#^(www[^\.]*\.){1}#', '', $_SERVER['HTTP_HOST']) . ")") ?>
<?php echo help("메일 주소에 단어 포함 (예 : @" . htmlspecialchars(preg_replace('#^(www[^\.]*\.){1}#', '', $_SERVER['HTTP_HOST'])) . ")") ?>
<input type="text" name="mb_email" value="<?php echo get_sanitize_input($mb_email); ?>" id="mb_email" class="frm_input" size="50">
</td>
</tr>
+4 -4
View File
@@ -12,10 +12,10 @@ $sql_common = " from {$g5['member_table']} ";
$sql_where = " where (1) ";
$mb_id1 = isset($_POST['mb_id1']) ? (int) $_POST['mb_id1'] : 1;
$mb_id1_from = isset($_POST['mb_id1_from']) ? clean_xss_tags($_POST['mb_id1_from'], 1, 1, 30) : '';
$mb_id1_to = isset($_POST['mb_id1_to']) ? clean_xss_tags($_POST['mb_id1_to'], 1, 1, 30) : '';
$mb_email = isset($_POST['mb_email']) ? clean_xss_tags($_POST['mb_email'], 1, 1, 100) : '';
$mb_mailling = isset($_POST['mb_mailling']) ? clean_xss_tags($_POST['mb_mailling'], 1, 1, 100) : '';
$mb_id1_from = isset($_POST['mb_id1_from']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_id1_from']), 1, 1, 30)) : '';
$mb_id1_to = isset($_POST['mb_id1_to']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_id1_to']), 1, 1, 30)) : '';
$mb_email = isset($_POST['mb_email']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_email']), 1, 1, 100)) : '';
$mb_mailling = isset($_POST['mb_mailling']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_mailling']), 1, 1, 100)) : '';
$mb_level_from = isset($_POST['mb_level_from'])? (int) $_POST['mb_level_from'] : 1;
$mb_level_to = isset($_POST['mb_level_to']) ? (int) $_POST['mb_level_to'] : 10;
+1 -1
View File
@@ -11,7 +11,7 @@ auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
$ma_id = isset($_POST['ma_id']) ? (int) $_POST['ma_id'] : 0;
$ma_subject = isset($_POST['ma_subject']) ? strip_tags(clean_xss_attributes($_POST['ma_subject'])) : '';
$ma_subject = isset($_POST['ma_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['ma_subject'])))) : '';
$ma_content = isset($_POST['ma_content']) ? $_POST['ma_content'] : '';
if ($w == '') {
+64 -7
View File
@@ -52,8 +52,11 @@ if ($w == '') {
$sound_only = '<strong class="sound_only">필수</strong>';
$mb['mb_mailling'] = 1;
$mb['mb_sms'] = 1;
$mb['mb_open'] = 1;
$mb['mb_level'] = $config['cf_register_level'];
$mb['mb_marketing_agree'] = 0;
$mb['mb_thirdparty_agree'] = 0;
$html_title = '추가';
} elseif ($w == 'u') {
$mb = get_member($mb_id);
@@ -139,6 +142,14 @@ $mb_sms_no = !$mb['mb_sms'] ? 'checked="checked"' : '';
$mb_open_yes = $mb['mb_open'] ? 'checked="checked"' : '';
$mb_open_no = !$mb['mb_open'] ? 'checked="checked"' : '';
// 마케팅 목적의 개인정보 수집 및 이용
$mb_marketing_agree_yes = $mb['mb_marketing_agree'] ? 'checked="checked"' : '';
$mb_marketing_agree_no = !$mb['mb_marketing_agree'] ? 'checked="checked"' : '';
// 개인정보 제3자 제공 동의
$mb_thirdparty_agree_yes = $mb['mb_thirdparty_agree'] ? 'checked="checked"' : '';
$mb_thirdparty_agree_no = !$mb['mb_thirdparty_agree'] ? 'checked="checked"' : '';
if (isset($mb['mb_certify'])) {
// 날짜시간형이라면 drop 시킴
if (preg_match("/-/", $mb['mb_certify'])) {
@@ -264,7 +275,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<th scope="row"><label for="mb_level">회원 권한</label></th>
<td><?php echo get_member_level_select('mb_level', 1, $member['mb_level'], $mb['mb_level']) ?></td>
<th scope="row">포인트</th>
<td><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $mb['mb_id'] ?>" target="_blank"><?php echo number_format($mb['mb_point']) ?></a> 점</td>
<td><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $mb['mb_id'] ?>" target="_blank"><?php echo number_format(isset($mb['mb_point']) ? $mb['mb_point'] : 0) ?></a> 점</td>
</tr>
<tr>
<th scope="row"><label for="mb_email">E-mail<strong class="sound_only">필수</strong></label></th>
@@ -327,7 +338,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<?php echo help('이미지 크기는 <strong>넓이 ' . $config['cf_member_icon_width'] . '픽셀 높이 ' . $config['cf_member_icon_height'] . '픽셀</strong>로 해주세요.') ?>
<input type="file" name="mb_icon" id="mb_icon">
<?php
$mb_dir = substr($mb['mb_id'], 0, 2);
$mb_dir = substr(isset($mb['mb_id']) ? $mb['mb_id'] : '', 0, 2);
$icon_file = G5_DATA_PATH . '/member/' . $mb_dir . '/' . get_mb_icon_name($mb['mb_id']) . '.gif';
if (file_exists($icon_file)) {
$icon_url = str_replace(G5_DATA_PATH, G5_DATA_URL, $icon_file);
@@ -344,7 +355,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<?php echo help('이미지 크기는 <strong>넓이 ' . $config['cf_member_img_width'] . '픽셀 높이 ' . $config['cf_member_img_height'] . '픽셀</strong>로 해주세요.') ?>
<input type="file" name="mb_img" id="mb_img">
<?php
$mb_dir = substr($mb['mb_id'], 0, 2);
$mb_dir = substr(isset($mb['mb_id']) ? $mb['mb_id'] : '', 0, 2);
$icon_file = G5_DATA_PATH . '/member_image/' . $mb_dir . '/' . get_mb_icon_name($mb['mb_id']) . '.gif';
if (file_exists($icon_file)) {
echo get_member_profile_img($mb['mb_id']);
@@ -354,21 +365,64 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
</td>
</tr>
<tr>
<th scope="row">메일 수신</th>
<th scope="row">광고성 이메일 수신</th>
<td>
<input type="radio" name="mb_mailling" value="1" id="mb_mailling_yes" <?php echo $mb_mailling_yes; ?>>
<label for="mb_mailling_yes">예</label>
<input type="radio" name="mb_mailling" value="0" id="mb_mailling_no" <?php echo $mb_mailling_no; ?>>
<label for="mb_mailling_no">아니오</label>
<?php if($w == "u" && $mb['mb_mailling_date'] != "0000-00-00 00:00:00"){
echo $mb['mb_mailling'] == 1 ? "<br>(동의 일자: ".$mb['mb_mailling_date'].")" : '';
} ?>
</td>
<th scope="row"><label for="mb_sms_yes">SMS 수신</label></th>
<th scope="row"><label for="mb_sms_yes">광고성 SMS/카카오톡 수신</label></th>
<td>
<input type="radio" name="mb_sms" value="1" id="mb_sms_yes" <?php echo $mb_sms_yes; ?>>
<label for="mb_sms_yes">예</label>
<input type="radio" name="mb_sms" value="0" id="mb_sms_no" <?php echo $mb_sms_no; ?>>
<label for="mb_sms_no">아니오</label>
<?php if($w == "u" && $mb['mb_sms_date'] != "0000-00-00 00:00:00"){
echo $mb['mb_sms'] == 1 ? "<br>(동의 일자: ".$mb['mb_sms_date'].")" : '';
} ?>
</td>
</tr>
<tr>
<th scope="row">마케팅 목적의<br>개인정보 수집 및 이용</th>
<td>
<input type="radio" name="mb_marketing_agree" value="1" id="mb_marketing_agree_yes" <?php echo $mb_marketing_agree_yes; ?>>
<label for="mb_marketing_agree_yes">예</label>
<input type="radio" name="mb_marketing_agree" value="0" id="mb_marketing_agree_no" <?php echo $mb_marketing_agree_no; ?>>
<label for="mb_marketing_agree_no">아니오</label>
<?php if($w == "u" && $mb['mb_marketing_date'] != "0000-00-00 00:00:00"){
echo $mb['mb_marketing_agree'] == 1 ? "<br>(동의 일자: ".$mb['mb_marketing_date'].")" : '';
} ?>
</td>
<th scope="row"><label for="mb_sms_yes">개인정보 제3자 제공</label></th>
<td>
<input type="radio" name="mb_thirdparty_agree" value="1" id="mb_thirdparty_agree_yes" <?php echo $mb_thirdparty_agree_yes; ?>>
<label for="mb_thirdparty_agree_yes">예</label>
<input type="radio" name="mb_thirdparty_agree" value="0" id="mb_thirdparty_agree_no" <?php echo $mb_thirdparty_agree_no; ?>>
<label for="mb_thirdparty_agree_no">아니오</label>
<?php if($w == "u" && $mb['mb_thirdparty_date'] != "0000-00-00 00:00:00"){
echo $mb['mb_thirdparty_agree'] == 1 ? "<br>(동의 일자: ".$mb['mb_thirdparty_date'].")" : '';
} ?>
</td>
</tr>
<?php if($w == "u"){?>
<tr>
<th scope="row">약관동의 변경내역</th>
<td colspan="3">
<section id="sodr_request_log_wrap" class="ad_agree_log">
<div>
<?php echo conv_content($mb['mb_agree_log'], 0); ?>
</div>
</section>
</td>
</tr>
<?php } ?>
<tr>
<th scope="row">정보 공개</th>
<td colspan="3">
@@ -376,6 +430,9 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<label for="mb_open_yes">예</label>
<input type="radio" name="mb_open" value="0" id="mb_open_no" <?php echo $mb_open_no; ?>>
<label for="mb_open_no">아니오</label>
<?php if($w == "u" && $mb['mb_open_date'] != "0000-00-00 00:00:00"){
echo $mb['mb_open'] == 1 ? "<br>(동의 일자: ".$mb['mb_open_date'].")" : '';
} ?>
</td>
</tr>
<tr>
@@ -502,7 +559,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<span class="provider_name"><?php echo $provider_name; //서비스이름 ?> ( <?php echo $account['displayname']; ?> )</span>
<span class="account_hidden" style="display:none"><?php echo $account['mb_id']; ?></span>
</div>
<div class="btn_info"><a href="<?php echo G5_SOCIAL_LOGIN_URL . '/unlink.php?mp_no=' . $account['mp_no'] ?>" class="social_unlink" data-provider="<?php echo $account['mp_no']; ?>">연동해제</a> <span class="sound_only"><?php echo substr($account['mp_register_day'], 2, 14); ?></span></div>
<div class="btn_info"><a href="<?php echo G5_SOCIAL_LOGIN_URL . '/unlink.php?mp_no=' . $account['mp_no'] ?>" class="social_unlink" data-provider="<?php echo $account['mp_no']; ?>">연동해제</a> <span class="sound_only"><?php echo substr(isset($account['mp_register_day']) ? $account['mp_register_day'] : '', 2, 14); ?></span></div>
</div>
<?php } //end foreach ?>
</li>
@@ -568,7 +625,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<?php for ($i = 1; $i <= 10; $i++) { ?>
<tr>
<th scope="row"><label for="mb_<?php echo $i ?>">여분 필드 <?php echo $i ?></label></th>
<td colspan="3"><input type="text" name="mb_<?php echo $i ?>" value="<?php echo $mb['mb_' . $i] ?>" id="mb_<?php echo $i ?>" class="frm_input" size="30" maxlength="255"></td>
<td colspan="3"><input type="text" name="mb_<?php echo $i ?>" value="<?php echo get_sanitize_input($mb['mb_' . $i]); ?>" id="mb_<?php echo $i ?>" class="frm_input" size="30" maxlength="255"></td>
</tr>
<?php } ?>
+89 -5
View File
@@ -18,8 +18,12 @@ $mb_certify_case = isset($_POST['mb_certify_case']) ? preg_replace('/[^0-9a-z_]/
$mb_certify = isset($_POST['mb_certify']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_certify']) : '';
$mb_zip = isset($_POST['mb_zip']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['mb_zip']) : '';
// 광고성 정보 수신
$mb_marketing_agree = isset($_POST['mb_marketing_agree']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_marketing_agree']), 1, 1)) : '0';
$mb_thirdparty_agree = isset($_POST['mb_thirdparty_agree']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_thirdparty_agree']), 1, 1)) : '0';
// 관리자가 자동등록방지를 사용해야 할 경우 ( 회원의 비밀번호 변경시 캡챠를 체크한다 )
if ($mb_password && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
if ($mb_password) {
include_once(G5_CAPTCHA_PATH . '/captcha.lib.php');
if (!chk_captcha()) {
@@ -80,14 +84,12 @@ for ($i = 1; $i <= 10; $i++) {
foreach ($check_keys as $key) {
if( in_array($key, array('mb_signature', 'mb_profile')) ){
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1, 0, 0) : '';
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1, 0, 0)) : '';
} else {
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
}
}
$mb_memo = isset($_POST['mb_memo']) ? $_POST['mb_memo'] : '';
$sql_common = " mb_name = '{$posts['mb_name']}',
mb_nick = '{$mb_nick}',
mb_email = '{$mb_email}',
@@ -109,8 +111,11 @@ $sql_common = " mb_name = '{$posts['mb_name']}',
mb_mailling = '{$posts['mb_mailling']}',
mb_sms = '{$posts['mb_sms']}',
mb_open = '{$posts['mb_open']}',
mb_open_date = '".G5_TIME_YMDHIS."',
mb_profile = '{$posts['mb_profile']}',
mb_level = '{$posts['mb_level']}',
mb_marketing_agree = '{$mb_marketing_agree}',
mb_thirdparty_agree = '{$mb_thirdparty_agree}',
mb_1 = '{$posts['mb_1']}',
mb_2 = '{$posts['mb_2']}',
mb_3 = '{$posts['mb_3']}',
@@ -122,6 +127,11 @@ $sql_common = " mb_name = '{$posts['mb_name']}',
mb_9 = '{$posts['mb_9']}',
mb_10 = '{$posts['mb_10']}' ";
// 부여하려는 mb_level 상한 검증 (자기보다 높은 권한 부여 차단)
if ($is_admin !== 'super' && (int) $posts['mb_level'] >= (int) $member['mb_level']) {
alert('자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.');
}
if ($w == '') {
$mb = get_member($mb_id);
if (isset($mb['mb_id']) && $mb['mb_id']) {
@@ -142,6 +152,36 @@ if ($w == '') {
alert('이미 존재하는 이메일입니다.\\nID : ' . $row['mb_id'] . '\\n이름 : ' . $row['mb_name'] . '\\n닉네임 : ' . $row['mb_nick'] . '\\n메일 : ' . $row['mb_email']);
}
$agree_items = array();
// 마케팅 목적의 개인정보 수집 및 이용
if ($mb_marketing_agree == 1) {
$sql_common .= " , mb_marketing_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "마케팅 목적의 개인정보 수집 및 이용(동의)";
}
// 광고성 이메일 수신
if ($mb_mailling == 1) {
$sql_common .= " , mb_mailling_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 이메일 수신(동의)";
}
// 광고성 SMS/카카오톡 수신
if ($mb_sms == 1) {
$sql_common .= " , mb_sms_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 SMS/카카오톡 수신(동의)";
}
// 개인정보 제3자 제공
if ($mb_thirdparty_agree == 1) {
$sql_common .= " , mb_thirdparty_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "개인정보 제3자 제공(동의)";
}
// 동의 로그 추가
if (!empty($agree_items)) {
$agree_log = "[".G5_TIME_YMDHIS.", 관리자 회원추가] " . implode(' | ', $agree_items) . "\n";
$sql_common .= " , mb_agree_log = CONCAT('{$agree_log}', IFNULL(mb_agree_log, ''))";
}
sql_query(" insert into {$g5['member_table']} set mb_id = '{$mb_id}', mb_password = '" . get_encrypt_string($mb_password) . "', mb_datetime = '" . G5_TIME_YMDHIS . "', mb_ip = '{$_SERVER['REMOTE_ADDR']}', mb_email_certify = '" . G5_TIME_YMDHIS . "', {$sql_common} ");
} elseif ($w == 'u') {
$mb = get_member($mb_id);
@@ -193,10 +233,54 @@ if ($w == '') {
$sql_certify = "";
}
// 현재 데이터 조회
$row = sql_fetch("select * from {$g5['member_table']} where mb_id = '{$mb_id}' ");
$agree_items = array();
// 마케팅 목적의 개인정보 수집 및 이용
$sql_marketing_date = "";
if ($row['mb_marketing_agree'] !== $mb_marketing_agree) {
$sql_marketing_date .= " , mb_marketing_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "마케팅 목적의 개인정보 수집 및 이용(" . ($mb_marketing_agree == 1 ? "동의" : "철회") . ")";
}
// 광고성 이메일 수신
$sql_mailling_date = "";
if ($row['mb_mailling'] !== $mb_mailling) {
$sql_mailling_date .= " , mb_mailling_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 이메일 수신(" . ($mb_mailling == 1 ? "동의" : "철회") . ")";
}
// 광고성 SMS/카카오톡 수신
$sql_sms_date = "";
if ($row['mb_sms'] !== $mb_sms) {
$sql_sms_date .= " , mb_sms_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 SMS/카카오톡 수신(" . ($mb_sms == 1 ? "동의" : "철회") . ")";
}
// 개인정보 제3자 제공
$sql_thirdparty_date = "";
if ($row['mb_thirdparty_agree'] !== $mb_thirdparty_agree) {
$sql_thirdparty_date .= " , mb_thirdparty_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "개인정보 제3자 제공(" . ($mb_thirdparty_agree == 1 ? "동의" : "철회") . ")";
}
// 동의 로그 추가
$sql_agree_log = "";
if (!empty($agree_items)) {
$agree_log = "[".G5_TIME_YMDHIS.", 관리자 회원수정] " . implode(' | ', $agree_items) . "\n";
$sql_agree_log .= " , mb_agree_log = CONCAT('{$agree_log}', IFNULL(mb_agree_log, ''))";
}
$sql = " update {$g5['member_table']}
set {$sql_common}
{$sql_password}
{$sql_certify}
{$sql_mailling_date}
{$sql_sms_date}
{$sql_marketing_date}
{$sql_thirdparty_date}
{$sql_agree_log}
where mb_id = '{$mb_id}' ";
sql_query($sql);
} else {
+22 -11
View File
@@ -6,6 +6,12 @@ auth_check_menu($auth, $sub_menu, 'r');
$sql_common = " from {$g5['member_table']} ";
// $sfl 화이트리스트 검증 (KVE-2026-0340)
$allowed_sfl = array('mb_id', 'mb_nick', 'mb_name', 'mb_level', 'mb_email', 'mb_tel', 'mb_hp', 'mb_point', 'mb_datetime', 'mb_ip', 'mb_recommend');
if (!in_array($sfl, $allowed_sfl)) {
$sfl = 'mb_id';
}
$sql_search = " where (1) ";
if ($stx) {
$sql_search .= " and ( ";
@@ -36,6 +42,10 @@ if (!$sst) {
$sod = "desc";
}
$allowed_sst = array('mb_datetime', 'mb_id', 'mb_name', 'mb_nick', 'mb_level', 'mb_point', 'mb_today_login', 'mb_open', 'mb_mailling', 'mb_sms', 'mb_adult', 'mb_certify', 'mb_email_certify', 'mb_intercept_date', 'mb_leave_date');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'mb_datetime';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
@@ -127,7 +137,7 @@ $colspan = 16;
<th scope="col" rowspan="2" id="mb_list_cert"><?php echo subject_sort_link('mb_certify', '', 'desc') ?>본인확인</a></th>
<th scope="col" id="mb_list_mailc"><?php echo subject_sort_link('mb_email_certify', '', 'desc') ?>메일인증</a></th>
<th scope="col" id="mb_list_open"><?php echo subject_sort_link('mb_open', '', 'desc') ?>정보공개</a></th>
<th scope="col" id="mb_list_mailr"><?php echo subject_sort_link('mb_mailling', '', 'desc') ?>메일수신</a></th>
<th scope="col" id="mb_list_mailr"><?php echo subject_sort_link('mb_mailling', '', 'desc') ?>광고성이메일</a></th>
<th scope="col" id="mb_list_auth">상태</th>
<th scope="col" id="mb_list_mobile">휴대폰</th>
<th scope="col" id="mb_list_lastcall"><?php echo subject_sort_link('mb_today_login', '', 'desc') ?>최종접속</a></th>
@@ -137,9 +147,9 @@ $colspan = 16;
<tr>
<th scope="col" id="mb_list_name"><?php echo subject_sort_link('mb_name') ?>이름</a></th>
<th scope="col" id="mb_list_nick"><?php echo subject_sort_link('mb_nick') ?>닉네임</a></th>
<th scope="col" id="mb_list_sms"><?php echo subject_sort_link('mb_sms', '', 'desc') ?>SMS수신</a></th>
<th scope="col" id="mb_list_adultc"><?php echo subject_sort_link('mb_adult', '', 'desc') ?>성인인증</a></th>
<th scope="col" id="mb_list_auth"><?php echo subject_sort_link('mb_intercept_date', '', 'desc') ?>접근차단</a></th>
<th scope="col" id="mb_list_sms"><?php echo subject_sort_link('mb_sms', '', 'desc') ?>광고성SMS</a></th>
<th scope="col" id="mb_list_deny"><?php echo subject_sort_link('mb_level', '', 'desc') ?>권한</a></th>
<th scope="col" id="mb_list_tel">전화번호</th>
<th scope="col" id="mb_list_join"><?php echo subject_sort_link('mb_datetime', '', 'desc') ?>가입일</a></th>
@@ -252,14 +262,15 @@ $colspan = 16;
<input type="radio" name="mb_certify[<?php echo $i; ?>]" value="ipin" id="mb_certify_ipin_<?php echo $i; ?>" <?php echo $row['mb_certify'] == 'ipin' ? 'checked' : ''; ?>>
<label for="mb_certify_ipin_<?php echo $i; ?>">아이핀</label>
</td>
<td headers="mb_list_mailc"><?php echo preg_match('/[1-9]/', $row['mb_email_certify']) ? '<span class="txt_true">Yes</span>' : '<span class="txt_false">No</span>'; ?></td>
<td headers="mb_list_open">
<td headers="mb_list_mailc" class="td_consent"><?php echo preg_match('/[1-9]/', $row['mb_email_certify']) ? '<span class="txt_true">Yes</span>' : '<span class="txt_false">No</span>'; ?></td>
<td headers="mb_list_open" class="td_consent">
<label for="mb_open_<?php echo $i; ?>" class="sound_only">정보공개</label>
<input type="checkbox" name="mb_open[<?php echo $i; ?>]" <?php echo $row['mb_open'] ? 'checked' : ''; ?> value="1" id="mb_open_<?php echo $i; ?>">
</td>
<td headers="mb_list_mailr">
<label for="mb_mailling_<?php echo $i; ?>" class="sound_only">메일수신</label>
<td headers="mb_list_mailr" class="td_consent">
<label for="mb_mailling_<?php echo $i; ?>" class="sound_only">광고성이메일수신</label>
<input type="checkbox" name="mb_mailling[<?php echo $i; ?>]" <?php echo $row['mb_mailling'] ? 'checked' : ''; ?> value="1" id="mb_mailling_<?php echo $i; ?>">
<input type="hidden" name="mb_mailling_default[<?php echo $i; ?>]" value="<?php echo isset($row['mb_mailling']) ? $row['mb_mailling'] : '0'; ?> " id="mb_mailling_default_<?php echo $i; ?>">
</td>
<td headers="mb_list_auth" class="td_mbstat">
<?php
@@ -280,11 +291,6 @@ $colspan = 16;
<td headers="mb_list_nick" class="td_name sv_use">
<div><?php echo $mb_nick ?></div>
</td>
<td headers="mb_list_sms">
<label for="mb_sms_<?php echo $i; ?>" class="sound_only">SMS수신</label>
<input type="checkbox" name="mb_sms[<?php echo $i; ?>]" <?php echo $row['mb_sms'] ? 'checked' : ''; ?> value="1" id="mb_sms_<?php echo $i; ?>">
</td>
<td headers="mb_list_adultc">
<label for="mb_adult_<?php echo $i; ?>" class="sound_only">성인인증</label>
<input type="checkbox" name="mb_adult[<?php echo $i; ?>]" <?php echo $row['mb_adult'] ? 'checked' : ''; ?> value="1" id="mb_adult_<?php echo $i; ?>">
@@ -295,6 +301,11 @@ $colspan = 16;
<label for="mb_intercept_date_<?php echo $i; ?>" class="sound_only">접근차단</label>
<?php } ?>
</td>
<td headers="mb_list_sms">
<label for="mb_sms_<?php echo $i; ?>" class="sound_only">광고성SMS/카카오톡수신</label>
<input type="checkbox" name="mb_sms[<?php echo $i; ?>]" <?php echo $row['mb_sms'] ? 'checked' : ''; ?> value="1" id="mb_sms_<?php echo $i; ?>">
<input type="hidden" name="mb_sms_default[<?php echo $i; ?>]" value="<?php echo isset($row['mb_sms']) ? $row['mb_sms'] : '0'; ?> " id="mb_sms_default_<?php echo $i; ?>">
</td>
<td headers="mb_list_auth" class="td_mbstat">
<?php echo get_member_level_select("mb_level[$i]", 1, $member['mb_level'], $row['mb_level']) ?>
</td>
+294
View File
@@ -0,0 +1,294 @@
<?php
/*************************************************************************
**
** 내보내기 관련 상수 정의
**
*************************************************************************/
define('MEMBER_EXPORT_PAGE_SIZE', 10000); // 파일당 처리할 회원 수
define('MEMBER_EXPORT_MAX_SIZE', 300000); // 최대 처리할 회원 수
define('MEMBER_BASE_DIR', "member_list"); // 엑셀 베이스 폴더
define('MEMBER_BASE_DATE', date('YmdHis')); // 폴더/파일명용 날짜
define('MEMBER_EXPORT_DIR', G5_DATA_PATH . "/" . MEMBER_BASE_DIR . "/" . MEMBER_BASE_DATE); // 엑셀 파일 저장 경로
define('MEMBER_LOG_DIR', G5_DATA_PATH . "/" . MEMBER_BASE_DIR . "/" . "log"); // 로그 파일 저장 경로
/*************************************************************************
**
** 공통 함수 정의
**
*************************************************************************/
/**
* 검색 옵션 설정
*/
function get_export_config($type = null)
{
$config = array(
'sfl_list' => array(
'mb_id'=>'아이디',
'mb_name'=>'이름',
'mb_nick'=>'닉네임',
'mb_email'=>'이메일',
'mb_tel'=>'전화번호',
'mb_hp'=>'휴대폰번호',
'mb_addr1'=>'주소'
),
'point_cond_map' => array(
'gte'=>'≥',
'lte'=>'≤',
'eq'=>'='
),
'intercept_list' => array(
'exclude'=>'차단회원 제외',
'only'=>'차단회원만'
),
'ad_range_list' => array(
'all' => '수신동의 회원 전체',
'mailling_only' => '이메일 수신동의 회원만',
'sms_only' => 'SMS/카카오톡 수신동의 회원만',
'month_confirm' => date('m월').' 수신동의 확인 대상만',
'custom_period' => '수신동의 기간 직접 입력'
),
);
return $type ? (isset($config[$type]) ? $config[$type] : array()) : $config;
}
/**
* 파라미터 수집 및 유효성 검사
*/
function get_member_export_params()
{
// 친구톡 양식 - 엑셀 양식에 포함할 항목
$fieldArray = array_map('trim', explode(',', isset($_GET['fields']) ? $_GET['fields'] : ''));
$vars = array();
foreach ($fieldArray as $index => $field) {
if(!empty($field)){
$vars['var' . ($index + 1)] = $field;
}
}
$params = array(
'page' => 1,
'formatType' => (int)(isset($_GET['formatType']) ? $_GET['formatType'] : 1),
'use_stx' => isset($_GET['use_stx']) ? $_GET['use_stx'] : 0,
'stx_cond' => clean_xss_tags(isset($_GET['stx_cond']) ? $_GET['stx_cond'] : 'like'),
'sfl' => clean_xss_tags(isset($_GET['sfl']) ? $_GET['sfl'] : ''),
'stx' => clean_xss_tags(isset($_GET['stx']) ? $_GET['stx'] : ''),
'use_level' => isset($_GET['use_level']) ? $_GET['use_level'] : 0,
'level_start' => (int)(isset($_GET['level_start']) ? $_GET['level_start'] : 1),
'level_end' => (int)(isset($_GET['level_end']) ? $_GET['level_end'] : 10),
'use_date' => isset($_GET['use_date']) ? $_GET['use_date'] : 0,
'date_start' => clean_xss_tags(isset($_GET['date_start']) ? $_GET['date_start'] : ''),
'date_end' => clean_xss_tags(isset($_GET['date_end']) ? $_GET['date_end'] : ''),
'use_point' => isset($_GET['use_point']) ? $_GET['use_point'] : 0,
'point' => isset($_GET['point']) ? $_GET['point'] : '',
'point_cond' => isset($_GET['point_cond']) ? $_GET['point_cond'] : 'gte',
'use_hp_exist' => isset($_GET['use_hp_exist']) ? $_GET['use_hp_exist'] : 0,
'ad_range_only' => isset($_GET['ad_range_only']) ? $_GET['ad_range_only'] : 0,
'ad_range_type' => clean_xss_tags(isset($_GET['ad_range_type']) ? $_GET['ad_range_type'] : 'all'),
'ad_mailling' => isset($_GET['ad_mailling']) ? $_GET['ad_mailling'] : 0,
'ad_sms' => isset($_GET['ad_sms']) ? $_GET['ad_sms'] : 0,
'agree_date_start' => clean_xss_tags(isset($_GET['agree_date_start']) ? $_GET['agree_date_start'] : ''),
'agree_date_end' => clean_xss_tags(isset($_GET['agree_date_end']) ? $_GET['agree_date_end'] : ''),
'use_intercept' => isset($_GET['use_intercept']) ? $_GET['use_intercept'] : 0,
'intercept' => clean_xss_tags(isset($_GET['intercept']) ? $_GET['intercept'] : 'exclude'),
'vars' => $vars,
);
// 레벨 범위 검증
if ($params['level_start'] > $params['level_end']) {
$tmp_level = $params['level_start'];
$params['level_start'] = $params['level_end'];
$params['level_end'] = $tmp_level;
}
// 가입기간 - 날짜 범위 검증
if ($params['use_date'] && $params['date_start'] && $params['date_end']) {
if ($params['date_start'] > $params['date_end']) {
$tmp_date = $params['date_start'];
$params['date_start'] = $params['date_end'];
$params['date_end'] = $tmp_date;
}
}
// 수신동의기간 - 날짜 범위 검증
if ($params['ad_range_type'] == 'custom_period' && $params['agree_date_start'] && $params['agree_date_end']) {
if ($params['agree_date_start'] > $params['agree_date_end']) {
$tmp_agree_date = $params['agree_date_start'];
$params['agree_date_start'] = $params['agree_date_end'];
$params['agree_date_end'] = $tmp_agree_date;
}
}
return $params;
}
/**
* 전체 데이터 개수 조회
*/
function member_export_get_total_count($params)
{
global $g5;
$where = member_export_build_where($params);
$sql = "SELECT COUNT(*) as cnt FROM {$g5['member_table']} {$where}";
$result = sql_query($sql);
if (!$result) {
throw new Exception("데이터 조회에 실패하였습니다. 다시 시도해주세요.");
}
$row = sql_fetch_array($result);
return (int)$row['cnt'];
}
/**
* WHERE 조건절 생성
*/
function member_export_build_where($params)
{
global $config;
$conditions = array();
// 기본 조건 - 탈퇴하지 않은 사용자
$conditions[] = "mb_leave_date = ''";
// 검색어 조건 (sql_escape_string 사용으로 보안 강화)
if (!empty($params['use_stx']) && $params['use_stx'] === '1') {
$sfl_list = get_export_config('sfl_list');
$sfl = in_array($params['sfl'], array_keys($sfl_list)) ? $params['sfl'] : '';
$stx = sql_escape_string($params['stx']);
if(!empty($sfl) && !empty($stx)){
if ($params['stx_cond'] === 'like') {
$conditions[] = "{$sfl} LIKE '%{$stx}%'";
} else {
$conditions[] = "{$sfl} = '{$stx}'";
}
}
}
// 권한 조건
if (!empty($params['use_level']) && $params['use_level'] === '1') {
$level_start = max(1, (int)$params['level_start']);
$level_end = min(10, (int)$params['level_end']);
$conditions[] = "(mb_level BETWEEN {$level_start} AND {$level_end})";
}
// 가입기간 조건
if (!empty($params['use_date']) && $params['use_date'] === '1') {
$date_start = isset($params['date_start']) ? sql_escape_string(trim($params['date_start'])) : '';
$date_end = isset($params['date_end']) ? sql_escape_string(trim($params['date_end'])) : '';
if ($date_start && $date_end) {
$conditions[] = "mb_datetime BETWEEN '{$date_start} 00:00:00' AND '{$date_end} 23:59:59'";
} elseif ($date_start) {
$conditions[] = "mb_datetime >= '{$date_start} 00:00:00'";
} elseif ($date_end) {
$conditions[] = "mb_datetime <= '{$date_end} 23:59:59'";
}
}
// 포인트 조건
if (!empty($params['use_point']) && $params['use_point'] === '1') {
$point = $params['point'];
$point_cond = $params['point_cond'];
if ($point != '') {
$point = (int)$point; // 정수로 캐스팅
switch ($point_cond) {
case 'lte':
$conditions[] = "mb_point <= {$point}";
break;
case 'eq':
$conditions[] = "mb_point = {$point}";
break;
default:
$conditions[] = "mb_point >= {$point}";
break;
}
}
}
// 휴대폰 번호 존재 조건
if (!empty($params['use_hp_exist']) && $params['use_hp_exist'] === '1') {
$conditions[] = "(mb_hp is not null and mb_hp != '')";
}
// 정보수신동의 조건
if (!empty($params['ad_range_only']) && $params['ad_range_only'] === '1') {
$range = isset($params['ad_range_type']) ? $params['ad_range_type'] : '';
// 공통: 마케팅 목적 수집·이용 동의 + (필요 시) 제3자 동의
$thirdparty_clause = $config['cf_sms_use'] !== '' ? " AND mb_thirdparty_agree = 1" : "";
$base_marketing = "mb_marketing_agree = 1{$thirdparty_clause}";
if ($range === 'all') {
// 마케팅 동의 + (이메일 OR SMS 동의)
$conditions[] = "({$base_marketing} AND (mb_mailling = 1 OR mb_sms = 1))";
} elseif ($range === 'mailling_only') {
// 마케팅 동의 + 이메일 동의
$conditions[] = "({$base_marketing} AND mb_mailling = 1)";
} elseif ($range === 'sms_only') {
// 마케팅 동의 + SMS/카카오톡 동의
$conditions[] = "({$base_marketing} AND mb_sms = 1)";
} elseif ($range === 'month_confirm' || $range === 'custom_period') {
// 채널 필터 체크
$useEmail = !empty($params['ad_mailling']);
$useSms = !empty($params['ad_sms']);
if ($range === 'month_confirm') {
// 23개월 전 그 달
$start = date('Y-m-01 00:00:00', strtotime('-23 months'));
$end = date('Y-m-t 23:59:59', strtotime('-23 months'));
$emailDateCond = "mb_mailling_date BETWEEN '{$start}' AND '{$end}'";
$smsDateCond = "mb_sms_date BETWEEN '{$start}' AND '{$end}'";
} else {
// 수신동의기간 직접 입력 - custom_period
$date_start = isset($params['agree_date_start']) ? sql_escape_string(trim($params['agree_date_start'])) : '';
$date_end = isset($params['agree_date_end']) ? sql_escape_string(trim($params['agree_date_end'])) : '';
if ($date_start && $date_end) {
$emailDateCond = "mb_mailling_date BETWEEN '{$date_start} 00:00:00' AND '{$date_end} 23:59:59'";
$smsDateCond = "mb_sms_date BETWEEN '{$date_start} 00:00:00' AND '{$date_end} 23:59:59'";
} elseif ($date_start) {
$emailDateCond = "mb_mailling_date >= '{$date_start} 00:00:00'";
$smsDateCond = "mb_sms_date >= '{$date_start} 00:00:00'";
} elseif ($date_end) {
$emailDateCond = "mb_mailling_date <= '{$date_end} 23:59:59'";
$smsDateCond = "mb_sms_date <= '{$date_end} 23:59:59'";
} else {
$emailDateCond = "mb_mailling_date <> '0000-00-00 00:00:00'";
$smsDateCond = "mb_sms_date <> '0000-00-00 00:00:00'";
}
}
if (!$useEmail && !$useSms) {
$conditions[] = "0=1"; // 둘 다 해제 ⇒ 결과 0건
} else {
// 조건 조립
$parts = array();
if ($useEmail) $parts[] = "(mb_mailling = 1 AND {$emailDateCond})";
if ($useSms) $parts[] = "(mb_sms = 1 AND {$smsDateCond})";
$conditions[] = !empty($parts) ? '(' . implode(' OR ', $parts) . ')' : '';
}
}
}
// 차단 회원 조건
if (!empty($params['use_intercept']) && $params['use_intercept'] === '1') {
switch ($params['intercept']) {
case 'exclude':
$conditions[] = "mb_intercept_date = ''";
break;
case 'only':
$conditions[] = "mb_intercept_date != ''";
break;
}
}
return empty($conditions) ? '' : 'WHERE ' . implode(' AND ', $conditions);
}
+483
View File
@@ -0,0 +1,483 @@
<?php
$sub_menu = "200400";
require_once './_common.php';
require_once './member_list_exel.lib.php'; // 회원관리파일 공통 라이브러리
auth_check_menu($auth, $sub_menu, 'r');
// 파라미터 수집 및 유효성 검사
$params = get_member_export_params();
// 총건수
$total_count = 0;
$total_error = "";
try {
$total_count = member_export_get_total_count($params);
} catch (Exception $e) {
$total_error = $e->getMessage(); // 메서드 호출 괄호 필수
}
$g5['title'] = '회원관리파일';
require_once './admin.head.php';
$colspan = 14;
?>
<h2>회원 엑셀 생성</h2>
<div class="local_desc01 local_desc">
<p><b>회원수 <?php echo number_format(MEMBER_EXPORT_PAGE_SIZE);?>건 초과 시</b> <?php echo number_format(MEMBER_EXPORT_PAGE_SIZE);?>건 단위로 분리 저장되며, <b>엑셀 생성 최대 건수는 <?php echo number_format(MEMBER_EXPORT_MAX_SIZE);?>건</b>입니다. 초과 시 조건 추가 설정 후 재시도하시기 바랍니다.</p>
<p><b>수신동의 확인 대상은 만료일까지 1달 미만인 회원</b>을 기준으로 필터링됩니다.</p>
<br>
<p>파일 생성 시 서버에 임시 생성된 파일 중 <b>오늘 날짜를 제외 한 파일은 자동 삭제</b>되며, 수동 삭제 필요 시 <a href="<?php echo G5_ADMIN_URL;?>/member_list_file_delete.php"><b>회원관리파일 일괄삭제</b></a>에서 진행하시기 바랍니다.</p>
<p>회원 정보 수정은 <a href="<?php echo G5_ADMIN_URL;?>/member_list.php" class="link"><b>회원 관리</b></a>에서 진행하실 수 있습니다.</p>
</div>
<div class="local_ov01 local_ov">
<span class="btn_ov01">
<span class="ov_txt">총건수 </span>
<?php if($total_error != "") { ?>
<span class="ov_num"> <?php echo $total_error ?></span>
<?php } else {?>
<span class="ov_num"> <?php echo number_format($total_count) ?>건</span>
<?php } ?>
</span>
</div>
<!-- 회원 검색 필터링 폼 -->
<form id="fsearch" name="fsearch" class="member_list_data" method="get">
<input type="hidden" name="token" value="<?php echo get_token(); ?>">
<fieldset>
<legend class="sound_only">회원 검색 필터링</legend>
<div class="sch_table">
<!-- 검색어 적용 -->
<div class="sch_row">
<div class="label">
<label>
<input type="checkbox" name="use_stx" value="1" <?php echo isset($_GET['use_stx']) ? 'checked' : ''; ?>>
검색어 적용
</label>
</div>
<div class="field">
<select name="sfl">
<?php
// 검색어 옵션 : [정의] get_export_config() - adm/member_list_exel.lib.php;
foreach (get_export_config('sfl_list') as $val => $label) {
$selected = (isset($_GET['sfl']) && $_GET['sfl'] === $val) ? 'selected' : '';
echo "<option value=\"$val\" $selected>$label</option>";
}
?>
</select>
<input type="text" name="stx" value="<?php echo htmlspecialchars(isset($_GET['stx']) ? $_GET['stx'] : ''); ?>" placeholder="검색어 입력">
<span class="radio_group">
<label><input type="radio" name="stx_cond" value="like" <?php echo (isset($_GET['stx_cond']) ? $_GET['stx_cond'] : 'like') === 'like' ? 'checked' : ''; ?>> 포함</label>
<label><input type="radio" name="stx_cond" value="equal" <?php echo (isset($_GET['stx_cond']) ? $_GET['stx_cond'] : '') === 'equal' ? 'checked' : ''; ?>> 일치</label>
</span>
</div>
</div>
<!-- 레벨 적용 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="use_level" value="1" <?php echo isset($_GET['use_level']) ? 'checked' : ''; ?>> 레벨 적용</label>
</div>
<div class="field">
<select name="level_start">
<?php for ($i = 1; $i <= 10; $i++): ?>
<option value="<?php echo $i; ?>" <?php echo (isset($_GET['level_start']) && $_GET['level_start'] == $i) ? 'selected' : ''; ?>><?php echo $i; ?></option>
<?php endfor; ?>
</select> ~
<select name="level_end">
<?php for ($i = 1; $i <= 10; $i++): ?>
<option value="<?php echo $i; ?>" <?php echo (isset($_GET['level_end']) && $_GET['level_end'] == $i) ? 'selected' : ''; ?>><?php echo $i; ?></option>
<?php endfor; ?>
</select>
</div>
</div>
<!-- 가입기간 적용 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="use_date" value="1" <?php echo isset($_GET['use_date']) ? 'checked' : ''; ?>> 가입기간 적용</label>
</div>
<div class="field">
<input type="date" name="date_start" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['date_start']) ? $_GET['date_start'] : ''); ?>"> ~
<input type="date" name="date_end" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['date_end']) ? $_GET['date_end'] : ''); ?>">
</div>
</div>
<!-- 포인트 적용 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="use_point" value="1" <?php echo isset($_GET['use_point']) ? 'checked' : ''; ?>> 포인트 적용</label>
</div>
<div class="field">
<input type="number" name="point" value="<?php echo htmlspecialchars(isset($_GET['point']) ? $_GET['point'] : ''); ?>" placeholder="포인트 입력">
<span class="radio_group">
<label><input type="radio" name="point_cond" value="gte" <?php echo (isset($_GET['point_cond']) ? $_GET['point_cond'] : 'gte') === 'gte' ? 'checked' : ''; ?>> 이상</label>
<label><input type="radio" name="point_cond" value="lte" <?php echo (isset($_GET['point_cond']) ? $_GET['point_cond'] : '') === 'lte' ? 'checked' : ''; ?>> 이하</label>
<label><input type="radio" name="point_cond" value="eq" <?php echo (isset($_GET['point_cond']) ? $_GET['point_cond'] : '') === 'eq' ? 'checked' : ''; ?>> 일치</label>
</span>
</div>
</div>
<!-- 차단회원 조건 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="use_intercept" value="1" <?php echo isset($_GET['use_intercept']) ? 'checked' : ''; ?>> 차단회원</label>
</div>
<div class="field">
<select name="intercept" id="intercept">
<?php
// 차단회원 옵션 : [정의] get_export_config() - adm/member_list_exel.lib.php
foreach (get_export_config('intercept_list') as $val => $label) {
$selected = ((isset($_GET['intercept']) ? $_GET['intercept'] : '') === $val) ? 'selected' : '';
echo "<option value=\"$val\" $selected>$label</option>";
}
?>
</select>
</div>
</div>
<!-- 휴대폰 번호 조건 - 초기세팅(설정에 휴대폰번호가 보이기/필수입력이면 기본값 checked로 설정) -->
<div class="sch_row">
<div class="label">
<label>
<?php $use_hp_checked = isset($_GET['token']) ? (isset($_GET['use_hp_exist']) ? 'checked' : '') : (($config['cf_use_hp'] || $config['cf_req_hp']) ? 'checked' : '');?>
<input type="checkbox" name="use_hp_exist" value="1" <?php echo $use_hp_checked; ?>> 휴대폰 번호 있는 경우만
</label>
</div>
</div>
<!-- 정보수신동의 조건 -->
<div class="sch_row">
<div class="label">
<label><input type="checkbox" name="ad_range_only" value="1" <?php echo isset($_GET['ad_range_only']) ? 'checked' : ''; ?>> 정보수신동의에 동의한 경우만</label>
</div>
<!-- 안내 문구 -->
<div class="field">
<p class="sch_notice">「정보통신망이용촉진및정보보호등에관한법률」에 따라 <b>광고성 정보 수신동의 여부</b>를 <b>매2년</b>마다 확인해야 합니다.</p>
</div>
</div>
<div class="sch_row <?php echo isset($_GET['ad_range_only']) ? '' : 'is-hidden'; ?>">
<div class="ad_range_wrap">
<div class="ad_range_box">
<div class="label">
<label for="ad_range_type">회원범위</label>
</div>
<div class="field">
<select name="ad_range_type" id="ad_range_type">
<?php
foreach (get_export_config('ad_range_list') as $val => $label) {
$selected = ((isset($_GET['ad_range_type']) ? $_GET['ad_range_type'] : '') === $val) ? 'selected' : '';
echo "<option value=\"$val\" $selected>$label</option>";
}
?>
</select>
<div class="ad_range_wrap">
<!-- 기간 직접 입력 -->
<div class="ad_range_box <?php echo isset($_GET['ad_range_only']) && (isset($_GET['ad_range_type']) ? $_GET['ad_range_type'] : '') == 'custom_period' ? '' : 'is-hidden'; ?>">
<div class="field">
<input type="date" name="agree_date_start" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['agree_date_start']) ? $_GET['agree_date_start'] : date('Y-m-d', strtotime('-1 month'))); ?>"> ~
<input type="date" name="agree_date_end" max="9999-12-31" value="<?php echo htmlspecialchars(isset($_GET['agree_date_end']) ? $_GET['agree_date_end'] : date('Y-m-d')); ?>">
<p>* 광고성 정보 수신(<b>이메일 또는 SMS/카카오톡</b>) 동의일자 기준</p>
</div>
</div>
<!-- 설명 문구 -->
<?php
$thirdpartyLbl = (!empty($config['cf_sms_use'])) ? ' / <b>개인정보 제3자 제공</b>' : '';
$ad_range_text = array(
'all' => "* <b>광고성 정보 수신(이메일 또는 SMS/카카오톡)</b> / <b>마케팅 목적의 개인정보 수집 및 이용</b>{$thirdpartyLbl}에 모두 동의한 회원을 선택합니다.",
'mailling_only' => "* <b>광고성 이메일 수신</b> / <b>마케팅 목적의 개인정보 수집 및 이용</b>{$thirdpartyLbl}에 모두 동의한 회원을 선택합니다.",
'sms_only' => "* <b>광고성 SMS/카카오톡 수신</b> / <b>마케팅 목적의 개인정보 수집 및 이용</b>{$thirdpartyLbl}에 모두 동의한 회원을 선택합니다.",
'month_confirm' => "* 23개월 전(" . date('Y년 m월', strtotime('-23 month')) . ") <b>광고성 정보 수신 동의(이메일 또는 SMS/카카오톡)</b>한 회원을 선택합니다."
);
if (isset($_GET['ad_range_only'], $_GET['ad_range_type']) && isset($ad_range_text[$_GET['ad_range_type']])) {
echo '<div class="ad_range_box"><p>' . $ad_range_text[$_GET['ad_range_type']] . '</p></div>';
}
?>
</div>
<br>
</div>
</div>
</div>
</div>
<!-- 채널 체크박스 -->
<div class="sch_row <?php echo isset($_GET['ad_range_only']) && in_array($_GET['ad_range_type'], array('month_confirm', 'custom_period')) ? '' : 'is-hidden'; ?>">
<div class="ad_range_wrap">
<div class="ad_range_box">
<div class="label">
</div>
<div class="field">
<?php $ad_mailling_checked = isset($_GET['token']) ? (isset($_GET['ad_mailling']) ? 'checked' : '') : 'checked';?>
<?php $ad_sms_checked = isset($_GET['token']) ? (isset($_GET['ad_sms']) ? 'checked' : '') : 'checked';?>
<label><input type="checkbox" name="ad_mailling" value="1" <?php echo $ad_mailling_checked; ?>> 광고성 이메일 수신</label>
<label><input type="checkbox" name="ad_sms" value="1" <?php echo $ad_sms_checked; ?>> 광고성 SMS/카카오톡 수신</label>
</div>
</div>
</div>
</div>
<div class="sch_btn">
<button type="button" id="btnExcelDownload">엑셀파일 다운로드</button>
<button type="button" class="btn_reset" onclick="location.href='?'">초기화</button>
</div>
</div>
</fieldset>
</form>
<script>
document.querySelector('input[name="ad_range_only"]').addEventListener('change', function () {
document.querySelectorAll('.ad_range_wrap').forEach(el => {
el.classList.toggle('is-hidden', !this.checked);
});
});
document.querySelectorAll('#fsearch input, #fsearch select').forEach(el => {
const submit = () => document.getElementById('fsearch').submit();
el.addEventListener(el.type === 'date' ? 'blur' : 'change', submit);
el.addEventListener('keydown', e => {
if (e.key === 'Enter') {
e.preventDefault();
submit();
}
});
});
</script>
<script>
let eventSource = null;
// 일반 엑셀 다운로드 버튼 클릭
document.getElementById('btnExcelDownload').addEventListener('click', () => {
startExcelDownload();
});
// 엑셀 다운로드 실행
// 1. 기존 SSE 종료
function closePreviousEventSource() {
if (eventSource) {
eventSource.close();
eventSource = null;
}
}
// 2. FormData QueryString 변환
function buildDownloadParams(selectedFields = []) {
const formData = new FormData(document.getElementById('fsearch'));
const params = new URLSearchParams(formData);
params.append('mode', 'start');
return params.toString();
}
// 3. 메인 함수
function startExcelDownload(selectedFields = []) {
closePreviousEventSource();
const query = buildDownloadParams(selectedFields);
showDownloadPopup();
eventSource = new EventSource(`member_list_exel_export.php?${query}`);
eventSource.onmessage = handleProgressUpdate();
eventSource.onerror = handleDownloadError();
}
// 다운로드 팝업 표시
function showDownloadPopup() {
const bodyHTML = `
<div class="excel-download-progress">
<div class="progress-desc">
<p class="progress-summary">총 <strong>0</strong>개 파일로 분할됩니다</p>
<p class="progress-message"><strong>(0 / 0)</strong> 파일 다운로드 중</p>
<p class="progress-error"></p>
</div>
<div class="progress-spinner">
<div class="spinner"></div>
<p class="loading-message">
엑셀 파일을 생성 중입니다. 잠시만 기다려주세요.<br>
현재 데이터 기준으로 <strong id="estimatedTimeText"></strong> 정도 소요될 수 있습니다.<br>
<strong>페이지를 벗어나거나 닫으면 다운로드가 중단</strong>되니, 작업 완료까지 기다려 주세요.
</p>
</div>
<div class="progress-box">
<div class="progress-download-box"></div>
</div>
</div>
`;
PopupManager.render('엑셀 다운로드 진행 중', bodyHTML, '', { disableOutsideClose: true });
// 닫기 버튼 이벤트 핸들링
const closeBtn = document.querySelector('.popup-close-btn');
if (closeBtn) {
closeBtn.removeAttribute('onclick');
closeBtn.addEventListener('click', handlePopupCloseWithConfirm);
}
}
// 닫기 버튼 클릭 시 다운로드 중단 여부 확인
function handlePopupCloseWithConfirm(e) {
if (eventSource) {
const confirmClose = confirm("엑셀 다운로드가 진행 중입니다.\n정말 중지하시겠습니까?");
if (!confirmClose) {
e.preventDefault();
return;
}
eventSource.close();
eventSource = null;
alert("엑셀 다운로드가 중단되었습니다.");
}
PopupManager.close('popupOverlay');
}
// 체크박스 선택 시 최대 3개 제한 및 선택된 항목 미리보기 표시
function bindFieldSelectEvents() {
const fieldSelectForm = document.getElementById('fieldSelectForm');
if (!fieldSelectForm) return;
fieldSelectForm.addEventListener('change', function (e) {
if (e.target.name === 'fields') {
const selected = fieldSelectForm.querySelectorAll('input[name="fields"]:checked');
if (selected.length > 3) {
alert("최대 3개까지 선택 가능합니다.");
e.target.checked = false;
return;
}
// 선택된 항목 표시
const previewContainer = document.getElementById('selectedFieldsPreview');
let spans = '<strong>선택된 항목:</strong>';
selected.forEach(field => {
const label = field.parentElement.textContent.trim();
spans += `<span class="field-tag">${label}</span>`;
});
previewContainer.innerHTML = spans;
}
});
}
// 엑셀 생성 및 다운로드 실행
function handleProgressUpdate() {
return function(e) {
const data = JSON.parse(e.data);
const { status, downloadType, message, total, current, totalChunks, currentChunk, zipFile, files, filePath } = data;
// DOM 요소 캐싱
const titleEl = document.getElementById('popupTitle');
const summaryEl = document.querySelector('.progress-summary');
const messageEl = document.querySelector('.progress-message');
const spinnerEl = document.querySelector('.progress-spinner');
const resultEl = document.querySelector('.loading-message');
const downloadBoxEl = document.querySelector('.progress-download-box');
const errorEl = document.querySelector('.progress-error');
if (status === "progress")
{
summaryEl.innerHTML = `총 <strong>${totalChunks}</strong>개 파일로 ` + (downloadType === 2 ? `분할 생성됩니다` : `다운로드됩니다`) + ` (총 ${total.toLocaleString('ko-KR')}건)`;
messageEl.innerHTML = downloadType === 2 ? `<strong>(${currentChunk} / ${totalChunks})</strong> 파일 생성 중` : `엑셀 파일 생성 중`;
/* 작업 소요 시간 : 예상 시간 (1만건당 10초) */
const sec = Math.max(5, Math.ceil(total * 0.0012 * 1.2)); // 최소 5초 보장
const text = `예상 처리 시간은 약 ${sec >= 60 ? `${Math.floor(sec / 60)}분 ${sec % 60}초` : `${sec}초`}`;
document.getElementById('estimatedTimeText').innerText = text;
}
else if (status === "zipping")
{
summaryEl.innerHTML = `총 <strong>${totalChunks}</strong>개 파일이 압축파일로 생성됩니다`;
messageEl.innerHTML = `<strong>${totalChunks}</strong> 파일 압축하는 중`;
}
else if (status === "zippingError")
{
errorEl.innerHTML = message;
}
else if (status === "error")
{
summaryEl.innerHTML = `엑셀 파일 다운로드 실패`;
resultEl.innerHTML = '';
spinnerEl?.classList.add('is-hidden');
const parts = message.split(/<br\s*\/?>/i);
messageEl.innerHTML = parts[0] || '';
errorEl.innerHTML = parts.slice(1).join('<br>') || '';
// SSE 작업 닫기
eventSource?.close();
eventSource = null;
}
else if (status === "done")
{
// SSE 작업 닫기
eventSource?.close();
eventSource = null;
titleEl.textContent = '엑셀 파일 다운로드 완료';
messageEl.innerHTML = `<strong>총 ${total.toLocaleString('ko-KR')}건의 데이터 다운로드가 완료되었습니다!</strong>`;
spinnerEl?.classList.add('is-hidden');
let html = '<p>* 자동으로 다운로드가 되지 않았다면 아래 버튼을 클릭해주세요.</p>';
const baseUrl = `<?php echo G5_DATA_URL; ?>/member_list/<?php echo date('Ymdhis'); ?>/`; // 공통 URL 분리
if (zipFile) {
const url = `${filePath}/${zipFile}`;
html += `<a href="${url}" class="btn btn_03" download>압축파일 다운로드</a>`;
downloadBoxEl.innerHTML = html;
triggerAutoDownload(url, zipFile);
} else if (files?.length) {
files.forEach((file, index) => {
const url = `${filePath}/${file}`;
html += `<a class="btn btn_03" href="${url}" download>엑셀파일 다운로드 ${index + 1}</a>`;
});
downloadBoxEl.innerHTML = html;
if (files.length === 1) {
const url = `${filePath}/${files[0]}`;
triggerAutoDownload(url, files[0]);
} else {
summaryEl.innerHTML = `총 <strong>${totalChunks}</strong>개 파일이 생성되었습니다. 아래 버튼을 눌러 다운로드 받아주세요.`;
}
}
}
}
}
// SSE 오류 처리
function handleDownloadError() {
return function(e){
const errorMessage = e?.message || e?.data || '알 수 없는 오류가 발생했습니다.';
document.querySelector('.progress-summary').innerHTML = `엑셀 파일 다운로드 실패`;
document.querySelector('.progress-message').innerHTML = `엑셀 파일 다운로드에 실패하였습니다`;
document.querySelector('.progress-error').innerHTML = errorMessage;
document.querySelector('.loading-message').innerHTML = '';
document.querySelector('.progress-spinner').classList.add('is-hidden');
if (eventSource) {
eventSource.close();
eventSource = null;
}
}
}
// 자동 다운로드 실행
function triggerAutoDownload(url, filename) {
const a = document.createElement('a');
a.href = url;
a.download = filename;
document.body.appendChild(a);
a.click();
document.body.removeChild(a);
}
</script>
<?php
require_once './admin.tail.php';
+565
View File
@@ -0,0 +1,565 @@
<?php
$sub_menu = "200400";
require_once './_common.php';
require_once './member_list_exel.lib.php'; // 회원관리파일 공통 라이브러리 (상수, 검색 옵션 설정, SQL WHERE 등)
include_once(G5_LIB_PATH.'/PHPExcel.php');
check_demo();
auth_check_menu($auth, $sub_menu, 'w');
ini_set('memory_limit', '-1');
session_write_close(); // 세션 종료 및 잠금 해제 (백그라운드 작업을 위해 필요)
// 파라미터 수집 및 유효성 검사
$params = get_member_export_params();
if (!$params || !is_array($params)) {
member_export_send_progress("error", "데이터가 올바르게 전달되지 않아 작업에 실패하였습니다.");
member_export_write_log(array(), array('success' => false, 'error' => '데이터가 올바르게 전달되지 않아 작업에 실패하였습니다.'));
exit;
}
// 기존 생성된 엑셀 파일 삭제 - LOG 및 오늘 날짜 폴더 제외
$resultExcelDelete = member_export_delete();
// 서버 전송 이벤트(SSE)를 위한 헤더 설정
member_export_set_sse_headers();
// 모드 확인
$mode = isset($_GET['mode']) ? $_GET['mode'] : '';
if ($mode !== 'start') {
member_export_send_progress("error", "잘못된 요청 입니다.");
member_export_write_log($params, array('success' => false, 'error' => '잘못된 요청 입니다.'));
exit;
}
/**
* 회원 내보내기 처리 실행 (예외 처리 포함)
*/
try {
main_member_export($params);
}
catch (Exception $e)
{
// 에러 로그 저장 및 SSE 에러 전송
error_log("[Member Export Error] " . $e->getMessage());
member_export_send_progress("error", $e->getMessage());
member_export_write_log($params, array('success' => false, 'error' => $e->getMessage()));
}
/**
* 메인 내보내기 프로세스
*/
function main_member_export($params)
{
$total = member_export_get_total_count($params);
if($total > MEMBER_EXPORT_MAX_SIZE){
throw new Exception("엑셀 다운로드 가능 범위(최대 " . number_format(MEMBER_EXPORT_MAX_SIZE) . "건)를 초과했습니다.<br>조건을 추가로 설정하신 후 다시 시도해 주세요.");
}
if($total <= 0){
throw new Exception("조회된 데이터가 없어 엑셀 파일을 생성할 수 없습니다.<br>조건을 추가로 설정하신 후 다시 시도해 주세요.");
}
$fileName = 'member_'.MEMBER_BASE_DATE;
$fileList = array();
$zipFileName = '';
if ($total > MEMBER_EXPORT_PAGE_SIZE) {
// 대용량 데이터 - 분할 처리
$pages = (int)ceil($total / MEMBER_EXPORT_PAGE_SIZE);
member_export_send_progress("progress", "", 2, $total, 0, $pages, 0);
for ($i = 1; $i <= $pages; $i++) {
$params['page'] = $i;
member_export_send_progress("progress", "", 2, $total, ($pages == $i ? $total : $i * MEMBER_EXPORT_PAGE_SIZE), $pages, $i);
try {
$data = member_export_get_data($params);
$fileList[] = member_export_create_excel($data, $fileName, $i);
} catch (Exception $e) {
throw new Exception("총 {$pages}개 중 {$i}번째 파일을 생성하지 못했습니다<br>" . $e->getMessage());
}
}
// 압축 파일 생성
if (count($fileList) > 1) {
member_export_send_progress("zipping", "", 2, $total, $total, $pages, $i);
$zipResult = member_export_create_zip($fileList, $fileName); // 압축 파일 생성
if($zipResult['error']){
member_export_write_log($params, array('success' => false, 'error' => $zipResult['error']));
member_export_send_progress("zippingError", $zipResult['error']);
}
if ($zipResult && $zipResult['result']) {
member_export_delete($fileList); // 압축 후 엑셀 파일 제거
$zipFileName = $zipResult['zipFile'];
}
}
} else {
// 소용량 데이터 - 단일 파일
member_export_send_progress("progress", "", 1, $total, 0);
$data = member_export_get_data($params);
member_export_send_progress("progress", "", 1, $total, $total/2);
$fileList[] = member_export_create_excel($data, $fileName, 0);
member_export_send_progress("progress", "", 1, $total, $total);
}
member_export_write_log($params, array('success' => true, 'total' => $total, 'files' => $fileList, 'zip' => isset($zipFileName) ? $zipFileName : null));
member_export_send_progress("done", "", 2, $total, $total, $pages, $pages, $fileList, $zipFileName);
}
/**
* 진행률 전송
*/
function member_export_send_progress($status, $message = "", $downloadType = 1, $total = 1, $current = 1, $totalChunks = 1, $currentChunk = 1, $files = array(), $zipFile = '')
{
// 연결 상태 확인
if (connection_aborted()) return;
$data = array(
'status' => $status,
'message' => $message,
'downloadType' => $downloadType,
'total' => $total,
'current' => $current,
'totalChunks' => $totalChunks,
'currentChunk' => $currentChunk,
'files' => $files,
'zipFile' => $zipFile,
'filePath' => G5_DATA_URL . "/" . MEMBER_BASE_DIR . "/" . MEMBER_BASE_DATE,
);
$json_options = defined('JSON_UNESCAPED_UNICODE') ? JSON_UNESCAPED_UNICODE : 0;
echo "data: " . json_encode($data, $json_options) . "\n\n";
// 더 안정적인 플러시
if (ob_get_level()) ob_end_flush();
flush();
}
/**
* 엑셀 내보내기 설정
*/
function member_export_get_config()
{
$type = 1;
$configs = array(
1 => array(
'title' => array("회원관리파일(일반)"),
'headers' => array('아이디', '이름', '닉네임', '휴대폰번호', '전화번호', '이메일', '주소', '회원권한', '포인트', '가입일', '차단',
'광고성 이메일 수신동의', '광고성 이메일 동의일자', '광고성 SMS/카카오톡 수신동의', '광고성 SMS/카카오톡 동의일자',
'마케팅목적의개인정보수집및이용동의', '마케팅목적의개인정보수집및이용동의일자', '개인정보제3자제공동의', '개인정보제3자제공동의일자'),
'fields' => array('mb_id', 'mb_name', 'mb_nick', 'mb_hp', 'mb_tel', 'mb_email', 'mb_addr1', 'mb_level', 'mb_point', 'mb_datetime', 'mb_intercept_date',
'mb_mailling','mb_mailling_date', 'mb_sms','mb_sms_date', 'mb_marketing_agree',
'mb_marketing_date', 'mb_thirdparty_agree', 'mb_thirdparty_date'),
'widths' => array(20, 20, 20, 20, 20, 30, 30, 10, 15, 25, 10, 20, 25, 20, 25, 20, 25, 20, 25),
),
);
return isset($configs[$type]) ? $configs[$type] : $configs[1];
}
/**
* SSE 헤더 설정
*/
function member_export_set_sse_headers()
{
header('Content-Type: text/event-stream');
header('Cache-Control: no-cache');
header('Connection: keep-alive');
header('X-Accel-Buffering: no');
if (ob_get_level()) ob_end_flush();
ob_implicit_flush(true);
}
/**
* 엑셀 컬럼 문자 반환
*/
function member_export_column_char($i)
{
return chr(65 + $i);
}
/**
* 회원 데이터 조회
*/
function member_export_get_data($params)
{
global $g5;
$config = member_export_get_config();
$fields = $config['fields'];
$fields = array_unique($fields);
// SQL 변환 맵 (가공이 필요한 필드만 정의)
$sqlTransformMap = array(
'mb_datetime' => "IF(mb_datetime = '0000-00-00 00:00:00', '', mb_datetime) AS mb_datetime",
'mb_intercept_date' => "IF(mb_intercept_date != '', '차단됨', '정상') AS mb_intercept_date",
'mb_sms' => "IF(mb_sms = '1', '동의', '미동의') AS mb_sms",
'mb_sms_date' => "IF(mb_sms != '1' OR mb_sms_date = '0000-00-00 00:00:00', '', mb_sms_date) AS mb_sms_date",
'mb_mailling' => "IF(mb_mailling = '1', '동의', '미동의') AS mb_mailling",
'mb_mailling_date' => "IF(mb_mailling != '1' OR mb_mailling_date = '0000-00-00 00:00:00', '', mb_mailling_date) AS mb_mailling_date",
'mb_marketing_agree' => "IF(mb_marketing_agree = '1', '동의', '미동의') AS mb_marketing_agree",
'mb_marketing_date' => "IF(mb_marketing_agree != '1' OR mb_marketing_date = '0000-00-00 00:00:00', '', mb_marketing_date) AS mb_marketing_date",
'mb_thirdparty_agree' => "IF(mb_thirdparty_agree = '1', '동의', '미동의') AS mb_thirdparty_agree",
'mb_thirdparty_date' => "IF(mb_thirdparty_agree != '1' OR mb_thirdparty_date = '0000-00-00 00:00:00', '', mb_thirdparty_date) AS mb_thirdparty_date",
);
// SQL 필드 생성
$sqlFields = array();
foreach ($fields as $field) {
$sqlFields[] = isset($sqlTransformMap[$field]) ? $sqlTransformMap[$field] : $field;
}
$field_list = implode(', ', $sqlFields);
$where = member_export_build_where($params);
$page = (int)(isset($params['page']) ? $params['page'] : 1);
if ($page < 1) $page = 1;
$offset = ($page - 1) * MEMBER_EXPORT_PAGE_SIZE;
$sql = "SELECT {$field_list} FROM {$g5['member_table']} {$where} ORDER BY mb_no DESC LIMIT {$offset}, " . MEMBER_EXPORT_PAGE_SIZE;
$result = sql_query($sql);
if (!$result) {
throw new Exception("데이터 조회에 실패하였습니다");
}
$excelData = array($config['title'], $config['headers']);
while ($row = sql_fetch_array($result)) {
$rowData = array();
foreach ($fields as $field) {
if (isset($row[$field])) {
$rowData[] = function_exists('csv_safe_cell') ? csv_safe_cell($row[$field]) : $row[$field];
} else {
$rowData[] = '';
}
}
$excelData[] = $rowData;
}
return $excelData;
}
/**
* 엑셀 파일 생성
*/
function member_export_create_excel($data, $fileName, $index = 0)
{
$config = member_export_get_config();
if (!class_exists('PHPExcel')) {
error_log('[Member Export Error] PHPExcel 라이브러리를 찾을 수 없습니다.');
throw new Exception('파일 생성 중 내부 오류가 발생했습니다: PHPExcel 라이브러리를 찾을 수 없습니다.');
}
// 현재 설정값 백업
$currentCache = PHPExcel_Settings::getCacheStorageMethod();
// 캐싱 모드 설정 (엑셀 생성 전용)
$cacheMethods = array(
PHPExcel_CachedObjectStorageFactory::cache_to_discISAM,
PHPExcel_CachedObjectStorageFactory::cache_in_memory_serialized
);
foreach ($cacheMethods as $method) {
if (PHPExcel_Settings::setCacheStorageMethod($method)) {
break;
}
}
try {
$excel = new PHPExcel();
$sheet = $excel->setActiveSheetIndex(0);
// 헤더 스타일 적용
$last_char = member_export_column_char(count($config['headers']) - 1);
$sheet->getStyle("A2:{$last_char}2")->applyFromArray(array(
'fill' => array(
'type' => PHPExcel_Style_Fill::FILL_SOLID,
'startcolor' => array('rgb' => 'D9E1F2'), // 연파랑 배경
),
));
// 셀 정렬 및 줄바꿈 설정
$sheet->getStyle("A:{$last_char}")->getAlignment()->setVertical(PHPExcel_Style_Alignment::VERTICAL_CENTER)->setWrapText(true);
// 컬럼 너비 설정
foreach ($config['widths'] as $i => $width) {
$sheet->getColumnDimension(member_export_column_char($i))->setWidth($width);
}
// 데이터 입력
$sheet->fromArray($data, NULL, 'A1');
// 디렉토리 확인
member_export_ensure_directory(MEMBER_EXPORT_DIR);
// 파일명 생성
$subname = $index == 0 ? 'all' : sprintf("%02d", $index);
$filename = $fileName . "_" . $subname . ".xlsx";
$filePath = MEMBER_EXPORT_DIR . "/" . $filename;
// 파일 저장
$writer = PHPExcel_IOFactory::createWriter($excel, 'Excel2007');
$writer->setPreCalculateFormulas(false);
$writer->save($filePath);
unset($excel, $sheet, $writer); // 생성 완료 후 메모리 해제
}
catch (Exception $e)
{
if ($currentCache) {
PHPExcel_Settings::setCacheStorageMethod($currentCache);
}
throw new Exception("엑셀 파일 생성에 실패하였습니다: " . $e->getMessage());
}
// 캐싱 모드 원래 상태로 복원
if ($currentCache) {
PHPExcel_Settings::setCacheStorageMethod($currentCache);
}
return $filename;
}
/**
* 압축 파일 생성
*/
function member_export_create_zip($files, $zipFileName)
{
if (!class_exists('ZipArchive')) {
error_log('[Member Export Error] ZipArchive 클래스를 사용할 수 없습니다.');
return array('error' => '파일을 압축하는 중 문제가 발생했습니다. 개별 파일로 제공됩니다.<br>: ZipArchive 클래스를 사용할 수 없습니다.');
}
member_export_ensure_directory(MEMBER_EXPORT_DIR);
$destinationZipPath = rtrim(MEMBER_EXPORT_DIR, "/") . "/" . $zipFileName . ".zip";
$zip = new ZipArchive();
if ($zip->open($destinationZipPath, ZipArchive::CREATE | ZipArchive::OVERWRITE) !== TRUE) {
return array('error' => "파일을 압축하는 중 문제가 발생했습니다. 개별 파일로 제공됩니다.");
}
foreach ($files as $file) {
$filePath = MEMBER_EXPORT_DIR . "/" . $file;
if (file_exists($filePath)) {
$zip->addFile($filePath, basename($filePath));
}
}
$result = $zip->close();
return array(
'result' => $result,
'zipFile' => $zipFileName . ".zip",
'zipPath' => $destinationZipPath,
);
}
/**
* 디렉토리 생성 및 확인
*/
function member_export_ensure_directory($dir)
{
if (!is_dir($dir)) {
if (!@mkdir($dir, G5_DIR_PERMISSION, true)) {
throw new Exception("디렉토리 생성 실패");
}
@chmod($dir, G5_DIR_PERMISSION);
}
if (!is_writable($dir)) {
throw new Exception("디렉토리 쓰기 권한 없음");
}
}
/**
* 파일 삭제 - 값이 있으면 해당 파일만 삭제, 없으면 디렉토리 내 모든 파일 삭제
* - 알집 생성 완료 시 엑셀 파일 제거
* - 작업 전 오늘 날짜 폴더 및 log 폴더를 제외한 나머지 파일 모두 제거
*/
function member_export_delete($fileList = array())
{
$cnt = 0;
// 파일 리스트가 있는 경우 -> 해당 파일만 삭제
if (!empty($fileList)) {
foreach ($fileList as $file) {
$filePath = rtrim(MEMBER_EXPORT_DIR, DIRECTORY_SEPARATOR) . DIRECTORY_SEPARATOR . $file;
if (file_exists($filePath) && is_file($filePath) && @unlink($filePath)) {
$cnt++;
}
}
}
// 파일 리스트가 없는 경우 -> 디렉토리 내 모든 파일 삭제
else {
$files = glob(rtrim(G5_DATA_PATH . "/" . MEMBER_BASE_DIR, '/') . '/*');
function deleteFolder($dir) {
foreach (glob($dir . '/{.,}*', GLOB_BRACE) as $item) {
if (in_array(basename($item), array('.', '..'))) continue;
is_dir($item) ? deleteFolder($item) : unlink($item);
}
rmdir($dir);
}
foreach ($files as $file) {
$name = basename($file);
// log 폴더와 오늘 날짜로 시작하는 폴더는 제외
if ($name === 'log' || preg_match('/^' . date('Ymd') . '\d{6}$/', $name)) continue;
if (is_file($file) && pathinfo($file, PATHINFO_EXTENSION) !== 'log' && @unlink($file)) {
$cnt++;
} elseif (is_dir($file)) {
deleteFolder($file); // 재귀 폴더 삭제 함수 사용
$cnt++;
}
}
}
return $cnt;
}
/**
* 로그 작성
*/
function member_export_write_log($params, $result = array())
{
global $member;
$maxSize = 1024 * 1024 * 2; // 2MB
$maxFiles = 10; // 최대 로그 파일 수 (필요시 조정)
$username = isset($member['mb_id']) ? $member['mb_id'] : 'guest';
$datetime = date("Y-m-d H:i:s");
if (!is_dir(MEMBER_LOG_DIR)) {
@mkdir(MEMBER_LOG_DIR, G5_DIR_PERMISSION, true);
@chmod(MEMBER_LOG_DIR, G5_DIR_PERMISSION);
}
$logFiles = glob(MEMBER_LOG_DIR . "/export_log_*.log");
if (!$logFiles) {
$logFiles = array();
}
// 최신 파일 기준 정렬 (최신 → 오래된)
usort($logFiles, 'member_export_compare_log_mtime');
$latestLogFile = isset($logFiles[0]) ? $logFiles[0] : null;
// 용량 기준으로 새 파일 생성
if (!$latestLogFile || filesize($latestLogFile) >= $maxSize) {
$latestLogFile = MEMBER_LOG_DIR . "/export_log_" . date("YmdHi") . ".log";
file_put_contents($latestLogFile, '');
array_unshift($logFiles, $latestLogFile);
}
// 최대 파일 수 초과 시 오래된 파일 제거
if (count($logFiles) > $maxFiles) {
$filesToDelete = array_slice($logFiles, $maxFiles);
foreach ($filesToDelete as $file) {
@unlink($file);
}
}
$success = isset($result['success']) && $result['success'] === true;
$status = $success ? '성공' : '실패';
// 조건 정리
$condition = array();
// 검색 조건
if ($params['use_stx'] == 1 && !empty($params['stx'])) {
$sfl_list = get_export_config('sfl_list');
$label = isset($sfl_list[$params['sfl']]) ? $sfl_list[$params['sfl']] : '';
$condition[] = "검색({$params['stx_cond']}) : {$label} - {$params['stx']}";
}
// 레벨 조건
if ($params['use_level'] == 1 && ($params['level_start'] || $params['level_end'])) {
$condition[] = "레벨: {$params['level_start']}~{$params['level_end']}";
}
// 가입일 조건
if ($params['use_date'] == 1 && ($params['date_start'] || $params['date_end'])) {
$condition[] = "가입일: {$params['date_start']}~{$params['date_end']}";
}
// 포인트 조건
if ($params['use_point'] == 1 && $params['point'] !== '') {
$point_cond_map = get_export_config('point_cond_map');
$symbol = isset($point_cond_map[$params['point_cond']]) ? $point_cond_map[$params['point_cond']] : '≥';
$condition[] = "포인트 {$symbol} {$params['point']}";
}
// 휴대폰 여부
if ($params['use_hp_exist'] == 1) {
$condition[] = "휴대폰번호 있는 경우만";
}
// 광고 수신 동의
if ($params['ad_range_only'] == 1) {
$ad_range_list = get_export_config('ad_range_list');
$label = isset($ad_range_list[$params['ad_range_type']]) ? $ad_range_list[$params['ad_range_type']] : '';
$condition[] = "수신동의: 예 ({$label})";
if ($params['ad_range_type'] == "custom_period" && ($params['agree_date_start'] || $params['agree_date_end'])) {
$condition[] = "수신동의일: {$params['agree_date_start']}~{$params['agree_date_end']}";
}
if (in_array($params['ad_range_type'], array("month_confirm", "custom_period"))){
$channels = array_filter(array(
!empty($params['ad_mailling']) && (int)$params['ad_mailling'] === 1 ? '이메일' : null,
!empty($params['ad_sms']) && (int)$params['ad_sms'] === 1 ? 'SMS/카카오톡' : null,
));
if ($channels) {
$condition[] = '수신채널: ' . implode(', ', $channels);
}
}
}
// 차단회원 처리
if ($params['use_intercept'] == 1) {
$intercept_list = get_export_config('intercept_list');
$label = isset($intercept_list[$params['intercept']]) ? $intercept_list[$params['intercept']] : '';
if ($label) $condition[] = $label;
}
$conditionStr = !empty($condition) ? implode(', ', $condition) : '없음';
$line1 = "[{$datetime}] [{$status}] 관리자: {$username}";
// 성공일 경우 추가 정보
if ($success) {
$total = isset($result['total']) ? $result['total'] : 0;
$fileCount = isset($result['zip']) ? 1 : count(isset($result['files']) ? $result['files'] : array());
$line1 .= " | 총 {$total}건 | 파일: {$fileCount}개";
}
$logEntry = $line1 . PHP_EOL;
$logEntry .= "조건: {$conditionStr}" . PHP_EOL;
if (!$success && !empty($result['error'])) {
$logEntry .= "오류 메시지: {$result['error']}" . PHP_EOL;
}
$logEntry .= PHP_EOL;
// 파일에 기록
if (@file_put_contents($latestLogFile, $logEntry, FILE_APPEND | LOCK_EX) === false) {
error_log("[Member Export Error] 로그 파일 기록 실패: {$latestLogFile}");
}
}
function member_export_compare_log_mtime($a, $b)
{
return filemtime($b) - filemtime($a);
}
+72
View File
@@ -0,0 +1,72 @@
<?php
$sub_menu = '100930';
include_once('./_common.php');
if ($is_admin != 'super')
alert('최고관리자만 접근 가능합니다.', G5_URL);
$g5['title'] = '회원관리파일 일괄삭제';
include_once(G5_ADMIN_PATH.'/admin.head.php');
?>
<div class="local_desc02 local_desc">
<p>
완료 메세지가 나오기 전에 프로그램의 실행을 중지하지 마십시오.
</p>
</div>
<?php
flush();
if (!$dir = @opendir(G5_DATA_PATH . '/member_list')) {
echo '<p>회원관리파일를 열지못했습니다.</p>';
}
$cnt = 0;
echo '<ul class="session_del">' . PHP_EOL;
$files = glob(G5_DATA_PATH . '/member_list/*');
$cnt = 0;
// 폴더 및 하위 파일 재귀 삭제 함수
function deleteFolder($folderPath) {
$items = glob($folderPath . '/*');
foreach ($items as $item) {
if (is_dir($item)) {
deleteFolder($item);
} else {
unlink($item);
}
}
rmdir($folderPath); // 폴더 자체 삭제
}
if (is_array($files)) {
foreach ($files as $member_list_file) {
// log 확장자가 아닌 파일/디렉토리 처리
$ext = strtolower(pathinfo($member_list_file, PATHINFO_EXTENSION));
$basename = basename($member_list_file);
if (is_file($member_list_file) && $ext !== 'log') {
unlink($member_list_file);
echo '<li>파일 삭제: ' . $member_list_file . '</li>' . PHP_EOL;
$cnt++;
} elseif (is_dir($member_list_file) && $basename !== 'log') {
deleteFolder($member_list_file);
echo '<li>폴더 삭제: ' . $member_list_file . '</li>' . PHP_EOL;
$cnt++;
}
flush();
if ($cnt % 10 == 0) {
echo PHP_EOL;
}
}
}
echo '<li>완료됨</li></ul>' . PHP_EOL;
echo '<div class="local_desc01 local_desc"><p><strong>회원관리파일 ' . $cnt . '건 삭제 완료됐습니다.</strong><br>프로그램의 실행을 끝마치셔도 좋습니다.</p></div>' . PHP_EOL;
?>
<?php
include_once(G5_ADMIN_PATH.'/admin.tail.php');
+29
View File
@@ -27,12 +27,38 @@ if ($_POST['act_button'] == "선택수정") {
$post_mb_sms = isset($_POST['mb_sms'][$k]) ? (int) $_POST['mb_sms'][$k] : 0;
$post_mb_open = isset($_POST['mb_open'][$k]) ? (int) $_POST['mb_open'][$k] : 0;
$agree_items = array();
// 광고성 이메일 수신동의 일자 추가
$post_mb_mailling_default = isset($_POST['mb_mailling_default'][$k]) ? (int) $_POST['mb_mailling_default'][$k] : 0;
$sql_mailling_date = "";
if ($post_mb_mailling_default != $post_mb_mailling) {
$sql_mailling_date = " , mb_mailling_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 이메일 수신(" . ($post_mb_mailling == 1 ? "동의" : "철회") . ")";
}
// 광고성 SMS/카카오톡 수신동의 일자 추가
$post_mb_sms_default = isset($_POST['mb_sms_default'][$k]) ? (int) $_POST['mb_sms_default'][$k] : 0;
$sql_sms_date = "";
if ($post_mb_sms_default != $post_mb_sms) {
$sql_sms_date = " , mb_sms_date = '".G5_TIME_YMDHIS."' ";
$agree_items[] = "광고성 SMS/카카오톡 수신(" . ($post_mb_sms == 1 ? "동의" : "철회") . ")";
}
// 동의 로그 추가
$sql_agree_log = "";
if (!empty($agree_items)) {
$agree_log = "[".G5_TIME_YMDHIS.", 회원관리 선택수정] " . implode(' | ', $agree_items) . "\n";
$sql_agree_log .= " , mb_agree_log = CONCAT('{$agree_log}', IFNULL(mb_agree_log, ''))";
}
$mb_datas[] = $mb = get_member($_POST['mb_id'][$k]);
if (!(isset($mb['mb_id']) && $mb['mb_id'])) {
$msg .= $mb['mb_id'] . ' : 회원자료가 존재하지 않습니다.\\n';
} elseif ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level']) {
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 회원은 수정할 수 없습니다.\\n';
} elseif ($is_admin != 'super' && $post_mb_level >= (int) $member['mb_level']) {
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.\\n';
} elseif ($member['mb_id'] == $mb['mb_id']) {
$msg .= $mb['mb_id'] . ' : 로그인 중인 관리자는 수정 할 수 없습니다.\\n';
} else {
@@ -50,6 +76,9 @@ if ($_POST['act_button'] == "선택수정") {
mb_open = '" . $post_mb_open . "',
mb_certify = '" . sql_real_escape_string($post_mb_certify) . "',
mb_adult = '{$mb_adult}'
{$sql_mailling_date}
{$sql_sms_date}
{$sql_agree_log}
where mb_id = '" . sql_real_escape_string($mb['mb_id']) . "' ";
sql_query($sql);
}
+13 -1
View File
@@ -117,6 +117,15 @@ if ($new == 'new' || !$code) {
});
});
function htmlEscape(str) {
return str
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;');
}
function add_menu_list(name, link, code) {
var $menulist = $("#menulist", opener.document);
var ms = new Date().getTime();
@@ -126,7 +135,10 @@ if ($new == 'new' || !$code) {
<?php } else { ?>
sub_menu_class = " class=\"td_category sub_menu_class\"";
<?php } ?>
name = htmlEscape(name);
link = htmlEscape(link);
var list = "<tr class=\"menu_list menu_group_<?php echo $code; ?>\">";
list += "<td" + sub_menu_class + ">";
list += "<label for=\"me_name_" + ms + "\" class=\"sound_only\">메뉴<strong class=\"sound_only\"> 필수</strong></label>";
+1 -1
View File
@@ -30,7 +30,7 @@ for ($i = 0; $i < $count; $i++) {
$code = is_array($_POST['code']) ? strip_tags($_POST['code'][$i]) : '';
$me_name = is_array($_POST['me_name']) ? strip_tags($_POST['me_name'][$i]) : '';
$me_link = (preg_match('/^javascript/i', $_POST['me_link'][$i]) || preg_match('/script:/i', $_POST['me_link'][$i])) ? G5_URL : strip_tags(clean_xss_attributes($_POST['me_link'][$i]));
$me_link = (preg_match('/^javascript/i', $_POST['me_link'][$i]) || preg_match('/script:/i', $_POST['me_link'][$i])) ? G5_URL : addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['me_link'][$i]))));
if (!$code || !$me_name || !$me_link) {
continue;
+2 -2
View File
@@ -16,7 +16,7 @@ if ($w == 'd') {
check_admin_token();
$nw_subject = isset($_POST['nw_subject']) ? strip_tags(clean_xss_attributes($_POST['nw_subject'])) : '';
$nw_subject = isset($_POST['nw_subject']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['nw_subject'])))) : '';
$posts = array();
$check_keys = array(
@@ -37,7 +37,7 @@ foreach ($check_keys as $key => $val) {
if ($val === 'int') {
$posts[$key] = isset($_POST[$key]) ? (int) $_POST[$key] : 0;
} elseif ($val === 'str') {
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : 0;
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : 0;
} else {
$posts[$key] = isset($_POST[$key]) ? trim($_POST[$key]) : 0;
}
+4 -1
View File
@@ -25,6 +25,9 @@ if (!$sst) {
$sst = "po_id";
$sod = "desc";
}
$allowed_sst = array('po_id', 'mb_id', 'po_content', 'po_point', 'po_datetime');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'po_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
@@ -66,7 +69,7 @@ if ($config['cf_point_term'] > 0) {
$po_expire_term = $config['cf_point_term'];
}
if (strstr($sfl, "mb_id")) {
if (strpos($sfl, "mb_id") !== false) {
$mb_id = $stx;
} else {
$mb_id = "";
+7 -2
View File
@@ -43,11 +43,16 @@ foreach ($_POST as $key => $value) {
}
if (in_array($key, $check_keys)) {
$_POST[$key] = strip_tags(clean_xss_attributes($value));
if (preg_match('/^po_cnt[1-9]$/', $key) || in_array($key, array('po_level', 'po_point', 'po_id'), true)) {
$_POST[$key] = (int) $value;
} else {
$_POST[$key] = addslashes(strip_tags(clean_xss_attributes(stripslashes($value))));
}
}
}
$po_id = isset($_POST['po_id']) ? $_POST['po_id'] : '';
$po_id = isset($_POST['po_id']) ? (int) $_POST['po_id'] : 0;
$_POST['po_use'] = isset($_POST['po_use']) ? (int) $_POST['po_use'] : 0;
if ($w == '') {
$sql = " insert {$g5['poll_table']}
+3
View File
@@ -21,6 +21,9 @@ if (!$sst) {
$sst = "po_id";
$sod = "desc";
}
$allowed_sst = array('po_id', 'po_subject', 'po_level', 'po_use', 'po_etc');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'po_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
+5
View File
@@ -6,6 +6,8 @@ auth_check_menu($auth, $sub_menu, 'r');
// 체크된 자료 삭제
if (isset($_POST['chk']) && is_array($_POST['chk'])) {
check_admin_token();
for ($i = 0; $i < count($_POST['chk']); $i++) {
$pp_id = (int) $_POST['chk'][$i];
@@ -36,6 +38,9 @@ if (!$sst) {
$sst = "pp_id";
$sod = "desc";
}
$allowed_sst = array('pp_id', 'pp_word', 'pp_date', 'pp_ip');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'pp_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
+7 -1
View File
@@ -15,12 +15,18 @@ $qaconfig = get_qa_config();
$check_keys = array('qa_title', 'qa_category', 'qa_skin', 'qa_mobile_skin', 'qa_use_email', 'qa_req_email', 'qa_use_hp', 'qa_req_hp', 'qa_use_sms', 'qa_send_number', 'qa_admin_hp', 'qa_admin_email', 'qa_subject_len', 'qa_mobile_subject_len', 'qa_page_rows', 'qa_mobile_page_rows', 'qa_image_width', 'qa_upload_size');
foreach ($check_keys as $key) {
$$key = $_POST[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
$$key = $_POST[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
}
$qa_include_head = isset($qa_include_head) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_head, 0, 255)) : '';
$qa_include_tail = isset($qa_include_tail) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_tail, 0, 255)) : '';
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
if ($is_admin !== 'super') {
$qa_include_head = isset($qaconfig['qa_include_head']) ? $qaconfig['qa_include_head'] : '';
$qa_include_tail = isset($qaconfig['qa_include_tail']) ? $qaconfig['qa_include_tail'] : '';
}
// 관리자가 자동등록방지를 사용해야 할 경우
if ($board && ($qaconfig['qa_include_head'] !== $qa_include_head || $qaconfig['qa_include_tail'] !== $qa_include_tail) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
include_once G5_CAPTCHA_PATH . '/captcha.lib.php';
+61 -24
View File
@@ -9,40 +9,76 @@ if (!$config['cf_email_use'])
include_once(G5_LIB_PATH.'/mailer.lib.php');
$token = get_token();
$g5['title'] = '메일 테스트';
include_once('./admin.head.php');
if (isset($_POST['email'])) {
check_admin_token();
$_POST['email'] = strip_tags($_POST['email']);
$email = explode(',', $_POST['email']);
$real_email = array();
$sent_email = array(); // 발송 요청 성공
$failed_email = array(); // 발송 실패 (메일 서버에서 거부/오류)
for ($i=0; $i<count($email); $i++){
if (!preg_match("/([0-9a-zA-Z_-]+)@([0-9a-zA-Z_-]+)\.([0-9a-zA-Z_-]+)/", $email[$i])) continue;
$real_email[] = $email[$i];
mailer($config['cf_admin_email_name'], $config['cf_admin_email'], trim($email[$i]), '[메일검사] 제목', '<span style="font-size:9pt;">[메일검사] 내용<p>이 내용이 제대로 보인다면 보내는 메일 서버에는 이상이 없는것입니다.<p>'.G5_TIME_YMDHIS.'<p>이 메일 주소로는 회신되지 않습니다.</span>', 1);
$to = trim($email[$i]);
$send_result = mailer($config['cf_admin_email_name'], $config['cf_admin_email'], $to, '[메일검사] 제목', '<span style="font-size:9pt;">[메일검사] 내용<p>이 내용이 제대로 보인다면 보내는 메일 서버에는 이상이 없는것입니다.<p>'.G5_TIME_YMDHIS.'<p>이 메일 주소로는 회신되지 않습니다.</span>', 1);
if ($send_result) {
$sent_email[] = $to;
} else {
$failed_email[] = $to;
}
}
if( $real_email ){
if( $sent_email || $failed_email ){
echo '<section>';
echo '<h2>결과메세지</h2>';
echo '<div class="local_desc01 local_desc"><p>';
echo '다음 '.count($real_email).'개의 메일 주소로 테스트 메일 발송이 완료되었습니다.';
echo '</p></div>';
echo '<ul>';
for ($i=0;$i<count($real_email);$i++) {
echo '<li>'.$real_email[$i].'</li>';
echo '<h2>결과 메시지</h2>';
if( $sent_email ){
echo '<div class="local_desc01 local_desc"><p>';
echo '다음 '.count($sent_email).'개의 메일 주소로 테스트 메일 <strong>발송 요청이 성공</strong>했습니다. <strong>수신함 도착 여부는 별도 확인이 필요합니다.</strong>';
echo '</p></div>';
echo '<ul>';
for ($i=0;$i<count($sent_email);$i++) {
echo '<li>'.get_text($sent_email[$i]).'</li>';
}
echo '</ul>';
echo '<div class="local_desc02 local_desc"><p>';
echo '<strong>발송 요청 성공은 사이트가 메일 서버에 메일을 넘겼다는 의미이며, 받은편지함 도착을 보장하지는 않습니다.</strong><br>';
echo '메일이 보이지 않는다면 아래 항목을 순서대로 확인해 주십시오.';
echo '</p></div>';
echo '<ol>';
echo '<li>받은편지함뿐 아니라 <strong>스팸함, 정크메일함, 프로모션함</strong>을 확인합니다.</li>';
echo '<li>네이버, 지메일, 회사메일 등 <strong>서로 다른 메일 주소</strong>로 다시 테스트합니다.</li>';
echo '<li>관리자 메일 주소가 사이트 도메인과 같은지 확인합니다. 도메인이 다르면 스팸으로 분류될 가능성이 높습니다.</li>';
echo '<li>도메인 메일을 사용한다면 <strong>SPF, DKIM, DMARC</strong> 설정을 확인합니다.</li>';
echo '<li>계속 도착하지 않으면 서버 개발자에게 메일 발송 로그를 확인해주세요.</li>';
echo '</ol>';
}
echo '</ul>';
echo '<div class="local_desc02 local_desc"><p>';
echo '해당 주소로 테스트 메일이 도착했는지 확인해 주십시오.<br>';
echo '만약, 테스트 메일이 오지 않는다면 더 다양한 계정의 메일 주소로 메일을 보내 보십시오.<br>';
echo '그래도 메일이 하나도 도착하지 않는다면 메일 서버(sendmail server)의 오류일 가능성이 높으니, 웹 서버관리자에게 문의하여 주십시오.<br>';
echo '도메인을 소유하고 있을시 SPF, DKIM 설정이 필요할수 있습니다.<br>';
echo '</p></div>';
if( $failed_email ){
echo '<div class="local_desc01 local_desc" style="color:#d9534f"><p>';
echo '다음 '.count($failed_email).'개의 메일 주소는 <strong>발송에 실패</strong>했습니다.';
echo '</p></div>';
echo '<ul>';
for ($i=0;$i<count($failed_email);$i++) {
echo '<li>'.get_text($failed_email[$i]).'</li>';
}
echo '</ul>';
echo '<div class="local_desc02 local_desc"><p>';
echo '발송 실패는 받는 사람의 문제가 아니라 <strong>보내는 서버(메일 발송) 설정 문제</strong>일 가능성이 높습니다.<br>';
echo 'SMTP 정보(주소/포트/인증)가 올바른지, 서버에서 메일 발송(sendmail/mail 함수)이 허용되어 있는지 확인하시고, 웹 서버 관리자(호스팅 업체)에게 문의해 주십시오.<br>';
echo '자세한 오류 내용은 서버의 PHP error_log 에 기록됩니다.<br>';
echo '</p></div>';
}
echo '</section>';
}
}
@@ -52,15 +88,16 @@ if (isset($_POST['email'])) {
<h2>테스트 메일 발송</h2>
<div class="local_desc02 local_desc">
<p>
메일서버가 정상적으로 동작 중인지 확인할 수 있습니다.<br>
사이트에서 메일 서버로 메일을 전달할 수 있는지 확인합니다. 이 테스트는 받은편지함 도착을 보장하지 않습니다.<br>
아래 입력칸에 테스트 메일을 발송하실 메일 주소를 입력하시면, [메일검사] 라는 제목으로 테스트 메일을 발송합니다.<br>
보내는 메일주소 : <?php echo get_sanitize_input($config['cf_admin_email']); ?><br>
<?php if (function_exists('domain_mail_host') && $config['cf_admin_email'] && stripos($config['cf_admin_email'], domain_mail_host()) === false) { ?>
<?php echo '외부메일설정이나 기타 설정을 하지 않았다면, 도메인과 다른 헤더로 여겨 스팸이나 차단될 가능성이 있습니다.<br>기본환경설정에서 관리자 메일 주소를 name'.domain_mail_host().' 과 같은 도메인 형식으로 설정할것을 권장합니다.'; ?>
<?php echo '외부메일설정이나 기타 설정을 하지 않았다면, 도메인과 다른 헤더로 여겨 스팸이나 차단될 가능성이 있습니다.<br>외부메일설정이나 기타 설정을 하지 않았다면, 기본환경설정에서 관리자 메일 주소를 name'.domain_mail_host().' 과 같은 도메인 형식으로 설정할것을 권장합니다.'; ?>
<?php } ?>
</p>
</div>
<form name="fsendmailtest" method="post">
<input type="hidden" name="token" value="<?php echo $token; ?>">
<fieldset id="fsendmailtest">
<legend>테스트메일 발송</legend>
<label for="email">받는 메일주소<strong class="sound_only"> 필수</strong></label>
@@ -70,11 +107,11 @@ if (isset($_POST['email'])) {
</form>
<div class="local_desc02 local_desc">
<p>
만약 [메일검사] 라는 내용으로 테스트 메일이 도착하지 않는다면 보내는 메일서버 혹은 받는 메일서버 중 문제가 발생했을 가능성이 있습니다.<br>
따라서 보다 정확한 테스트를 원하신다면 여러 곳으로 테스트 메일을 발송하시기 바랍니다.<br>
테스트 결과가 발송 요청 성공으로 표시되어도 수신 메일 서버의 스팸 정책에 따라 도착하지 않을 수 있습니다.<br>
정확한 확인을 위해 여러 메일 서비스로 테스트하고, 도착하지 않으면 스팸함과 도메인 인증(SPF, DKIM, DMARC)을 확인해 주십시오.<br>
</p>
</div>
</section>
<?php
include_once('./admin.tail.php');
include_once('./admin.tail.php');
+7 -6
View File
@@ -17,9 +17,10 @@ include_once('./admin.head.php');
<h3>신용카드 전자결제 서비스<br><span>(계좌이체, 가상계좌 결제 포함)</span></h3>
<ul>
<li><a href="http://sir.kr/main/service/p_pg.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_01.jpg" alt="KCP 신용카드 전자결제 신청하기"></a></li>
<li><a href="http://sir.kr/main/service/lg_pg.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_02.jpg?v2" alt="토스페이먼츠 전자결제 신청하기"></a></li>
<li class="last"><a href="http://sir.kr/main/service/inicis_pg.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_06.jpg" alt="KG 이니시스 전자결제 신청하기"></a></li>
<li><a href="https://sir.kr/services/pg/kcp" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_01.jpg" alt="NHN KCP 신용카드 전자결제 신청하기"></a></li>
<li><a href="https://sir.kr/services/pg/toss" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_02.jpg?v2" alt="토스페이먼츠 전자결제 신청하기"></a></li>
<li><a href="https://sir.kr/services/pg/inicis" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_06.jpg" alt="KG 이니시스 전자결제 신청하기"></a></li>
<li class="last"><a href="https://sir.kr/services/pg/nice" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_07.jpg" alt="나이스페이먼츠 전자결제 신청하기"></a></li>
</ul>
</div>
@@ -27,8 +28,8 @@ include_once('./admin.head.php');
<h3>본인확인 서비스</h3>
<ul>
<li><a href="http://sir.kr/main/service/p_cert.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_01.jpg" alt="KCP 신청하기"></a></li>
<li><a href="http://sir.kr/main/service/inicis_cert.php" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_06.jpg" alt="KG이니시스 신청하기"></a></li>
<li><a href="https://sir.kr/services/auth/kcp" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_01.jpg" alt="NHN KCP 휴대폰 본인확인 신청하기"></a></li>
<li><a href="https://sir.kr/services/auth/inicis" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_06.jpg" alt="KG이니시스 본인확인 신청하기"></a></li>
</ul>
</div>
@@ -38,7 +39,7 @@ include_once('./admin.head.php');
<h3>SMS 문자 서비스</h3>
<p>주문이나 배송시에 상점운영자 또는 고객에게 휴대폰으로 단문메세지 (최대 한글 40자, 영문 80자)를 발송합니다.</p>
</div>
<div class="svc_btn2"><a href="http://icodekorea.com/res/join_company_fix_a.php?sellid=sir2" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_05.jpg" alt="아이코드 SMS 서비스 신청하기"></a></div>
<div class="svc_btn2"><a href="https://sir.kr/services/message/icode" target="_blank"><img src="<?php echo G5_ADMIN_URL ?>/img/svc_btn_05.jpg" alt="아이코드 SMS 서비스 신청하기"></a></div>
</div>
</div>
+1 -1
View File
@@ -31,7 +31,7 @@ include_once("./admin.head.php");
echo $list_tag_st;
while($file=readdir($dir)) {
if (!strstr($file,'sess_')) continue;
if (strpos($file,'sess_') === false) continue;
if (strpos($file,'sess_')!=0) continue;
$session_file = G5_DATA_PATH.'/session/'.$file;
+244 -4
View File
@@ -1,6 +1,45 @@
<?php
if (!defined('_GNUBOARD_')) exit;
function get_shop_skin_dirs($is_mobile=false)
{
global $config;
$skin_path = $is_mobile ? G5_MOBILE_PATH.'/'.G5_SKIN_DIR : G5_SKIN_PATH;
$skins = get_skin_dir('shop', $skin_path);
if(defined('G5_THEME_PATH') && $config['cf_theme']) {
$theme_skin_path = $is_mobile ? G5_THEME_MOBILE_PATH.'/'.G5_SKIN_DIR : G5_THEME_PATH.'/'.G5_SKIN_DIR;
$dirs = get_skin_dir('shop', $theme_skin_path);
if(!empty($dirs)) {
foreach($dirs as $dir) {
$skins[] = 'theme/'.$dir;
}
}
}
return $skins;
}
function check_shop_skin_dir($skin_dir, $label, $is_mobile=false)
{
if( $skin_dir === '' ) {
return;
}
if( preg_match('#\.+(\/|\\\)#', $skin_dir) ){
alert($label.' 폴더명에 포함될수 없는 문자가 들어있습니다.');
}
if( ! is_include_path_check($skin_dir, 1) ){
alert('오류 : 데이터폴더가 포함된 path 또는 잘못된 path 를 포함할수 없습니다.');
}
if( ! in_array($skin_dir, get_shop_skin_dirs($is_mobile), true) ){
alert($label.'을 올바르게 선택해 주십시오.');
}
}
// 상품옵션별재고 또는 상품재고에 더하기
function add_io_stock($it_id, $ct_qty, $io_id="", $io_type=0)
{
@@ -125,12 +164,15 @@ function pg_setting_check($is_print=false){
$msg = '';
$pg_msg = '';
$pg_test_conf_link = G5_ADMIN_URL.'/shop_admin/configform.php#de_card_test1';
if( $default['de_card_test'] ){
if( $default['de_pg_service'] === 'kcp' && $default['de_kcp_mid'] && $default['de_kcp_site_key'] ){
$pg_msg = 'NHN KCP';
} else if ( $default['de_pg_service'] === 'lg' && $config['cf_lg_mid'] && $config['cf_lg_mert_key'] ){
$pg_msg = 'LG유플러스';
} else if ( $default['de_pg_service'] === 'toss' && $config['cf_lg_mid'] && $config['cf_toss_client_key'] && $config['cf_toss_secret_key'] ){
$msg .= '<div class="admin_pg_notice od_test_caution">(주의!) 토스페이먼츠 결제의 결제 설정이 현재 테스트결제로 되어 있습니다.<br>반드시 <a href="#lg_info_anchor">상점 API키</a>를 <u>[테스트]키</u>로 설정한 후 테스트결제를 진행해야합니다.<br>쇼핑몰 운영 시에는 실결제로 전환하여 <u>[라이브]키</u>로 설정해 주시기 바랍니다.<br>아래 링크를 클릭하여 실결제로 설정하여 운영해 주세요.<br><a href="'.$pg_test_conf_link.'" class="pg_test_conf_link">'.$pg_test_conf_link.'</a></div>';
} else if ( $default['de_pg_service'] === 'inicis' && $default['de_inicis_mid'] && $default['de_inicis_sign_key'] ){
$pg_msg = 'KG이니시스';
} else if ( $default['de_pg_service'] === 'nicepay' && $default['de_nicepay_mid'] && $default['de_nicepay_key'] ){
@@ -147,7 +189,6 @@ function pg_setting_check($is_print=false){
}
if( $pg_msg ){
$pg_test_conf_link = G5_ADMIN_URL.'/shop_admin/configform.php#de_card_test1';
$msg .= '<div class="admin_pg_notice od_test_caution">(주의!) '.$pg_msg.' 결제의 결제 설정이 현재 테스트결제 로 되어 있습니다.<br>테스트결제시 실제 결제가 되지 않으므로, 쇼핑몰 운영중이면 반드시 실결제로 설정하여 운영하셔야 합니다.<br>아래 링크를 클릭하여 실결제로 설정하여 운영해 주세요.<br><a href="'.$pg_test_conf_link.'" class="pg_test_conf_link">'.$pg_test_conf_link.'</a></div>';
}
@@ -159,6 +200,7 @@ function pg_setting_check($is_print=false){
}
function is_cancel_shop_pg_order($od){
global $default;
$is_od_pg_cancel = false;
@@ -170,9 +212,205 @@ function is_cancel_shop_pg_order($od){
$is_od_pg_cancel = true;
}
if($od['od_pg'] === 'toss' && in_array($od['od_settle_case'], array('계좌이체', '휴대폰'))) {
$is_od_pg_cancel = true;
}
if ($od['od_pg'] === 'inicis' && !empty($default['de_inicis_pro_use']) && !empty($od['od_tno'])
&& in_array($od['od_settle_case'], array('신용카드', '간편결제', '가상계좌', '계좌이체', '휴대폰', '삼성페이', 'lpay', 'inicis_kakaopay'))) {
$is_od_pg_cancel = true;
}
return $is_od_pg_cancel;
}
function check_order_inicis_pro_payments($run_external = true){
include_once(G5_SHOP_PATH.'/inicis/pro/inicis_pro.lib.php');
// 사이트 이용 흐름에서 실행되는 경량 감시는 잠금 대기 없이 즉시 시도하고,
// 획득하지 못하면 다른 요청이 이미 처리 중이므로 그대로 넘어간다.
$monitor_lock = inicis_pro_lock('monitor_process', $run_external ? 10 : 0);
if ($monitor_lock === '')
return false;
check_order_inicis_pro_payments_run($run_external);
inicis_pro_unlock($monitor_lock);
return true;
}
// 서버 스케줄러 없이 사이트 접속 흐름에서 실행되는 경량 감시.
// 방문자 응답을 먼저 종료해 페이지 지연 없이 뒤에서 처리한다.
function check_order_inicis_pro_payments_inline(){
global $default;
if (empty($default['de_pg_service']) || $default['de_pg_service'] !== 'inicis' || empty($default['de_inicis_pro_use']))
return;
if (function_exists('fastcgi_finish_request'))
@fastcgi_finish_request();
@ignore_user_abort(true);
check_order_inicis_pro_payments(false);
}
function check_order_inicis_pro_payments_run($run_external = true){
global $g5, $config, $default;
include_once(G5_SHOP_PATH.'/inicis/pro/inicis_pro.lib.php');
include_once(G5_ADMIN_PATH.'/shop_admin/inicislog.lib.php');
if (!inicis_pro_audit_schema_ready()) {
// 스키마가 준비되지 않았어도 감시 시각을 전진시켜, 사이트 접속 흐름의
// 인라인 감시가 매 요청마다 재등록·재실행되는 것을 막는다.
if (array_key_exists('de_inicis_pro_monitor_at', $default))
sql_query(" update {$g5['g5_shop_default_table']}
set de_inicis_pro_monitor_at = '".G5_TIME_YMDHIS."' ", false);
return;
}
$log_days = isset($default['de_inicis_pro_log_days']) ? (int) $default['de_inicis_pro_log_days'] : 365;
if ($log_days >= 30) {
inicis_pro_purge_events($log_days, 500);
inicis_pro_purge_payloads($log_days, 200);
}
$summary_days = isset($default['de_inicis_pro_summary_days']) ? (int) $default['de_inicis_pro_summary_days'] : 1825;
if ($summary_days >= 365)
inicis_pro_purge_summaries($summary_days, 50);
$tables = inicis_pro_audit_tables();
$expired_count = 0;
$expired_result = sql_query(" select ip_oid from `{$tables['summary']}`
where ip_status = 'request_ready'
and ip_updated_at < date_sub(now(), interval 30 minute)
order by ip_updated_at asc
limit 50 ", false);
if ($expired_result) {
while ($expired = sql_fetch_array($expired_result)) {
if (inicis_pro_audit_write($expired['ip_oid'], 'request', 'request_expired', array(
'source' => 'system',
'message' => '결제창 요청 후 인증결과가 없어 미진행으로 정리'
)))
$expired_count++;
}
}
$order_amount_sql = "(o.od_cart_price + o.od_send_cost + o.od_send_cost2 - o.od_cart_coupon - o.od_coupon - o.od_send_coupon - o.od_receipt_point)";
$anomaly_sql = inicis_admin_anomaly_sql();
$sql_from = " from `{$tables['summary']}` p
left join {$g5['g5_shop_order_table']} o on p.ip_order_type <> 'personal' and o.od_id = p.ip_oid
left join {$g5['g5_shop_personalpay_table']} pp on p.ip_order_type = 'personal' and pp.pp_id = p.ip_oid ";
$sql_fields = " select p.*,
o.od_id as order_oid, o.od_tno as order_tid, o.od_status as order_status,
o.od_receipt_price as order_receipt_price, o.od_misu as order_misu, o.od_cancel_price as order_cancel_price,
o.od_settle_case as order_settle_case, $order_amount_sql as order_amount,
pp.pp_id as personal_oid, pp.pp_tno as personal_tid, pp.pp_price as personal_amount, pp.pp_receipt_price as personal_receipt_price ";
$recover_result = sql_query(" select ip_oid from `{$tables['summary']}`
where ip_tid = ''
and ip_status in ('authentication_received','approval_started','validation_failed','order_saving')
and ip_updated_at < date_sub(now(), interval 3 minute)
order by ip_updated_at asc
limit 5 ", false);
if ($recover_result) {
while ($recover_row = sql_fetch_array($recover_result))
inicis_pro_recover_approved_tid($recover_row['ip_oid'], 'system');
}
$reconcile_count = 0;
$reconcile_failed_count = 0;
if ($run_external && empty($default['de_card_test']) && !empty($default['de_inicis_pro_reconcile_use']) && inicis_pro_get_iniapi_key() !== '') {
$result = sql_query(" $sql_fields $sql_from
where p.ip_tid <> ''
and p.ip_updated_at < date_sub(now(), interval 3 minute)
and (p.ip_pg_checked_at is null or p.ip_pg_checked_at < date_sub(now(), interval 1 hour))
and (p.ip_refund_required = '1'
or $anomaly_sql
or (p.ip_updated_at > date_sub(now(), interval 7 day)
and (p.ip_status in ('order_saved','paid','paid_after_cancel','vbank_issued','canceled','refund_completed')
or p.ip_cancel_status <> '')))
order by p.ip_refund_required desc, p.ip_updated_at asc
limit 10 ", false);
if ($result) {
while ($row = sql_fetch_array($result)) {
$inquiry = inicis_pro_inquiry($row['ip_tid'], $row['ip_oid'], $row);
if (inicis_pro_save_inquiry($row['ip_oid'], $inquiry, 'system') && !empty($inquiry['success']))
$reconcile_count++;
else
$reconcile_failed_count++;
}
}
}
$anomaly_count_row = sql_fetch(" select count(*) as cnt $sql_from where $anomaly_sql ");
$anomaly_count = isset($anomaly_count_row['cnt']) ? (int) $anomaly_count_row['cnt'] : 0;
if ($run_external)
$monitor_message = '미진행 '.$expired_count.'건 정리 / KG 대사 성공 '.$reconcile_count.'건, 실패 '.$reconcile_failed_count.'건 / 확인 필요 '.$anomaly_count.'건';
else
$monitor_message = '미진행 '.$expired_count.'건 정리 / 확인 필요 '.$anomaly_count.'건';
if (array_key_exists('de_inicis_pro_monitor_at', $default)) {
$monitor_set = "de_inicis_pro_monitor_at = '".G5_TIME_YMDHIS."'";
if (isset($default['de_inicis_pro_monitor_message']))
$monitor_set .= ", de_inicis_pro_monitor_message = '".sql_escape_string($monitor_message)."'";
sql_query(" update {$g5['g5_shop_default_table']} set $monitor_set ", false);
}
// 테스트 거래는 상세 화면에서 직접 조회하며 운영 메일에는 포함하지 않는다.
if (!empty($default['de_card_test']))
return;
if (empty($default['de_inicis_pro_alert_use']) || empty($config['cf_email_use']) || empty($config['cf_admin_email']))
return;
$result = sql_query(" $sql_fields $sql_from
where $anomaly_sql
order by p.ip_updated_at asc
limit 20 ", false);
if (!$result)
return;
$alert_rows = array();
$mail_msg = '';
while ($row = sql_fetch_array($result)) {
if (!inicis_admin_is_anomaly($row))
continue;
$alert_key = inicis_admin_alert_key($row);
if (!empty($row['ip_alert_key']) && $row['ip_alert_key'] === $alert_key)
continue;
$pg_state = !empty($row['ip_pg_checked_at'])
? ($row['ip_pg_result_code'] === '00' ? inicis_admin_pg_status_label($row['ip_pg_status']) : '거래조회 실패')
: '미조회';
$mail_msg .= '<tr>'
.'<td style="padding:6px;border:1px solid #ddd"><a href="'.G5_ADMIN_URL.'/shop_admin/inicislogview.php?oid='.urlencode($row['ip_oid']).'">'.get_text($row['ip_oid']).'</a></td>'
.'<td style="padding:6px;border:1px solid #ddd">'.get_text(inicis_admin_status_label(inicis_admin_primary_status($row))).'</td>'
.'<td style="padding:6px;border:1px solid #ddd">'.get_text($pg_state).'</td>'
.'<td style="padding:6px;border:1px solid #ddd;text-align:right">'.number_format((int) $row['ip_amount']).'원</td>'
.'</tr>';
$alert_rows[] = array('oid' => $row['ip_oid'], 'key' => $alert_key);
}
if (!count($alert_rows))
return;
include_once(G5_LIB_PATH.'/mailer.lib.php');
$content = '<p>KG이니시스 결제와 영카트 주문을 대조해야 하는 거래가 확인됐습니다.</p>'
.'<p>자동으로 주문을 생성하거나 결제를 취소하지 않았습니다. KG이니시스 거래조회 결과와 상점관리자 거래내역을 확인한 후 조치해 주십시오.</p>'
.'<table style="border-collapse:collapse"><thead><tr><th style="padding:6px;border:1px solid #ddd">주문번호</th><th style="padding:6px;border:1px solid #ddd">로컬 상태</th><th style="padding:6px;border:1px solid #ddd">KG 상태</th><th style="padding:6px;border:1px solid #ddd">금액</th></tr></thead><tbody>'
.$mail_msg.'</tbody></table>';
$sent = mailer($config['cf_admin_email_name'], $config['cf_admin_email'], $config['cf_admin_email'], '['.$config['cf_title'].'] KG이니시스 결제 확인 필요', $content, 1);
if (!$sent)
return;
foreach ($alert_rows as $alert_row) {
sql_query(" update `{$tables['summary']}`
set ip_alerted_at = '".G5_TIME_YMDHIS."',
ip_alert_key = '".sql_escape_string($alert_row['key'])."'
where ip_oid = '".sql_escape_string($alert_row['oid'])."' ", false);
}
}
function check_order_inicis_tmps(){
global $g5, $config, $default, $member;
@@ -180,7 +418,9 @@ function check_order_inicis_tmps(){
if( ! $admin_cookie_time ){
if( $default['de_pg_service'] === 'inicis' && empty($default['de_card_test']) ){
if ($default['de_pg_service'] === 'inicis' && !empty($default['de_inicis_pro_use'])) {
check_order_inicis_pro_payments();
} elseif( $default['de_pg_service'] === 'inicis' && empty($default['de_card_test']) ){
$sql = " select * from {$g5['g5_shop_inicis_log_table']} where P_TID <> '' and P_TYPE in ('CARD', 'ISP', 'BANK') and P_MID <> '' and P_STATUS = '00' and is_mail_send = 0 and substr(P_AUTH_DT, 1, 14) < '".date('YmdHis', strtotime('-3 minutes', G5_SERVER_TIME))."' ";
$result = sql_query($sql, false);
@@ -195,7 +435,7 @@ function check_order_inicis_tmps(){
$oid = $row['oid'];
$p_tid = $row['P_TID'];
$p_mid = strtolower($tmps['P_MID']);
$p_mid = strtolower($row['P_MID']);
if( in_array($p_mid, array('iniescrow0', 'inipaytest')) ) continue;
@@ -235,4 +475,4 @@ function check_order_inicis_tmps(){
set_cookie('admin_visit_time', G5_SERVER_TIME, 3600); //1시간 간격으로 체크
}
} //end function check_order_inicis_tmps;
} //end function check_order_inicis_tmps;
+7 -7
View File
@@ -20,14 +20,14 @@ $bn_bimg = isset($_FILES['bn_bimg']['tmp_name']) ? $_FILES['bn_bimg']['tmp_
$bn_bimg_name = isset($_FILES['bn_bimg']['name']) ? $_FILES['bn_bimg']['name'] : '';
$bn_id = isset($_REQUEST['bn_id']) ? preg_replace('/[^0-9]/', '', $_REQUEST['bn_id']) : 0;
$bn_bimg_del = (isset($_POST['bn_bimg_del']) && $_POST['bn_bimg_del']) ? preg_replace('/[^0-9]/', '', $_POST['bn_id']) : 0;
$bn_url = isset($_POST['bn_url']) ? strip_tags(clean_xss_attributes($bn_url)) : '';
$bn_alt = isset($_POST['bn_alt']) ? strip_tags(clean_xss_attributes($bn_alt)) : '';
$bn_device = isset($_POST['bn_device']) ? clean_xss_tags($_POST['bn_device'], 1, 1) : '';
$bn_position = isset($_POST['bn_position']) ? clean_xss_tags($_POST['bn_position'], 1, 1) : '';
$bn_url = isset($_POST['bn_url']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bn_url'])))) : '';
$bn_alt = isset($_POST['bn_alt']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['bn_alt'])))) : '';
$bn_device = isset($_POST['bn_device']) ? safe_replace_regex($_POST['bn_device']) : '';
$bn_position = isset($_POST['bn_position']) ? addslashes(clean_xss_tags(stripslashes($_POST['bn_position']), 1, 1)) : '';
$bn_border = isset($_POST['bn_border']) ? (int) $_POST['bn_border'] : 0;
$bn_new_win = isset($_POST['bn_new_win']) ? (int) $_POST['bn_new_win'] : 0;
$bn_begin_time = isset($_POST['bn_begin_time']) ? clean_xss_tags($_POST['bn_begin_time'], 1, 1) : '';
$bn_end_time = isset($_POST['bn_end_time']) ? clean_xss_tags($_POST['bn_end_time'], 1, 1) : '';
$bn_begin_time = isset($_POST['bn_begin_time']) ? safe_replace_regex($_POST['bn_begin_time'], 'time') : '';
$bn_end_time = isset($_POST['bn_end_time']) ? safe_replace_regex($_POST['bn_end_time'], 'time') : '';
$bn_order = isset($_POST['bn_order']) ? (int) $_POST['bn_order'] : 0;
if ($bn_bimg_del) @unlink(G5_DATA_PATH."/banner/$bn_id");
@@ -99,4 +99,4 @@ if ($w == "" || $w == "u")
goto_url("./bannerform.php?w=u&amp;bn_id=$bn_id");
} else {
goto_url("./bannerlist.php");
}
}
+3 -3
View File
@@ -75,7 +75,7 @@ foreach( $check_str_keys as $key=>$val ){
if( $val === 'int' ){
$value = isset($_POST[$key]) ? (int) $_POST[$key] : 0;
} else {
$value = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
$value = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
}
$$key = $_POST[$key] = $value;
}
@@ -123,7 +123,7 @@ if ($w == "" || $w == "u")
$sql = " select mb_id from {$g5['member_table']} where mb_id = '$ca_mb_id' ";
$row = sql_fetch($sql);
if (!$row['mb_id'])
alert("\'$ca_mb_id\' 은(는) 존재하는 회원아이디가 아닙니다.");
alert("'$ca_mb_id' 은(는) 존재하는 회원아이디가 아닙니다.");
}
}
@@ -256,4 +256,4 @@ if ($w == "" || $w == "u")
goto_url("./categoryform.php?w=u&amp;ca_id=$ca_id&amp;$qstr");
} else {
goto_url("./categorylist.php?$qstr");
}
}
+3
View File
@@ -42,6 +42,9 @@ if (!$sst)
$sst = "ca_id";
$sod = "asc";
}
$allowed_sst = array('ca_id', 'ca_name', 'ca_mb_id', 'ca_use');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'ca_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = "order by $sst $sod";
// 출력할 레코드를 얻음
+4 -4
View File
@@ -19,7 +19,7 @@ for ($i=0; $i<$post_ca_id_count; $i++)
$sql = " select mb_id from {$g5['member_table']} where mb_id = '".sql_real_escape_string($str_ca_mb_id)."' ";
$row = sql_fetch($sql);
if (!$row['mb_id'])
alert("\'{$str_ca_mb_id}\' 은(는) 존재하는 회원아이디가 아닙니다.", "./categorylist.php?$qstr");
alert("'{$str_ca_mb_id}' 은(는) 존재하는 회원아이디가 아닙니다.", "./categorylist.php?$qstr");
}
$check_files = array();
@@ -51,7 +51,7 @@ for ($i=0; $i<$post_ca_id_count; $i++)
alert('스킨파일명에 포함될수 없는 문자가 들어있습니다.');
}
if( ! is_include_path_check($file) ){
if( ! is_include_path_check($file, 1) ){
alert('오류 : 데이터폴더가 포함된 path 또는 잘못된 path 를 포함할수 없습니다.');
}
@@ -62,7 +62,7 @@ for ($i=0; $i<$post_ca_id_count; $i++)
}
}
$p_ca_name = is_array($_POST['ca_name']) ? strip_tags(clean_xss_attributes($_POST['ca_name'][$i])) : '';
$p_ca_name = is_array($_POST['ca_name']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['ca_name'][$i])))) : '';
$posts = array();
@@ -94,4 +94,4 @@ for ($i=0; $i<$post_ca_id_count; $i++)
}
goto_url("./categorylist.php?$qstr");
goto_url("./categorylist.php?$qstr");
+184 -24
View File
@@ -207,6 +207,44 @@ if( ! isset($default['de_inicis_iniapi_key']) ){
sql_query($sql, false);
}
// KG이니시스 INIpay PRO 설정 추가
if (!isset($default['de_inicis_pro_use'])) {
$sql = "ALTER TABLE `{$g5['g5_shop_default_table']}`
ADD COLUMN `de_inicis_pro_use` TINYINT(4) NOT NULL DEFAULT '0' AFTER `de_inicis_sign_key`,
ADD COLUMN `de_inicis_hash_key` VARCHAR(255) NOT NULL DEFAULT '' AFTER `de_inicis_pro_use`; ";
sql_query($sql, false);
}
if (!isset($default['de_inicis_pro_alert_use'])) {
sql_query("ALTER TABLE `{$g5['g5_shop_default_table']}` ADD COLUMN `de_inicis_pro_alert_use` TINYINT(4) NOT NULL DEFAULT '1'", false);
$default['de_inicis_pro_alert_use'] = 1;
}
if (!isset($default['de_inicis_pro_reconcile_use'])) {
sql_query("ALTER TABLE `{$g5['g5_shop_default_table']}` ADD COLUMN `de_inicis_pro_reconcile_use` TINYINT(4) NOT NULL DEFAULT '0'", false);
$default['de_inicis_pro_reconcile_use'] = 0;
}
if (!isset($default['de_inicis_pro_log_days'])) {
sql_query("ALTER TABLE `{$g5['g5_shop_default_table']}` ADD COLUMN `de_inicis_pro_log_days` INT(11) NOT NULL DEFAULT '365'", false);
$default['de_inicis_pro_log_days'] = 365;
}
if (!isset($default['de_inicis_pro_summary_days'])) {
sql_query("ALTER TABLE `{$g5['g5_shop_default_table']}` ADD COLUMN `de_inicis_pro_summary_days` INT(11) NOT NULL DEFAULT '1825'", false);
$default['de_inicis_pro_summary_days'] = 1825;
}
if (!array_key_exists('de_inicis_pro_monitor_at', $default)) {
sql_query("ALTER TABLE `{$g5['g5_shop_default_table']}` ADD COLUMN `de_inicis_pro_monitor_at` DATETIME DEFAULT NULL", false);
$default['de_inicis_pro_monitor_at'] = '';
}
if (!isset($default['de_inicis_pro_monitor_message'])) {
sql_query("ALTER TABLE `{$g5['g5_shop_default_table']}` ADD COLUMN `de_inicis_pro_monitor_message` VARCHAR(255) NOT NULL DEFAULT ''", false);
$default['de_inicis_pro_monitor_message'] = '';
}
// KG이니시스 INIpay PRO 결제 감사 테이블이 없으면 생성한다.
include_once(G5_SHOP_PATH.'/inicis/pro/inicis_pro.lib.php');
if (function_exists('inicis_pro_audit_ensure_tables'))
inicis_pro_audit_ensure_tables();
// NICEPAY mid, key 추가
if (! isset($default['de_nicepay_mid'])) {
$sql = "ALTER TABLE `{$g5['g5_shop_default_table']}`
@@ -215,6 +253,14 @@ if (! isset($default['de_nicepay_mid'])) {
sql_query($sql, false);
}
// 토스페이먼츠 client, secret key 추가
if( ! isset($config['cf_toss_client_key']) ){
$sql = "ALTER TABLE `{$g5['config_table']}`
ADD COLUMN `cf_toss_client_key` VARCHAR(100) NOT NULL DEFAULT '' AFTER `cf_lg_mert_key`,
ADD COLUMN `cf_toss_secret_key` VARCHAR(100) NOT NULL DEFAULT '' AFTER `cf_toss_client_key`; ";
sql_query($sql, false);
}
if( function_exists('pg_setting_check') ){
pg_setting_check(true);
}
@@ -632,21 +678,27 @@ if(!$default['de_kakaopay_cancelpwd']){
<tr id="kcp_vbank_url" class="pg_vbank_url">
<th scope="row">NHN KCP 가상계좌<br>입금통보 URL</th>
<td>
<?php echo help("NHN KCP 가상계좌 사용시 다음 주소를 <strong><a href=\"http://admin.kcp.co.kr\" target=\"_blank\">NHN KCP 관리자</a> &gt; 상점정보관리 &gt; 정보변경 &gt; 공통URL 정보 &gt; 공통URL 변경후</strong>에 넣으셔야 상점에 자동으로 입금 통보됩니다."); ?>
<?php echo help("NHN KCP 가상계좌 사용시 다음 주소를 <strong><a href=\"https://partner.kcp.co.kr\" target=\"_blank\">NHN KCP 관리자</a> &gt; 상점정보관리 &gt; 정보변경 &gt; 공통URL 정보 &gt; 공통URL 변경후</strong>에 넣으셔야 상점에 자동으로 입금 통보됩니다."); ?>
<?php echo G5_SHOP_URL; ?>/settle_kcp_common.php</td>
</tr>
<tr id="inicis_vbank_url" class="pg_vbank_url">
<th scope="row">KG이니시스 가상계좌 입금통보 URL</th>
<th scope="row">KG이니시스 가상계좌<br>입금통보 URL</th>
<td>
<?php echo help("KG이니시스 가상계좌 사용시 다음 주소를 <strong><a href=\"https://iniweb.inicis.com/\" target=\"_blank\">KG이니시스 관리자</a> &gt; 거래내역 &gt; 가상계좌 &gt; 입금통보방식선택 &gt; URL 수신 설정</strong>에 넣으셔야 상점에 자동으로 입금 통보됩니다."); ?>
<?php echo G5_SHOP_URL; ?>/settle_inicis_common.php</td>
</tr>
<tr id="nicepay_vbank_url" class="pg_vbank_url">
<th scope="row">NICEPAY 가상계좌 입금통보 URL</th>
<th scope="row">NICEPAY 가상계좌<br>입금통보 URL</th>
<td>
<?php echo help("NICEPAY 가상계좌 사용시 다음 주소를 <strong><a href=\"https://npg.nicepay.co.kr/\" target=\"_blank\">NICEPAY 관리자</a> &gt; 가맹점관리자페이지 설정 (메인화면 → 가맹점정보 클릭)</strong>에 넣으셔야 상점에 자동으로 입금 통보됩니다."); ?>
<?php echo G5_SHOP_URL; ?>/settle_nicepay_common.php</td>
</tr>
<tr id="toss_vbank_url" class="pg_vbank_url">
<th scope="row">토스페이먼츠 가상계좌<br>입금통보 URL</th>
<td>
<?php echo help("토스페이먼츠 가상계좌 사용시 다음 주소를 <strong><a href=\"https://app.tosspayments.com/\" target=\"_blank\">토스페이먼츠 상점관리자</a> &gt; 개발자센터 &gt; 웹훅 &gt; 웹훅 등록하기에 URL</strong>에 넣으시고, <strong>구독할 이벤트를 [DEPOSIT_CALLBACK]</strong>을 선택하셔야 상점에 자동으로 입금 통보됩니다."); ?>
<?php echo G5_SHOP_URL; ?>/settle_toss_common.php</td>
</tr>
<tr>
<th scope="row"><label for="de_hp_use">휴대폰결제사용</label></th>
<td>
@@ -680,13 +732,14 @@ if(!$default['de_kakaopay_cancelpwd']){
<tr>
<th scope="row"><label for="de_easy_pay_use">PG사 간편결제 버튼 사용</label></th>
<td>
<?php echo help("주문서 작성 페이지에 PG사 간편결제(PAYCO, PAYNOW, KPAY) 버튼의 별도 사용 여부를 설정합니다.", 50); ?>
<?php echo help("주문서 작성 페이지에 PG사 간편결제(PAYCO, 토스, KPAY...) 버튼의 별도 사용 여부를 설정합니다.", 50); ?>
<select id="de_easy_pay_use" name="de_easy_pay_use">
<option value="0" <?php echo get_selected($default['de_easy_pay_use'], 0); ?>>노출안함</option>
<option value="1" <?php echo get_selected($default['de_easy_pay_use'], 1); ?>>노출함</option>
</select>
</td>
</tr>
<tr>
<th scope="row"><label for="de_taxsave_use">현금영수증<br>발급사용</label></th>
<td>
@@ -700,13 +753,13 @@ if(!$default['de_kakaopay_cancelpwd']){
<?php
$account_checked = $vbank_checked = $transfer_checked = '';
if (strstr($default['de_taxsave_types'], 'account')) {
if (strpos($default['de_taxsave_types'], 'account') !== false) {
$account_checked = 'checked="checked"';
}
if (strstr($default['de_taxsave_types'], 'vbank')) {
if (strpos($default['de_taxsave_types'], 'vbank') !== false) {
$vbank_checked = 'checked="checked"';
}
if (strstr($default['de_taxsave_types'], 'transfer')) {
if (strpos($default['de_taxsave_types'], 'transfer') !== false) {
$transfer_checked = 'checked="checked"';
}
?>
@@ -775,7 +828,8 @@ if(!$default['de_kakaopay_cancelpwd']){
<?php echo help('쇼핑몰에서 사용할 결제대행사를 선택합니다.'); ?>
<ul class="de_pg_tab">
<li class="<?php if($default['de_pg_service'] == 'kcp') echo 'tab-current'; ?>"><a href="#kcp_info_anchor" data-value="kcp" title="NHN KCP 선택하기" >NHN KCP</a></li>
<li class="<?php if($default['de_pg_service'] == 'lg') echo 'tab-current'; ?>"><a href="#lg_info_anchor" data-value="lg" title="토스페이먼츠 선택하기">토스페이먼츠</a></li>
<li class="<?php if($default['de_pg_service'] == 'lg') echo 'tab-current'; ?>"><a href="#lg_info_anchor" data-value="lg" title="토스페이먼츠(구버전) 선택하기">토스페이먼츠(구버전)</a></li>
<li class="<?php if($default['de_pg_service'] == 'toss') echo 'tab-current'; ?>"><a href="#lg_info_anchor" data-value="toss" title="토스페이먼츠 선택하기">토스페이먼츠</a></li>
<li class="<?php if($default['de_pg_service'] == 'inicis') echo 'tab-current'; ?>"><a href="#inicis_info_anchor" data-value="inicis" title="KG이니시스 선택하기">KG이니시스</a></li>
<li class="<?php if($default['de_pg_service'] == 'nicepay') echo 'tab-current'; ?>"><a href="#nicepay_info_anchor" data-value="nicepay" title="NICEPAY 선택하기">NICEPAY</a></li>
</ul>
@@ -833,12 +887,26 @@ if(!$default['de_kakaopay_cancelpwd']){
</td>
</tr>
<tr class="pg_info_fld lg_info_fld">
<th scope="row"><label for="cf_lg_mert_key">토스페이먼츠 MERT KEY</label></th>
<th scope="row"><label for="cf_lg_mert_key">토스페이먼츠(구버전) MERT KEY</label></th>
<td>
<?php echo help("토스페이먼츠 상점MertKey는 상점관리자 -> 계약정보 -> 상점정보관리에서 확인하실 수 있습니다.\n예) 95160cce09854ef44d2edb2bfb05f9f3\n<a href=\"".G5_ADMIN_URL."/config_form.php#anc_cf_cert\">기본환경설정 &gt; 본인확인</a> 설정의 토스페이먼츠 MERT KEY와 동일합니다."); ?>
<?php echo help("토스페이먼츠(구버전) 상점 MertKey는 상점관리자 -> 개발자센터 -> API키 -> 머트 키에서 확인하실 수 있습니다.\n예) 95160cce09854ef44d2edb2bfb05f9f3"); ?>
<input type="text" name="cf_lg_mert_key" value="<?php echo get_sanitize_input($config['cf_lg_mert_key']); ?>" id="cf_lg_mert_key" class="frm_input " size="36" maxlength="50">
</td>
</tr>
<tr class="pg_info_fld lg_info_fld_v2">
<th scope="row"><label for="cf_toss_client_key">토스페이먼츠 API Client Key</label></th>
<td>
<?php echo help("토스페이먼츠 API 클라이언트 키는 상점관리자 -> 개발자센터 -> API키 -> 클라이언트 키에서 확인하실 수 있습니다. 예) live_ck_tosspayment\n실결제용 [라이브] 키와 테스트용 [테스트] 키는 서로 다르므로, <b>테스트로 결제시에는 [테스트] 키</b>로 변경하여 사용해주시기 바랍니다. 예) 테스트 키: test_ck_tosspayment"); ?>
<input type="text" name="cf_toss_client_key" value="<?php echo get_sanitize_input($config['cf_toss_client_key']); ?>" id="cf_toss_client_key" class="frm_input " size="40" maxlength="50">
</td>
</tr>
<tr class="pg_info_fld lg_info_fld_v2">
<th scope="row"><label for="cf_toss_secret_key">토스페이먼츠 API Secret Key</label></th>
<td>
<?php echo help("토스페이먼츠 API 시크릿 키는 상점관리자 -> 개발자센터 -> API키 -> 시크릿 키에서 확인하실 수 있습니다. 예) live_sk_tosspayment\n실결제용 [라이브] 키와 테스트용 [테스트] 키는 서로 다르므로, <b>테스트로 결제시에는 [테스트] 키</b>로 변경하여 사용해주시기 바랍니다. 예) 테스트 키: test_sk_tosspayment"); ?>
<input type="text" name="cf_toss_secret_key" value="<?php echo get_sanitize_input($config['cf_toss_secret_key']); ?>" id="cf_toss_secret_key" class="frm_input " size="40" maxlength="50">
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld" id="inicis_info_anchor">
<th scope="row">
<label for="de_inicis_mid">KG이니시스 상점아이디</label><br>
@@ -849,34 +917,73 @@ if(!$default['de_kakaopay_cancelpwd']){
<span class="sitecode">SIR</span> <input type="text" name="de_inicis_mid" value="<?php echo $default['de_inicis_mid']; ?>" id="de_inicis_mid" class="frm_input code_input" size="10" maxlength="10"> 영문소문자(숫자포함 가능)
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_pro_use">KG이니시스 INIpay PRO</label></th>
<td>
<?php echo help("체크시 PC와 모바일에서 가장 최신 결제모듈인 KG이니시스 INIpay PRO 통합 결제창을 사용합니다. 실결제시 반드시 필수로 KG이니시스 모바일 금액위변조 Hash Key 를 입력해야 합니다."); ?>
<input type="checkbox" name="de_inicis_pro_use" value="1" id="de_inicis_pro_use"<?php echo !empty($default['de_inicis_pro_use']) ? ' checked' : ''; ?>> <label for="de_inicis_pro_use">사용</label>
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_sign_key">KG이니시스 웹결제 사인키</label></th>
<td>
<?php echo help("KG이니시스에서 발급받은 웹결제 사인키를 입력합니다.\n<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > 부가정보의 웹결제 signkey생성 조회 버튼 클릭, 팝업창에서 생성 버튼 클릭 후 해당 값을 입력합니다."); ?>
<?php echo help("KG이니시스에서 발급받은 웹결제 사인키를 입력합니다.\n<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > KEY 정보의 웹결제 signkey생성 조회 버튼 클릭, 팝업창에서 생성 버튼 클릭 후 해당 값을 입력합니다."); ?>
<input type="text" name="de_inicis_sign_key" value="<?php echo get_sanitize_input($default['de_inicis_sign_key']); ?>" id="de_inicis_sign_key" class="frm_input" size="40" maxlength="50">
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_hash_key">KG이니시스 모바일 금액위변조 Hash Key</label></th>
<td>
<?php echo help("<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > KEY 정보의 모바일 금액위변조 HashKey를 입력합니다."); ?>
<input type="text" name="de_inicis_hash_key" value="<?php echo isset($default['de_inicis_hash_key']) ? get_sanitize_input($default['de_inicis_hash_key']) : ''; ?>" id="de_inicis_hash_key" class="frm_input" size="40" maxlength="255" autocomplete="off">
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_iniapi_key">KG이니시스 INIAPI KEY</label></th>
<td>
<?php echo help("<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > 부가정보 > INIAPI key 생성 조회 하여 KEY를 여기에 입력합니다.\n이 항목은 영카트 주문에서 kg이니시스 PG 결제 취소, 부분취소, 에스크로 배송등록, 현금영수증 발급에 필요합니다."); ?>
<?php echo help("<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > KEY 정보 > INIAPI key 생성 조회 하여 KEY를 여기에 입력합니다.\n이 항목은 영카트 주문에서 kg이니시스 PG 결제 취소, 부분취소, 에스크로 배송등록, 현금영수증 발급에 필요합니다."); ?>
<input type="text" name="de_inicis_iniapi_key" value="<?php echo get_sanitize_input($default['de_inicis_iniapi_key']); ?>" id="de_inicis_iniapi_key" class="frm_input" size="30" maxlength="30">
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_iniapi_iv">KG이니시스 INIAPI IV</label></th>
<td>
<?php echo help("<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > 부가정보 > INIAPI IV 생성 조회 하여 KEY를 여기에 입력합니다.\n이 항목은 영카트 주문에서 kg이니시스 현금영수증 발급에 필요합니다."); ?>
<?php echo help("<a href='https://iniweb.inicis.com/' target='_blank'>KG이니시스 가맹점관리자</a> > 상점정보 > 계약정보 > KEY 정보 > INIAPI IV 생성 조회 하여 KEY를 여기에 입력합니다.\n이 항목은 영카트 주문에서 kg이니시스 현금영수증 발급에 필요합니다."); ?>
<input type="text" name="de_inicis_iniapi_iv" value="<?php echo get_sanitize_input($default['de_inicis_iniapi_iv']); ?>" id="de_inicis_iniapi_iv" class="frm_input" size="30" maxlength="30">
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row">KG이니시스 PRO 운영 감시</th>
<td>
<?php echo help("결제 이상 알림과 미진행 거래 정리는 서버 작업 스케줄러 없이 사이트 접속 흐름에서 자동 실행됩니다. KG이니시스 INIAPI 거래대사는 관리자 접속 시 함께 실행됩니다.\n관리자 접속이 드물거나 독립 실행이 필요하면 서버 작업 스케줄러에서 5~10분 간격으로 다음 명령을 추가로 실행할 수 있습니다(선택).\nphp ".G5_SHOP_PATH."/inicis/pro/monitor.php --host=".preg_replace('/[^A-Za-z0-9.:-]/', '', isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : 'localhost').((!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') ? ' --https' : '')." --client-ip=".preg_replace('/[^0-9.]/', '', isset($_SERVER['SERVER_ADDR']) ? $_SERVER['SERVER_ADDR'] : '')."\n거래대사는 최근 완료 거래와 확인 필요 거래를 KG이니시스 INIAPI로 조회하며 주문 생성이나 결제 취소를 자동 실행하지 않습니다."); ?>
<input type="checkbox" name="de_inicis_pro_alert_use" value="1" id="de_inicis_pro_alert_use"<?php echo !empty($default['de_inicis_pro_alert_use']) ? ' checked' : ''; ?>> <label for="de_inicis_pro_alert_use">이상 거래 메일 알림</label>
&nbsp;
<input type="checkbox" name="de_inicis_pro_reconcile_use" value="1" id="de_inicis_pro_reconcile_use"<?php echo !empty($default['de_inicis_pro_reconcile_use']) ? ' checked' : ''; ?>> <label for="de_inicis_pro_reconcile_use">최근 완료·확인 필요 거래 자동 대사</label>
<br>최근 감시: <?php echo !empty($default['de_inicis_pro_monitor_at']) ? get_text($default['de_inicis_pro_monitor_at']) : '실행 기록 없음'; ?>
<?php if (!empty($default['de_inicis_pro_monitor_message'])) { ?> / <?php echo get_text($default['de_inicis_pro_monitor_message']); ?><?php } ?>
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_pro_log_days">PRO 상세 이력 보존기간</label></th>
<td>
<?php echo help("단계별 상세 이력과 기존 이니시스 로그의 결제 응답 payload를 설정 기간 이후 순차 삭제합니다. 결제 요약은 아래의 별도 보존기간을 적용합니다. 0은 자동 정리 안 함이며, 보존하는 경우 30~3650일로 설정하십시오."); ?>
<input type="text" name="de_inicis_pro_log_days" value="<?php echo isset($default['de_inicis_pro_log_days']) ? (int) $default['de_inicis_pro_log_days'] : 365; ?>" id="de_inicis_pro_log_days" class="frm_input" size="6" maxlength="4"> 일
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row"><label for="de_inicis_pro_summary_days">PRO 결제 요약 보존기간</label></th>
<td>
<?php echo help("주문이 이미 삭제됐고 확인 또는 환불이 필요하지 않은 최종 결제 요약을 설정 기간 이후 순차 삭제합니다. 실제 주문이 남아 있거나 환불 확인이 필요한 거래는 삭제하지 않습니다. 0은 자동 정리 안 함이며, 보존하는 경우 365~3650일로 설정하십시오."); ?>
<input type="text" name="de_inicis_pro_summary_days" value="<?php echo isset($default['de_inicis_pro_summary_days']) ? (int) $default['de_inicis_pro_summary_days'] : 1825; ?>" id="de_inicis_pro_summary_days" class="frm_input" size="6" maxlength="4"> 일
</td>
</tr>
<tr class="pg_info_fld inicis_info_fld">
<th scope="row">
<label for="de_samsung_pay_use">KG이니시스 삼성페이 사용</label>
<a href="http://sir.kr/main/service/samsungpay.php" target="_blank" class="kg_btn">삼성페이 서비스신청하기</a>
</th>
<td>
<?php echo help("KG이니시스와 별도로 <strong>삼성페이 사용 계약을 하신 경우</strong>에만 체크해주세요. (모바일 주문서 결제수단에 삼성페이가 노출됩니다.) <br >실결제시 반드시 결제대행사 KG이니시스 항목에 상점 아이디와 웹결제 사인키를 입력해 주세요.", 50); ?>
<?php echo help("KG이니시스와 별도로 <strong>삼성페이 사용 계약을 하신 경우</strong>에만 체크해주세요. INIpay PRO 사용 시 PC와 모바일 주문서에 삼성페이가 노출되며 삼성페이 결제창을 직접 호출합니다. 구버전 결제에서는 모바일 주문서에만 노출됩니다.<br>실결제 시 상점 아이디와 사용 중인 결제모듈의 인증키(PRO: HashKey, 구버전: 웹결제 사인키)를 입력해 주세요.", 50); ?>
<input type="checkbox" name="de_samsung_pay_use" value="1" id="de_samsung_pay_use"<?php echo $default['de_samsung_pay_use']?' checked':''; ?>> <label for="de_samsung_pay_use">사용</label>
</td>
</tr>
@@ -885,7 +992,7 @@ if(!$default['de_kakaopay_cancelpwd']){
<label for="de_inicis_lpay_use">KG이니시스 L.pay 사용</label>
</th>
<td>
<?php echo help("체크시 KG이니시스 L.pay를 사용합니다. <br >실결제시 반드시 결제대행사 KG이니시스 항목의 상점 정보( 아이디, 웹결제 사인키 )를 입력해 주세요.", 50); ?>
<?php echo help("체크 시 KG이니시스 L.pay를 사용합니다. INIpay PRO에서는 주문서에서 L.pay 선택 시 L.pay 결제창을 직접 호출합니다.<br>실결제 시 상점 아이디와 사용 중인 결제모듈의 인증키(PRO: HashKey, 구버전: 웹결제 사인키)를 입력해 주세요.", 50); ?>
<input type="checkbox" name="de_inicis_lpay_use" value="1" id="de_inicis_lpay_use"<?php echo $default['de_inicis_lpay_use']?' checked':''; ?>> <label for="de_inicis_lpay_use">사용</label>
</td>
</tr>
@@ -894,7 +1001,7 @@ if(!$default['de_kakaopay_cancelpwd']){
<label for="de_inicis_kakaopay_use">KG이니시스 카카오페이 사용</label>
</th>
<td>
<?php echo help("체크시 KG이니시스 결제의 카카오페이를 사용합니다. 주문서 결제수단에 카카오페이가 노출됩니다. <br>실결제시 반드시 결제대행사 KG이니시스 항목의 상점 정보( 아이디, 웹결제 사인키 )를 입력해 주세요.", 50); ?>
<?php echo help("체크 시 KG이니시스 결제의 카카오페이를 사용합니다. INIpay PRO에서는 주문서에서 카카오페이 선택 시 카카오페이 결제창을 직접 호출합니다.<br>실결제 시 상점 아이디와 사용 중인 결제모듈의 인증키(PRO: HashKey, 구버전: 웹결제 사인키)를 입력해 주세요.", 50); ?>
<input type="checkbox" name="de_inicis_kakaopay_use" value="1" id="de_inicis_kakaopay_use"<?php echo $default['de_inicis_kakaopay_use']?' checked':''; ?>> <label for="de_inicis_kakaopay_use">사용</label>
</td>
</tr>
@@ -903,7 +1010,7 @@ if(!$default['de_kakaopay_cancelpwd']){
<label for="de_inicis_cartpoint_use">KG이니시스 신용카드 포인트 결제</label>
</th>
<td>
<?php echo help("신용카드 포인트 결제에 대해 이니시스와 계약을 맺은 상점에서만 적용하는 옵션입니다.<br>체크시 pc 결제에서는 신용카드 포인트 사용 여부에 대한 팝업창에 사용 버튼과 사용안함 버튼이 표기되어 결제하는 고객의 선택여부에 따라 신용카드 포인트 결제가 가능합니다.<br >모바일에서는 신용카드 포인트 사용이 가능합니다.", 50); ?>
<?php echo help("신용카드 포인트 결제에 대해 이니시스와 계약을 맺은 상점에서만 적용하는 구버전 결제 옵션입니다.<br>체크 시 PC 결제에서는 신용카드 포인트 사용 여부를 선택할 수 있고 모바일에서도 카드 포인트를 사용할 수 있습니다.<br>INIpay PRO에는 이 설정을 전달하지 않습니다. PRO 카드 포인트 사용은 KG이니시스에서 해당 MID의 지원 여부와 요청 규격을 확인한 후 적용해야 합니다.", 50); ?>
<input type="checkbox" name="de_inicis_cartpoint_use" value="1" id="de_inicis_cartpoint_use"<?php echo $default['de_inicis_cartpoint_use']?' checked':''; ?>> <label for="de_inicis_cartpoint_use">사용</label>
</td>
</tr>
@@ -949,7 +1056,7 @@ if(!$default['de_kakaopay_cancelpwd']){
</tr>
<tr class="pg_info_fld nicepay_info_fld" id="nicepay_info_anchor">
<th scope="row"><label for="de_nicepay_mid">NICEPAY MID</label><br><a href="http://sir.kr/main/service/inicis_pg.php" target="_blank" id="scf_nicepay_reg" class="nicepay_btn">NICEPAY 신청하기</a></th>
<th scope="row"><label for="de_nicepay_mid">NICEPAY MID</label><br><a href="http://sir.kr/main/service/nicepayments_pg.php" target="_blank" id="scf_nicepay_reg" class="nicepay_btn">NICEPAY 신청하기</a></th>
<td>
<span class="frm_info">NICEPAY로 부터 발급 받으신 상점MID를 SR 을 제외한 나머지 자리를 입력 합니다.<br>NICEPAY 상점관리자 > 가맹점정보 > KEY관리에서 확인 할수 있습니다.<br>만약, 상점아이디가 SR로 시작하지 않는다면 계약담당자에게 변경 요청을 해주시기 바랍니다. 예) SRpaytestm</span>
<span class="sitecode">SR</span>
@@ -1067,8 +1174,10 @@ if(!$default['de_kakaopay_cancelpwd']){
<a href="http://testadmin8.kcp.co.kr/" target="_blank" class="btn_frmline">테스트 관리자</a>
</div>
<div class="scf_cardtest lg_cardtest">
<a href="https://app.tosspayments.com/" target="_blank" class="btn_frmline">실결제 관리자</a>
<a href="https://pgweb.tosspayments.com/tmert" target="_blank" class="btn_frmline">테스트 관리자</a>
<a href="https://app.tosspayments.com/" target="_blank" class="btn_frmline">상점 관리자</a>
</div>
<div class="scf_cardtest toss_cardtest">
<a href="https://app.tosspayments.com/" target="_blank" class="btn_frmline">상점 관리자</a>
</div>
<div class="scf_cardtest inicis_cardtest">
<a href="https://iniweb.inicis.com/" target="_blank" class="btn_frmline">상점 관리자</a>
@@ -1089,11 +1198,14 @@ if(!$default['de_kakaopay_cancelpwd']){
<dt>휴대폰</dt><dd>테스트 지원되지 않음.</dd>
</dl>
<ul id="kcp_cardtest_tip" class="scf_cardtest_tip_adm scf_cardtest_tip_adm_hide">
<li>테스트결제의 <a href="http://testadmin8.kcp.co.kr/assist/login.LoginAction.do" target="_blank">상점관리자</a> 로그인 정보는 NHN KCP로 문의하시기 바랍니다. (기술지원 1544-8661)</li>
<li>테스트결제의 <a href="https://testpartner.kcp.co.kr/" target="_blank">상점관리자</a> 로그인 정보는 NHN KCP로 문의하시기 바랍니다. (기술지원 1544-8661)</li>
<li><b>일반결제</b>의 테스트 사이트코드는 <b>T0000</b> 이며, <b>에스크로 결제</b>의 테스트 사이트코드는 <b>T0007</b> 입니다.</li>
</ul>
<ul id="lg_cardtest_tip" class="scf_cardtest_tip_adm scf_cardtest_tip_adm_hide">
<li>테스트결제의 <a href="https://pgweb.tosspayments.com/tmert" target="_blank">상점관리자</a> 로그인 정보는 토스페이먼츠 상점아이디 첫 글자에 t를 추가해서 로그인하시기 바랍니다. 예) tsi_lguplus</li>
<li>테스트 결제건에 대한 <a href="https://app.tosspayments.com/" target="_blank">상점관리자</a> 접근은, 상점관리자 상단 '테스트 모드'를 활성화 하여서 접근할 수 있습니다.</li>
</ul>
<ul id="toss_cardtest_tip" class="scf_cardtest_tip_adm scf_cardtest_tip_adm_hide">
<li>테스트 결제건에 대한 <a href="https://app.tosspayments.com/" target="_blank">상점관리자</a> 접근은, 상점관리자 상단 '테스트 모드'를 활성화 하여서 접근할 수 있습니다.</li>
</ul>
<ul id="inicis_cardtest_tip" class="scf_cardtest_tip_adm scf_cardtest_tip_adm_hide">
<li><b>일반결제</b>의 테스트 사이트 mid는 <b>INIpayTest</b> 이며, <b>에스크로 결제</b>의 테스트 사이트 mid는 <b>iniescrow0</b> 입니다.</li>
@@ -1754,6 +1866,26 @@ function byte_check(el_cont, el_byte)
</form>
<script>
function inicis_pro_retention_check(id, min, label)
{
var el = document.getElementById(id);
if (!el) return true;
var raw = el.value.replace(/^\s+|\s+$/g, "");
if (raw === "") return true;
if (!/^[0-9]+$/.test(raw)) {
alert("INIpay PRO " + label + " 보존기간은 숫자로 입력해 주십시오.");
el.focus();
return false;
}
var days = parseInt(raw, 10);
if (days !== 0 && (days < min || days > 3650)) {
alert("INIpay PRO " + label + " 보존기간은 0 또는 " + min + "~3650일로 설정해 주십시오.");
el.focus();
return false;
}
return true;
}
function fconfig_check(f)
{
<?php echo get_editor_js('de_baesong_content'); ?>
@@ -1763,13 +1895,40 @@ function fconfig_check(f)
var msg = "",
pg_msg = "";
if (!inicis_pro_retention_check("de_inicis_pro_log_days", 30, "상세 이력")) return false;
if (!inicis_pro_retention_check("de_inicis_pro_summary_days", 365, "결제 요약")) return false;
if (f.de_pg_service.value == "inicis") {
var pro_use_el = document.getElementById("de_inicis_pro_use");
var inicis_test = parseInt(f.de_card_test.value, 10) > 0;
if (pro_use_el && pro_use_el.checked && !inicis_test) {
var hash_el = document.getElementById("de_inicis_hash_key");
if (hash_el && hash_el.value.replace(/[^A-Za-z0-9+\/=_-]/g, "") === "") {
alert("INIpay PRO를 사용하려면 HashKey를 입력해 주십시오.");
hash_el.focus();
return false;
}
var reconcile_el = document.getElementById("de_inicis_pro_reconcile_use");
var iniapi_el = document.getElementById("de_inicis_iniapi_key");
if (reconcile_el && reconcile_el.checked && iniapi_el && iniapi_el.value.replace(/^\s+|\s+$/g, "") === "") {
alert("INIpay PRO 자동 거래대사를 사용하려면 INIAPI KEY를 입력해 주십시오.");
iniapi_el.focus();
return false;
}
}
}
if( f.de_pg_service.value == "kcp" ){
if( f.de_kcp_mid.value && f.de_kcp_site_key.value && parseInt(f.de_card_test.value) > 0 ){
pg_msg = "NHN KCP";
}
} else if ( f.de_pg_service.value == "lg" ) {
if( f.cf_lg_mid.value && f.cf_lg_mert_key.value && parseInt(f.de_card_test.value) > 0 ){
pg_msg = "토스페이먼츠";
pg_msg = "토스페이먼츠(구버전)";
}
} else if ( f.de_pg_service.value == "toss" ) {
if( f.cf_lg_mid.value && f.cf_toss_client_key.value && f.cf_toss_secret_key.value && parseInt(f.de_card_test.value) > 0 ){
msg += "(주의!) 토스페이먼츠 결제의 결제 설정이 현재 테스트결제로 되어 있습니다.\n상점 API키를 [테스트]키로 설정한 후 테스트결제를 진행해주세요.\n쇼핑몰 운영중이면 반드시 실결제 전환 및 [라이브]키로 설정하여 운영하셔야 합니다.\n실결제로 변경하려면 결제설정 탭 -> 결제 테스트에서 실결제를 선택해 주세요.\n정말로 테스트결제로 설정하시겠습니까?";
}
} else if ( f.de_pg_service.value == "inicis" ) {
if( f.de_inicis_mid.value && f.de_inicis_sign_key.value && parseInt(f.de_card_test.value) > 0 ){
@@ -2102,4 +2261,5 @@ if($default['de_iche_use'] || $default['de_vbank_use'] || $default['de_hp_use']
}
}
include_once (G5_ADMIN_PATH.'/admin.tail.php');
include_once (G5_ADMIN_PATH.'/admin.tail.php');
+45 -4
View File
@@ -64,6 +64,8 @@ foreach($check_skin_keys as $key){
if( isset($_POST[$key]) && preg_match('#\.+(\/|\\\)#', $_POST[$key]) ){
alert('스킨설정에 유효하지 문자가 포함되어 있습니다.');
}
$$key = $_POST[$key] = sql_real_escape_string($_POST[$key]);
}
// 현금영수증 발급수단
@@ -159,10 +161,18 @@ $check_sanitize_keys = array(
'de_kcp_site_key', //NHN KCP SITE KEY
'cf_lg_mid', //LG유플러스 상점아이디
'cf_lg_mert_key', //LG유플러스 MERT KEY
'cf_toss_client_key', //토스페이먼츠 MERT KEY
'cf_toss_secret_key', //토스페이먼츠 MERT KEY
'de_inicis_mid', //KG이니시스 상점아이디
'de_inicis_iniapi_key', //KG이니시스 INIAPI KEY
'de_inicis_iniapi_iv', //KG이니시스 INIAPI IV
'de_inicis_sign_key', //KG이니시스 웹결제 사인키
'de_inicis_pro_use', //KG이니시스 INIpay PRO 사용
'de_inicis_hash_key', //KG이니시스 INIpay PRO HashKey
'de_inicis_pro_alert_use', //KG이니시스 INIpay PRO 이상 거래 알림
'de_inicis_pro_reconcile_use', //KG이니시스 INIpay PRO 자동 거래대사
'de_inicis_pro_log_days', //KG이니시스 INIpay PRO 상세 이력 보존기간
'de_inicis_pro_summary_days', //KG이니시스 INIpay PRO 결제 요약 보존기간
'de_samsung_pay_use', //KG이니시스 삼성페이 사용
'de_inicis_lpay_use', //KG이니시스 Lpay 사용
'de_inicis_kakaopay_use', //KG이니시스 카카오페이 사용
@@ -243,12 +253,35 @@ $check_sanitize_keys = array(
foreach( $check_sanitize_keys as $key ){
if( in_array($key, array('de_bank_account')) ){
$$key = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1, 0, 0) : '';
$$key = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1, 0, 0)) : '';
} else {
$$key = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
$$key = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
}
}
$de_inicis_pro_use = !empty($de_inicis_pro_use) ? 1 : 0;
$de_inicis_hash_key = preg_replace('/[^A-Za-z0-9+\/=_-]/', '', $de_inicis_hash_key);
$de_inicis_pro_alert_use = !empty($de_inicis_pro_alert_use) ? 1 : 0;
$de_inicis_pro_reconcile_use = !empty($de_inicis_pro_reconcile_use) ? 1 : 0;
$de_inicis_pro_log_days = (int) $de_inicis_pro_log_days;
if ($de_inicis_pro_log_days !== 0 && ($de_inicis_pro_log_days < 30 || $de_inicis_pro_log_days > 3650))
alert('INIpay PRO 상세 이력 보존기간은 0 또는 30~3650일로 설정해 주십시오.');
$de_inicis_pro_summary_days = (int) $de_inicis_pro_summary_days;
if ($de_inicis_pro_summary_days !== 0 && ($de_inicis_pro_summary_days < 365 || $de_inicis_pro_summary_days > 3650))
alert('INIpay PRO 결제 요약 보존기간은 0 또는 365~3650일로 설정해 주십시오.');
if ($de_pg_service === 'inicis' && $de_inicis_pro_use) {
if (empty($de_card_test) && $de_inicis_hash_key === '')
alert('INIpay PRO를 사용하려면 HashKey를 입력해 주십시오.');
if (!function_exists('curl_init'))
alert('INIpay PRO를 사용하려면 PHP cURL 모듈이 필요합니다.');
if (!function_exists('hash') || !in_array('sha512', hash_algos()))
alert('INIpay PRO를 사용하려면 SHA-512 해시 지원이 필요합니다.');
if ($de_inicis_pro_reconcile_use && empty($de_card_test) && trim($de_inicis_iniapi_key) === '')
alert('INIpay PRO 자동 거래대사를 사용하려면 INIAPI KEY를 입력해 주십시오.');
}
$warning_msg = '';
// kcp 전자결제를 사용할 때 site key 입력체크
@@ -407,6 +440,12 @@ $sql = " update {$g5['g5_shop_default_table']}
de_inicis_iniapi_key = '{$de_inicis_iniapi_key}',
de_inicis_iniapi_iv = '{$de_inicis_iniapi_iv}',
de_inicis_sign_key = '{$de_inicis_sign_key}',
de_inicis_pro_use = '{$de_inicis_pro_use}',
de_inicis_hash_key = '{$de_inicis_hash_key}',
de_inicis_pro_alert_use = '{$de_inicis_pro_alert_use}',
de_inicis_pro_reconcile_use = '{$de_inicis_pro_reconcile_use}',
de_inicis_pro_log_days = '{$de_inicis_pro_log_days}',
de_inicis_pro_summary_days = '{$de_inicis_pro_summary_days}',
de_iche_use = '{$de_iche_use}',
de_sms_cont1 = '{$_POST['de_sms_cont1']}',
de_sms_cont2 = '{$_POST['de_sms_cont2']}',
@@ -465,7 +504,9 @@ $sql = " update {$g5['config_table']}
cf_icode_server_port = '{$_POST['cf_icode_server_port']}',
cf_icode_token_key = '{$cf_icode_token_key}',
cf_lg_mid = '{$cf_lg_mid}',
cf_lg_mert_key = '{$cf_lg_mert_key}' ";
cf_lg_mert_key = '{$cf_lg_mert_key}',
cf_toss_client_key = '{$cf_toss_client_key}',
cf_toss_secret_key = '{$cf_toss_secret_key}' ";
sql_query($sql);
run_event('shop_admin_configformupdate');
@@ -474,4 +515,4 @@ if( $warning_msg ){
alert($warning_msg, "./configform.php");
} else {
goto_url("./configform.php");
}
}
+9 -9
View File
@@ -4,7 +4,7 @@ include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "w");
$cp_id = isset($_REQUEST['cp_id']) ? clean_xss_tags($_REQUEST['cp_id'], 1, 1) : '';
$cp_id = isset($_REQUEST['cp_id']) ? safe_replace_regex($_REQUEST['cp_id'], 'cp_id') : '';
$cp = array(
'cp_method'=>'',
'cp_subject'=>'',
@@ -46,13 +46,13 @@ include_once(G5_PLUGIN_PATH.'/jquery-ui/datepicker.php');
?>
<form name="fcouponform" action="./couponformupdate.php" method="post" onsubmit="return form_check(this);">
<input type="hidden" name="w" value="<?php echo $w; ?>">
<input type="hidden" name="cp_id" value="<?php echo $cp_id; ?>">
<input type="hidden" name="sst" value="<?php echo $sst; ?>">
<input type="hidden" name="sod" value="<?php echo $sod; ?>">
<input type="hidden" name="sfl" value="<?php echo $sfl; ?>">
<input type="hidden" name="stx" value="<?php echo $stx; ?>">
<input type="hidden" name="page" value="<?php echo $page;?>">
<input type="hidden" name="w" value="<?php echo get_sanitize_input($w); ?>">
<input type="hidden" name="cp_id" value="<?php echo get_sanitize_input($cp_id); ?>">
<input type="hidden" name="sst" value="<?php echo get_sanitize_input($sst); ?>">
<input type="hidden" name="sod" value="<?php echo get_sanitize_input($sod); ?>">
<input type="hidden" name="sfl" value="<?php echo get_sanitize_input($sfl); ?>">
<input type="hidden" name="stx" value="<?php echo get_sanitize_input($stx); ?>">
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page);?>">
<div class="tbl_frm01 tbl_wrap">
<table>
@@ -292,4 +292,4 @@ function form_check(f)
</script>
<?php
include_once (G5_ADMIN_PATH.'/admin.tail.php');
include_once (G5_ADMIN_PATH.'/admin.tail.php');
+4 -2
View File
@@ -6,6 +6,8 @@ auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
$cp_id = isset($_REQUEST['cp_id']) ? safe_replace_regex($_REQUEST['cp_id'], 'cp_id') : '';
$_POST = array_map('trim', $_POST);
$check_sanitize_keys = array(
@@ -25,7 +27,7 @@ $check_sanitize_keys = array(
);
foreach( $check_sanitize_keys as $key ){
$$key = $_POST[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
$$key = $_POST[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
}
if(!$_POST['cp_subject'])
@@ -264,4 +266,4 @@ if ($w == '' && (isset($_POST['cp_sms_send']) || isset($_POST['cp_email_send']))
}
}
goto_url('./couponlist.php');
goto_url('./couponlist.php');
+5
View File
@@ -6,6 +6,8 @@ auth_check_menu($auth, $sub_menu, "r");
$sql_common = " from {$g5['g5_shop_coupon_table']} ";
if ($sfl && !in_array($sfl, array('mb_id', 'cp_subject', 'cp_id'))) $sfl = '';
$sql_search = " where (1) ";
if ($stx) {
$sql_search .= " and ( ";
@@ -24,6 +26,9 @@ if (!$sst) {
$sst = "cp_no";
$sod = "desc";
}
$allowed_sst = array('cp_no', 'cp_id', 'cp_subject', 'mb_id', 'cp_end', 'cp_start', 'cp_method');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'cp_no';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
+4 -2
View File
@@ -6,6 +6,8 @@ auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
$cz_id = isset($_REQUEST['cz_id']) ? (int) $_REQUEST['cz_id'] : 0;
@mkdir(G5_DATA_PATH."/coupon", G5_DIR_PERMISSION);
@chmod(G5_DATA_PATH."/coupon", G5_DIR_PERMISSION);
@@ -28,7 +30,7 @@ $check_sanitize_keys = array(
);
foreach( $check_sanitize_keys as $key ){
$$key = $_POST[$key] = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
$$key = $_POST[$key] = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
}
if(!$_POST['cz_subject'])
@@ -150,4 +152,4 @@ if($_FILES['cp_img']['tmp_name']) {
sql_query($sql);
}
goto_url('./couponzonelist.php?'.$qstr);
goto_url('./couponzonelist.php?'.$qstr);
+3
View File
@@ -15,6 +15,9 @@ if (!$sst) {
$sst = "cz_id";
$sod = "desc";
}
$allowed_sst = array('cz_id');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'cz_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
+425
View File
@@ -0,0 +1,425 @@
<?php
if (!defined('_GNUBOARD_')) exit;
if (!function_exists('inicis_admin_status_label')) {
function inicis_admin_status_label($status)
{
$labels = array(
'request_ready' => '결제창 요청 준비',
'request_expired' => '결제창 종료·미진행',
'authentication_received' => '인증결과 수신',
'authentication_failed' => '인증 실패',
'validation_failed' => '주문 검증 실패',
'approval_started' => '승인 요청 중',
'communication_failed' => '승인 통신 실패',
'approval_failed' => '승인 실패',
'approved' => '승인 성공',
'order_saving' => '주문 저장 중',
'order_saved' => '주문 저장 완료',
'notification_received' => '서버 통보 수신',
'notification_failed' => '서버 통보 검증 실패',
'notification_acknowledged' => '처리 완료 통보 확인',
'vbank_issued' => '가상계좌 발급',
'paid' => '입금 통보 처리 완료',
'paid_after_cancel' => '취소 후 입금·환불 필요',
'refund_required' => '환불 필요',
'refund_completed' => '환불 확인 완료',
'cancel_requested' => '취소 요청 중',
'canceled' => '취소 완료',
'cancel_failed' => '취소 확인 필요',
'partial_canceled' => '부분취소 완료',
'partial_cancel_failed' => '부분취소 확인 필요',
'inquiry_success' => 'KG 거래조회 완료',
'inquiry_failed' => 'KG 거래조회 실패',
'approval_reference_recovered' => '승인 TID 복구'
);
return isset($labels[$status]) ? $labels[$status] : $status;
}
}
if (!function_exists('inicis_admin_pay_type_label')) {
function inicis_admin_pay_type_label($pay_type, $easy_pay)
{
$easy_labels = array(
'SAMSUNGPAY' => '삼성페이',
'LPAY' => 'L.pay',
'KAKAOPAY' => '카카오페이',
'EASYPAY' => '간편결제'
);
$easy_pay = strtoupper((string) $easy_pay);
if (isset($easy_labels[$easy_pay]))
return $easy_labels[$easy_pay].' (CARD)';
$pay_labels = array('CARD' => '신용카드', 'BANK' => '계좌이체', 'VBANK' => '가상계좌', 'HPP' => '휴대폰');
$pay_type = strtoupper((string) $pay_type);
return isset($pay_labels[$pay_type]) ? $pay_labels[$pay_type] : $pay_type;
}
}
if (!function_exists('inicis_admin_stage_label')) {
function inicis_admin_stage_label($stage)
{
$labels = array(
'request' => '결제 요청',
'authentication' => '결제 인증',
'validation' => '주문 검증',
'approval' => '결제 승인',
'order' => '주문 저장',
'notification' => '서버 통보',
'cancel' => '결제 취소',
'reconcile' => 'KG 거래대사'
);
return isset($labels[$stage]) ? $labels[$stage] : $stage;
}
}
if (!function_exists('inicis_admin_pg_status_label')) {
function inicis_admin_pg_status_label($status)
{
$status = strtoupper((string) $status);
$labels = array(
'0' => '승인',
'1' => '취소',
'9' => '거래 없음',
'N' => '가상계좌 입금대기',
'Y' => '가상계좌 입금완료',
'C' => '가상계좌 입금 전 취소',
'APPROVAL' => '승인',
'CANCEL' => '전체취소',
'PART_CANCEL' => '부분취소',
'DEPOSIT_COMPLETED' => '가상계좌 입금완료',
'NON_DEPOSIT' => '가상계좌 입금대기',
'DEPOSIT_CANCELED' => '가상계좌 입금취소',
'WAITING_FOR_REFUND' => '가상계좌 환불대기',
'REFUND_COMPLETED' => '가상계좌 환불완료'
);
return isset($labels[$status]) ? $labels[$status] : $status;
}
}
if (!function_exists('inicis_admin_source_label')) {
function inicis_admin_source_label($source)
{
$labels = array(
'web' => 'PC 브라우저',
'mobile' => '모바일 브라우저',
'server' => '이니시스 통보',
'system' => '시스템',
'admin' => '관리자'
);
return isset($labels[$source]) ? $labels[$source] : $source;
}
}
if (!function_exists('inicis_admin_primary_status')) {
function inicis_admin_primary_status($row)
{
if (!empty($row['ip_refund_required']))
return 'refund_required';
if (!empty($row['ip_noti_status']) && $row['ip_noti_status'] === 'notification_failed')
return 'notification_failed';
if (!empty($row['ip_cancel_status']) && in_array($row['ip_cancel_status'], array('cancel_failed', 'partial_cancel_failed')))
return $row['ip_cancel_status'];
if (!empty($row['ip_cancel_status']) && $row['ip_cancel_status'] === 'cancel_requested')
return 'cancel_requested';
if (!empty($row['ip_noti_status']) && $row['ip_noti_status'] === 'notification_received')
return 'notification_received';
// 서버 통보가 이후 정상 확인·처리 상태로 넘어갔는데도 이전 통보 검증 실패가
// 원본 상태에 남아 있으면, 최신 통보 상태를 대표 상태로 사용한다.
if (isset($row['ip_status']) && $row['ip_status'] === 'notification_failed'
&& !empty($row['ip_noti_status']) && $row['ip_noti_status'] !== 'notification_failed')
return $row['ip_noti_status'];
return isset($row['ip_status']) ? $row['ip_status'] : '';
}
}
if (!function_exists('inicis_admin_has_order')) {
function inicis_admin_has_order($row)
{
if (isset($row['ip_order_type']) && $row['ip_order_type'] === 'personal')
return !empty($row['personal_oid']);
return !empty($row['order_oid']);
}
}
if (!function_exists('inicis_admin_order_tid')) {
function inicis_admin_order_tid($row)
{
if (isset($row['ip_order_type']) && $row['ip_order_type'] === 'personal')
return isset($row['personal_tid']) ? $row['personal_tid'] : '';
return isset($row['order_tid']) ? $row['order_tid'] : '';
}
}
if (!function_exists('inicis_admin_order_amount')) {
function inicis_admin_order_amount($row)
{
if (isset($row['ip_order_type']) && $row['ip_order_type'] === 'personal')
return isset($row['personal_amount']) ? (int) $row['personal_amount'] : 0;
return isset($row['order_amount']) ? (int) $row['order_amount'] : 0;
}
}
if (!function_exists('inicis_admin_is_anomaly')) {
function inicis_admin_is_anomaly($row)
{
if (!empty($row['ip_audit_error']))
return true;
$status = isset($row['ip_status']) ? $row['ip_status'] : '';
$noti_status = isset($row['ip_noti_status']) ? $row['ip_noti_status'] : '';
$cancel_status = isset($row['ip_cancel_status']) ? $row['ip_cancel_status'] : '';
if (!empty($row['ip_refund_required']) || in_array($status, array('paid_after_cancel', 'refund_required')))
return true;
if ($noti_status === 'notification_failed')
return true;
if (in_array($cancel_status, array('cancel_failed', 'partial_cancel_failed')))
return true;
if ($status === 'partial_cancel_failed')
return true;
$has_order = inicis_admin_has_order($row);
$saved_tid = $has_order ? inicis_admin_order_tid($row) : '';
$amount_mismatch = $has_order && (int) $row['ip_amount'] > 0
&& inicis_admin_order_amount($row) !== (int) $row['ip_amount'];
$tid_mismatch = $has_order && !empty($row['ip_tid']) && $saved_tid !== $row['ip_tid'];
$mismatch = $amount_mismatch || $tid_mismatch;
$is_personal = isset($row['ip_order_type']) && $row['ip_order_type'] === 'personal';
$order_canceled = $has_order && !$is_personal
&& isset($row['order_status']) && $row['order_status'] === '취소';
$order_receipt = $is_personal
? (isset($row['personal_receipt_price']) ? (int) $row['personal_receipt_price'] : 0)
: (isset($row['order_receipt_price']) ? (int) $row['order_receipt_price'] : 0);
$order_misu = !$is_personal && isset($row['order_misu']) ? (int) $row['order_misu'] : 0;
$vbank_paid = isset($row['ip_pay_type']) && $row['ip_pay_type'] === 'VBANK'
&& ($status === 'paid' || in_array($noti_status, array('paid', 'paid_after_cancel')));
if ($status !== 'refund_completed' && $vbank_paid
&& ($order_canceled || !$has_order || $order_receipt !== (int) $row['ip_amount'] || $order_misu !== 0))
return true;
if (isset($row['ip_pay_type']) && $row['ip_pay_type'] === 'VBANK'
&& ($status === 'vbank_issued' || $noti_status === 'vbank_issued') && $order_canceled
&& $status !== 'canceled' && $cancel_status !== 'canceled')
return true;
$local_order_active = false;
if ($has_order) {
if (isset($row['ip_order_type']) && $row['ip_order_type'] === 'personal')
$local_order_active = isset($row['personal_receipt_price']) && (int) $row['personal_receipt_price'] > 0;
else
$local_order_active = isset($row['order_status']) && $row['order_status'] !== '취소';
}
$pg_status = !empty($row['ip_pg_result_code']) && $row['ip_pg_result_code'] === '00'
? strtoupper((string) $row['ip_pg_status']) : '';
$pg_mismatch = $pg_status !== ''
&& ((!empty($row['ip_pg_tid']) && !empty($row['ip_tid']) && $row['ip_pg_tid'] !== $row['ip_tid'])
|| ((int) $row['ip_pg_amount'] > 0 && (int) $row['ip_amount'] > 0 && (int) $row['ip_pg_amount'] !== (int) $row['ip_amount']));
$pg_paid = in_array($pg_status, array('0', 'Y', 'APPROVAL', 'PART_CANCEL', 'DEPOSIT_COMPLETED'));
$pg_pending = in_array($pg_status, array('N', 'NON_DEPOSIT'));
$pg_attention = $pg_status === 'WAITING_FOR_REFUND';
$pg_canceled = in_array($pg_status, array('1', '9', 'C', 'CANCEL', 'DEPOSIT_CANCELED', 'REFUND_COMPLETED'));
if ($pg_attention)
return true;
// 부분취소 합계로 전액 환불된 주문이 취소 상태이면 PG의 부분취소 표시와 일치하는 종결 상태로 본다.
$part_cancel_settled = $pg_status === 'PART_CANCEL' && !$local_order_active && !$is_personal
&& isset($row['order_refund_price'], $row['order_receipt_price'])
&& (int) $row['order_receipt_price'] > 0
&& (int) $row['order_refund_price'] >= (int) $row['order_receipt_price'];
if ($pg_paid)
return $pg_mismatch || (!$part_cancel_settled && (!$local_order_active || $mismatch));
$updated = isset($row['ip_updated_at']) ? strtotime($row['ip_updated_at']) : false;
if ($pg_pending)
return $pg_mismatch || $status === 'canceled' || $status === 'cancel_failed' || $mismatch
|| (!$has_order && $updated !== false && $updated < G5_SERVER_TIME - 180);
if ($pg_canceled)
return $pg_mismatch || $local_order_active;
if (in_array($status, array('authentication_received', 'approval_started', 'cancel_requested'))
|| $noti_status === 'notification_received' || $cancel_status === 'cancel_requested')
return $updated !== false && $updated < G5_SERVER_TIME - 180;
if ($status === 'communication_failed')
return true;
if ($status === 'validation_failed' && !empty($row['ip_tid']))
return true;
if ($status === 'cancel_failed' || $cancel_status === 'cancel_failed')
return true;
if ($status === 'canceled') {
return $local_order_active;
}
if ($status === 'notification_received')
return $updated !== false && $updated < G5_SERVER_TIME - 180;
if ($has_order)
return $mismatch;
$approved_states = array('approved', 'order_saving', 'order_saved', 'notification_received', 'vbank_issued', 'paid');
if (!in_array($status, $approved_states))
return false;
return $updated !== false && $updated < G5_SERVER_TIME - 180;
}
}
if (!function_exists('inicis_admin_anomaly_sql')) {
function inicis_admin_anomaly_sql()
{
$order_amount = "(o.od_cart_price + o.od_send_cost + o.od_send_cost2 - o.od_cart_coupon - o.od_coupon - o.od_send_coupon - o.od_receipt_point)";
$has_order = "((p.ip_order_type = 'personal' and pp.pp_id is not null) or (p.ip_order_type <> 'personal' and o.od_id is not null))";
$saved_tid = "if(p.ip_order_type = 'personal', ifnull(pp.pp_tno, ''), ifnull(o.od_tno, ''))";
$saved_amount = "if(p.ip_order_type = 'personal', ifnull(pp.pp_price, 0), ifnull($order_amount, 0))";
$mismatch = "($has_order and ((p.ip_tid <> '' and p.ip_tid <> $saved_tid) or (p.ip_amount > 0 and p.ip_amount <> $saved_amount)))";
$local_active = "((p.ip_order_type = 'personal' and pp.pp_id is not null and pp.pp_receipt_price > 0) or (p.ip_order_type <> 'personal' and o.od_id is not null and o.od_status <> '취소'))";
$local_canceled = "(p.ip_order_type <> 'personal' and o.od_id is not null and o.od_status = '취소')";
$vbank_paid_mismatch = "(p.ip_status <> 'refund_completed' and p.ip_pay_type = 'VBANK'
and (p.ip_status = 'paid' or p.ip_noti_status in ('paid','paid_after_cancel'))
and ((p.ip_order_type = 'personal' and (pp.pp_id is null or pp.pp_receipt_price <> p.ip_amount))
or (p.ip_order_type <> 'personal' and (o.od_id is null or o.od_status = '취소' or o.od_receipt_price <> p.ip_amount or o.od_misu <> 0))))";
$vbank_canceled_before_payment = "(p.ip_pay_type = 'VBANK' and (p.ip_status = 'vbank_issued' or p.ip_noti_status = 'vbank_issued')
and p.ip_status <> 'canceled' and p.ip_cancel_status <> 'canceled' and $local_canceled)";
$stale = "p.ip_updated_at < date_sub(now(), interval 3 minute)";
$pg_paid = "(p.ip_pg_result_code = '00' and p.ip_pg_status in ('0','Y','APPROVAL','PART_CANCEL','DEPOSIT_COMPLETED'))";
$pg_pending = "(p.ip_pg_result_code = '00' and p.ip_pg_status in ('N','NON_DEPOSIT'))";
$pg_attention = "(p.ip_pg_result_code = '00' and p.ip_pg_status = 'WAITING_FOR_REFUND')";
$pg_canceled = "(p.ip_pg_result_code = '00' and p.ip_pg_status in ('1','9','C','CANCEL','DEPOSIT_CANCELED','REFUND_COMPLETED'))";
$pg_known = "($pg_paid or $pg_pending or $pg_attention or $pg_canceled)";
$part_cancel_settled = "(p.ip_pg_result_code = '00' and p.ip_pg_status = 'PART_CANCEL'
and $local_canceled and o.od_receipt_price > 0 and o.od_refund_price >= o.od_receipt_price)";
$pg_mismatch = "(p.ip_pg_result_code = '00' and ((p.ip_pg_tid <> '' and p.ip_tid <> '' and p.ip_pg_tid <> p.ip_tid) or (p.ip_pg_amount > 0 and p.ip_amount > 0 and p.ip_pg_amount <> p.ip_amount)))";
$approved_states = "'approved','order_saving','order_saved','notification_received','vbank_issued','paid'";
$local_anomaly = "(p.ip_status = 'cancel_failed'
or p.ip_status = 'communication_failed'
or (p.ip_status = 'validation_failed' and p.ip_tid <> '')
or (p.ip_status in ('authentication_received','approval_started','cancel_requested') and $stale)
or (p.ip_noti_status = 'notification_received' and $stale)
or (p.ip_cancel_status = 'cancel_requested' and $stale)
or (p.ip_status = 'canceled' and $local_active)
or (p.ip_status = 'notification_received' and $stale)
or $mismatch
or (not $has_order and p.ip_status in ($approved_states) and $stale))";
return "(p.ip_audit_error = '1'
or p.ip_refund_required = '1'
or p.ip_status in ('paid_after_cancel','refund_required')
or p.ip_noti_status = 'notification_failed'
or p.ip_cancel_status in ('cancel_failed','partial_cancel_failed')
or p.ip_status = 'partial_cancel_failed'
or $vbank_paid_mismatch
or $vbank_canceled_before_payment
or $pg_mismatch
or $pg_attention
or ($pg_paid and not $part_cancel_settled and (not $local_active or $mismatch))
or ($pg_pending and (p.ip_status in ('canceled','cancel_failed') or $mismatch or (not $has_order and $stale)))
or ($pg_canceled and $local_active)
or (not $pg_known and $local_anomaly))";
}
}
if (!function_exists('inicis_admin_alert_key')) {
function inicis_admin_alert_key($row)
{
return md5(
(isset($row['ip_status']) ? $row['ip_status'] : '').'|'.
(isset($row['ip_tid']) ? $row['ip_tid'] : '').'|'.
(isset($row['ip_amount']) ? $row['ip_amount'] : '').'|'.
(isset($row['ip_pg_result_code']) ? $row['ip_pg_result_code'] : '').'|'.
(isset($row['ip_pg_status']) ? $row['ip_pg_status'] : '').'|'.
(isset($row['ip_pg_tid']) ? $row['ip_pg_tid'] : '').'|'.
(isset($row['ip_pg_amount']) ? $row['ip_pg_amount'] : '').'|'.
(isset($row['ip_noti_status']) ? $row['ip_noti_status'] : '').'|'.
(isset($row['ip_noti_code']) ? $row['ip_noti_code'] : '').'|'.
(isset($row['ip_cancel_status']) ? $row['ip_cancel_status'] : '').'|'.
(!empty($row['ip_refund_required']) ? '1' : '0').'|'.
(inicis_admin_has_order($row) ? '1' : '0').'|'.
inicis_admin_order_tid($row).'|'.inicis_admin_order_amount($row).'|'.
(isset($row['order_status']) ? $row['order_status'] : '').'|'.
(isset($row['order_receipt_price']) ? $row['order_receipt_price'] : '').'|'.
(isset($row['order_misu']) ? $row['order_misu'] : '').'|'.
(isset($row['personal_receipt_price']) ? $row['personal_receipt_price'] : '').'|'.
(!empty($row['ip_audit_error']) ? '1' : '0')
);
}
}
if (!function_exists('inicis_admin_recommendation')) {
function inicis_admin_recommendation($row)
{
if (!empty($row['ip_audit_error']))
return '감사 상세 이력 기록이 일부 누락됐습니다. 서버 오류 로그를 확인하고 KG이니시스 상점관리자 거래내역을 기준으로 상태를 확정하십시오.';
if (!empty($row['ip_refund_required']) || in_array($row['ip_status'], array('paid_after_cancel', 'refund_required')))
return '취소된 주문에 가상계좌 입금이 확인됐습니다. 상품을 발송하지 말고 KG이니시스 상점관리자에서 입금 TID를 확인한 뒤 고객 환불을 처리하고 KG 거래조회를 다시 실행하십시오.';
if (!empty($row['ip_noti_status']) && $row['ip_noti_status'] === 'notification_failed')
return '최근 KG 서버 통보를 검증하거나 저장하지 못했습니다. 통보 실패 코드와 서버 오류 로그를 확인하고 상점관리자에서 입금통보 결과를 재전송하십시오.';
if (!empty($row['ip_cancel_status']) && $row['ip_cancel_status'] === 'cancel_failed')
return 'PG 전체취소 결과를 확정하지 못했습니다. 영카트 주문상태를 변경하지 말고 KG이니시스 상점관리자의 원거래를 직접 확인하십시오.';
if (!empty($row['ip_cancel_status']) && $row['ip_cancel_status'] === 'partial_cancel_failed')
return '부분취소 결과를 확정하지 못했습니다. KG이니시스 상점관리자의 원거래와 부분취소 거래내역을 직접 대조하십시오.';
if (!empty($row['ip_noti_status']) && $row['ip_noti_status'] === 'notification_received')
return '가상계좌 입금 통보 수신 후 주문 반영 완료 기록이 없습니다. 주문 입금액과 미수금을 확인하고, 불일치하면 KG이니시스 상점관리자에서 입금 통보를 재전송하십시오.';
if (!empty($row['ip_cancel_status']) && $row['ip_cancel_status'] === 'cancel_requested')
return 'PG 취소 요청 후 결과가 확정되지 않았습니다. 영카트 주문을 추가로 변경하지 말고 KG이니시스 상점관리자에서 원거래 취소 여부를 먼저 확인하십시오.';
if (!empty($row['ip_pg_checked_at']) && $row['ip_pg_result_code'] !== '00')
return 'KG 거래조회가 실패했습니다. 해당 MID의 거래조회 계약, INIAPI KEY와 서버 IPv4를 확인한 후 다시 조회하거나 KG이니시스 상점관리자에서 직접 조회하십시오.';
$has_order = inicis_admin_has_order($row);
$pg_status = !empty($row['ip_pg_result_code']) && $row['ip_pg_result_code'] === '00' ? strtoupper((string) $row['ip_pg_status']) : '';
$pg_paid = in_array($pg_status, array('0', 'Y', 'APPROVAL', 'PART_CANCEL', 'DEPOSIT_COMPLETED'));
$pg_pending = in_array($pg_status, array('N', 'NON_DEPOSIT'));
$pg_attention = $pg_status === 'WAITING_FOR_REFUND';
$pg_canceled = in_array($pg_status, array('1', '9', 'C', 'CANCEL', 'DEPOSIT_CANCELED', 'REFUND_COMPLETED'));
if ($pg_status !== '' && ((!empty($row['ip_pg_tid']) && !empty($row['ip_tid']) && $row['ip_pg_tid'] !== $row['ip_tid'])
|| ((int) $row['ip_pg_amount'] > 0 && (int) $row['ip_amount'] > 0 && (int) $row['ip_pg_amount'] !== (int) $row['ip_amount'])))
return 'KG 거래조회 결과와 영카트 결제 이력의 TID 또는 금액이 다릅니다. 자동 조치하지 말고 KG이니시스 상점관리자 원거래 내역을 직접 확인하십시오.';
if ($pg_attention)
return '가상계좌 입금 후 환불 대기 상태입니다. 환불이 완료될 때까지 KG이니시스 상점관리자에서 상태를 계속 확인하십시오.';
if ($pg_paid && !$has_order)
return 'KG이니시스에는 승인 또는 입금이 있으나 영카트 주문이 없습니다. 원 주문 데이터와 재고·포인트 반영 여부를 확인한 뒤 안전한 복원이 불가능하면 상점관리자에서 승인 취소하십시오.';
if ($pg_pending && !$has_order)
return '가상계좌가 발급됐지만 영카트 주문이 없습니다. 고객 입금 전에 주문 복원 가능 여부를 확인하고, 복원이 불가능하면 해당 가상계좌 거래를 정리하십시오.';
$recommend_is_personal = isset($row['ip_order_type']) && $row['ip_order_type'] === 'personal';
$order_canceled_match = $has_order && ($recommend_is_personal
? !(isset($row['personal_receipt_price']) && (int) $row['personal_receipt_price'] > 0)
: (isset($row['order_status']) && $row['order_status'] === '취소'));
if ($pg_canceled && $order_canceled_match)
return 'KG이니시스 거래와 영카트 주문이 모두 취소 상태로 일치합니다. 별도 조치가 필요하지 않습니다.';
if ($pg_canceled && $has_order)
return 'KG이니시스 거래는 취소 또는 거래 없음 상태입니다. 영카트 주문의 결제금액·상태를 확인하고 PG 상태와 일치하도록 관리자 처리하십시오.';
if ($pg_status === 'PART_CANCEL' && $order_canceled_match && !$recommend_is_personal
&& isset($row['order_refund_price'], $row['order_receipt_price'])
&& (int) $row['order_receipt_price'] > 0
&& (int) $row['order_refund_price'] >= (int) $row['order_receipt_price'])
return 'KG이니시스 거래가 부분취소 합계로 전액 환불되었고 영카트 주문도 취소 상태입니다. 별도 조치가 필요하지 않습니다.';
if (isset($row['ip_status']) && in_array($row['ip_status'], array('authentication_received', 'approval_started', 'communication_failed')) && empty($row['ip_tid']))
return '최종 승인 TID가 영카트에 저장되기 전에 처리가 중단됐을 수 있습니다. 같은 주문을 다시 결제시키기 전에 KG이니시스 상점관리자에서 주문번호 OID로 승인 여부를 확인하십시오.';
if (isset($row['ip_status']) && $row['ip_status'] === 'validation_failed' && !empty($row['ip_tid']))
return '승인 TID가 생성된 뒤 주문 검증이 중단됐습니다. KG 거래조회 결과를 확인하고 주문이 없다면 승인 취소 여부를 결정하십시오.';
if ($has_order && ((!empty($row['ip_tid']) && inicis_admin_order_tid($row) !== $row['ip_tid'])
|| ((int) $row['ip_amount'] > 0 && inicis_admin_order_amount($row) !== (int) $row['ip_amount'])))
return '결제 이력과 주문 DB의 TID 또는 금액이 다릅니다. 주문 상태를 변경하기 전에 KG이니시스 원거래 TID와 승인금액을 직접 대조하십시오.';
if (isset($row['ip_status']) && $row['ip_status'] === 'cancel_failed')
return '자동 취소 결과를 확정하지 못했습니다. KG 거래조회를 다시 실행하고 승인 상태라면 상점관리자에서 취소 여부를 결정하십시오.';
if (isset($row['ip_status']) && $row['ip_status'] === 'partial_cancel_failed')
return '부분취소 결과를 확정하지 못했습니다. KG이니시스 상점관리자의 원거래와 부분취소 거래내역을 직접 대조하십시오.';
return inicis_admin_is_anomaly($row)
? 'KG이니시스 상점관리자에서 승인 TID와 금액을 확인한 뒤 영카트 주문 상태와 맞추십시오.'
: '현재 별도 조치가 필요하지 않습니다. KG 거래상태와 영카트 주문의 TID 및 금액이 일치합니다.';
}
}
+77
View File
@@ -0,0 +1,77 @@
<?php
$sub_menu = '400420';
include_once('./_common.php');
check_demo();
auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
include_once(G5_SHOP_PATH.'/inicis/pro/inicis_pro.lib.php');
include_once('./inicislog.lib.php');
if (!inicis_pro_audit_schema_ready())
alert('결제 현황 DB 업그레이드를 먼저 실행해 주십시오.', G5_ADMIN_URL.'/dbupgrade.php');
if (inicis_pro_get_iniapi_key() === '')
alert('KG이니시스 INIAPI KEY를 먼저 설정해 주십시오.', './configform.php');
$tables = inicis_pro_audit_tables();
$mode = isset($_POST['mode']) && !is_array($_POST['mode']) ? $_POST['mode'] : '';
$targets = array();
if ($mode === 'batch') {
$order_amount_sql = "(o.od_cart_price + o.od_send_cost + o.od_send_cost2 - o.od_cart_coupon - o.od_coupon - o.od_send_coupon - o.od_receipt_point)";
$anomaly_sql = inicis_admin_anomaly_sql();
$result = sql_query(" select p.*,
o.od_id as order_oid, o.od_tno as order_tid, o.od_status as order_status,
o.od_receipt_price as order_receipt_price, o.od_misu as order_misu, o.od_cancel_price as order_cancel_price,
o.od_settle_case as order_settle_case, $order_amount_sql as order_amount,
pp.pp_id as personal_oid, pp.pp_tno as personal_tid, pp.pp_price as personal_amount, pp.pp_receipt_price as personal_receipt_price
from `{$tables['summary']}` p
left join {$g5['g5_shop_order_table']} o on p.ip_order_type <> 'personal' and o.od_id = p.ip_oid
left join {$g5['g5_shop_personalpay_table']} pp on p.ip_order_type = 'personal' and pp.pp_id = p.ip_oid
left join {$g5['g5_shop_inicis_log_table']} il on il.oid = p.ip_oid
where (p.ip_tid <> '' or (il.P_TID <> '' and il.P_STATUS = '00'))
and $anomaly_sql
order by p.ip_updated_at asc
limit 5 ");
while ($row = sql_fetch_array($result))
$targets[] = $row;
} else {
$oid_raw = isset($_POST['oid']) && !is_array($_POST['oid']) ? trim($_POST['oid']) : '';
$oid = inicis_pro_clean_oid($oid_raw);
if ($oid === '' || $oid !== $oid_raw)
alert('결제 주문번호가 올바르지 않습니다.', './inicisloglist.php');
$row = sql_fetch(" select * from `{$tables['summary']}` where ip_oid = '".sql_escape_string($oid)."' ");
if (empty($row['ip_id']))
alert('결제 처리 이력을 찾을 수 없습니다.', './inicisloglist.php');
$targets[] = $row;
}
if (!count($targets))
alert('KG이니시스에서 조회할 확인 필요 거래가 없습니다.', './inicisloglist.php');
$success_count = 0;
$failed_count = 0;
$last_oid = '';
foreach ($targets as $target) {
$last_oid = $target['ip_oid'];
$target_tid = !empty($target['ip_tid']) ? $target['ip_tid'] : inicis_pro_recover_approved_tid($target['ip_oid'], 'admin');
if ($target_tid === '') {
if ($mode !== 'batch')
alert('승인 TID가 없어 KG이니시스 거래조회를 실행할 수 없습니다. 인증 전 미완료 결제이거나 승인 TID가 복구되지 않은 거래입니다.', './inicislogview.php?oid='.urlencode($target['ip_oid']));
$failed_count++;
continue;
}
$inquiry = inicis_pro_inquiry($target_tid, $target['ip_oid'], $target);
if (inicis_pro_save_inquiry($target['ip_oid'], $inquiry, 'admin') && !empty($inquiry['success']))
$success_count++;
else
$failed_count++;
}
$message = 'KG이니시스 거래조회가 완료되었습니다. 성공 '.$success_count.'건, 실패 '.$failed_count.'건';
if ($mode !== 'batch' && $last_oid !== '')
alert($message, './inicislogview.php?oid='.urlencode($last_oid));
alert($message, './inicisloglist.php?risk=anomaly');
+265
View File
@@ -0,0 +1,265 @@
<?php
$sub_menu = '400420';
include_once('./_common.php');
auth_check_menu($auth, $sub_menu, 'r');
include_once(G5_SHOP_PATH.'/inicis/pro/inicis_pro.lib.php');
include_once('./inicislog.lib.php');
$g5['title'] = 'KG이니시스 INIpay PRO 결제 처리 현황';
$tables = inicis_pro_audit_tables();
$tables_ready = inicis_pro_audit_tables_ready();
$schema_ready = inicis_pro_audit_schema_ready();
$status = isset($_GET['status']) && !is_array($_GET['status']) ? preg_replace('/[^a-z_]/', '', strtolower($_GET['status'])) : '';
$allowed_status = array('', 'request_ready', 'request_expired', 'authentication_received', 'authentication_failed', 'validation_failed', 'approval_started', 'communication_failed', 'approval_failed', 'approved', 'order_saving', 'order_saved', 'notification_received', 'notification_failed', 'vbank_issued', 'paid', 'paid_after_cancel', 'refund_required', 'refund_completed', 'cancel_requested', 'canceled', 'cancel_failed', 'partial_canceled', 'partial_cancel_failed');
if (!in_array($status, $allowed_status))
$status = '';
$risk = isset($_GET['risk']) && !is_array($_GET['risk']) ? preg_replace('/[^a-z_]/', '', strtolower($_GET['risk'])) : '';
if (!in_array($risk, array('', 'anomaly', 'failed', 'processing', 'complete', 'canceled', 'abandoned')))
$risk = '';
$sfl = isset($_GET['sfl']) && !is_array($_GET['sfl']) ? $_GET['sfl'] : 'ip_oid';
if (!in_array($sfl, array('ip_oid', 'ip_tid', 'ip_auth_tid', 'mb_id')))
$sfl = 'ip_oid';
$stx = isset($_GET['stx']) && !is_array($_GET['stx']) ? get_search_string($_GET['stx']) : '';
$fr_date = isset($_GET['fr_date']) && !is_array($_GET['fr_date']) && preg_match('/^[0-9]{4}-[0-9]{2}-[0-9]{2}$/', $_GET['fr_date']) ? $_GET['fr_date'] : '';
$to_date = isset($_GET['to_date']) && !is_array($_GET['to_date']) && preg_match('/^[0-9]{4}-[0-9]{2}-[0-9]{2}$/', $_GET['to_date']) ? $_GET['to_date'] : '';
include_once(G5_ADMIN_PATH.'/admin.head.php');
if (!$tables_ready) {
?>
<div class="local_desc02 local_desc">
<p>결제 현황 테이블이 아직 설치되지 않았습니다. 최고관리자로 <a href="<?php echo G5_ADMIN_URL; ?>/dbupgrade.php"><strong>DB 업그레이드</strong></a>를 실행한 후 이용해 주십시오.</p>
</div>
<?php
include_once(G5_ADMIN_PATH.'/admin.tail.php');
exit;
}
if (!$schema_ready) {
?>
<div class="local_desc02 local_desc">
<p>결제 현황 테이블의 운영 감시 필드가 설치되지 않았습니다. 최고관리자로 <a href="<?php echo G5_ADMIN_URL; ?>/dbupgrade.php"><strong>DB 업그레이드</strong></a>를 실행한 후 이용해 주십시오.</p>
</div>
<?php
include_once(G5_ADMIN_PATH.'/admin.tail.php');
exit;
}
include_once(G5_PLUGIN_PATH.'/jquery-ui/datepicker.php');
$order_amount_sql = "(o.od_cart_price + o.od_send_cost + o.od_send_cost2 - o.od_cart_coupon - o.od_coupon - o.od_send_coupon - o.od_receipt_point)";
$has_order_sql = "((p.ip_order_type = 'personal' and pp.pp_id is not null) or (p.ip_order_type <> 'personal' and o.od_id is not null))";
$anomaly_sql = inicis_admin_anomaly_sql();
$where = array();
if ($status === 'refund_required')
$where[] = "p.ip_refund_required = '1'";
elseif ($status !== '')
$where[] = "(p.ip_status = '".sql_escape_string($status)."' or p.ip_noti_status = '".sql_escape_string($status)."' or p.ip_cancel_status = '".sql_escape_string($status)."')";
if ($stx !== '')
$where[] = "p.$sfl like '%".sql_escape_string($stx)."%'";
if ($fr_date !== '')
$where[] = "p.ip_created_at >= '".sql_escape_string($fr_date)." 00:00:00'";
if ($to_date !== '')
$where[] = "p.ip_created_at <= '".sql_escape_string($to_date)." 23:59:59'";
if ($risk === 'anomaly')
$where[] = $anomaly_sql;
elseif ($risk === 'failed')
$where[] = "(p.ip_status in ('authentication_failed','validation_failed','communication_failed','approval_failed') or p.ip_noti_status = 'notification_failed' or p.ip_cancel_status in ('cancel_failed','partial_cancel_failed'))";
elseif ($risk === 'processing')
$where[] = "(p.ip_status in ('request_ready','authentication_received','approval_started','order_saving','cancel_requested') or p.ip_cancel_status = 'cancel_requested')";
elseif ($risk === 'complete')
$where[] = "$has_order_sql and p.ip_status in ('order_saved','paid','refund_completed') and not ($anomaly_sql)";
elseif ($risk === 'canceled')
$where[] = "(p.ip_status = 'canceled' or p.ip_cancel_status in ('canceled','partial_canceled'))";
elseif ($risk === 'abandoned')
$where[] = "p.ip_status = 'request_expired'";
$sql_from = " from `{$tables['summary']}` p
left join {$g5['g5_shop_order_table']} o on p.ip_order_type <> 'personal' and o.od_id = p.ip_oid
left join {$g5['g5_shop_personalpay_table']} pp on p.ip_order_type = 'personal' and pp.pp_id = p.ip_oid ";
$sql_where = count($where) ? ' where '.implode(' and ', $where) : '';
$count = sql_fetch(" select count(*) as cnt $sql_from $sql_where ");
$total_count = isset($count['cnt']) ? (int) $count['cnt'] : 0;
$all_count = sql_fetch(" select count(*) as cnt from `{$tables['summary']}` ");
$anomaly_count = sql_fetch(" select count(*) as cnt $sql_from where $anomaly_sql ");
$failed_count = sql_fetch(" select count(*) as cnt from `{$tables['summary']}` where ip_status in ('authentication_failed','validation_failed','communication_failed','approval_failed') or ip_noti_status = 'notification_failed' or ip_cancel_status in ('cancel_failed','partial_cancel_failed') ");
$audit_error_count = sql_fetch(" select count(*) as cnt from `{$tables['summary']}` where ip_audit_error = '1' ");
$rows = (int) $config['cf_page_rows'];
if ($rows < 1)
$rows = 20;
$total_page = ceil($total_count / $rows);
if ($page < 1)
$page = 1;
if ($total_page > 0 && $page > $total_page)
$page = (int) $total_page;
$from_record = ($page - 1) * $rows;
$sql = " select p.*,
o.od_id as order_oid, o.od_tno as order_tid, o.od_status as order_status, o.od_receipt_price as order_receipt_price,
o.od_misu as order_misu, o.od_cancel_price as order_cancel_price, o.od_refund_price as order_refund_price, o.od_settle_case as order_settle_case, $order_amount_sql as order_amount,
pp.pp_id as personal_oid, pp.pp_tno as personal_tid, pp.pp_price as personal_amount, pp.pp_receipt_price as personal_receipt_price
$sql_from
$sql_where
order by p.ip_id desc
limit $from_record, $rows ";
$result = sql_query($sql);
$query = array(
'status' => $status,
'risk' => $risk,
'sfl' => $sfl,
'stx' => $stx,
'fr_date' => $fr_date,
'to_date' => $to_date
);
$query_string = http_build_query($query, '', '&amp;');
// 상세보기 링크는 목록으로 돌아올 때 현재 페이지까지 유지하도록 page를 포함한다.
$view_query_string = $query_string.'&amp;page='.$page;
?>
<div class="local_ov01 local_ov">
<a href="./inicisloglist.php" class="ov_listall">전체목록</a>
<span class="btn_ov01"><span class="ov_txt">전체</span><span class="ov_num"><?php echo number_format((int) $all_count['cnt']); ?>건</span></span>
<a href="?risk=anomaly" class="btn_ov01"><span class="ov_txt">확인 필요</span><span class="ov_num"><?php echo number_format((int) $anomaly_count['cnt']); ?>건</span></a>
<a href="?risk=failed" class="btn_ov01"><span class="ov_txt">실패</span><span class="ov_num"><?php echo number_format((int) $failed_count['cnt']); ?>건</span></a>
</div>
<div class="local_desc01 local_desc">
<p>이 화면은 INIpay PRO의 결제 요청, 인증, 승인, 주문 저장, 서버 통보 및 취소 이력을 표시합니다. KG 거래조회 결과가 있으면 실제 PG 상태와 주문 DB를 함께 비교합니다. 거래조회 실패 또는 조회 전 거래는 KG이니시스 상점관리자에서 TID와 금액을 다시 확인하십시오.</p>
<p>최근 자동 감시: <?php echo !empty($default['de_inicis_pro_monitor_at']) ? get_text($default['de_inicis_pro_monitor_at']) : '실행 기록 없음'; ?><?php if (!empty($default['de_inicis_pro_monitor_message'])) { ?> / <?php echo get_text($default['de_inicis_pro_monitor_message']); ?><?php } ?></p>
<p>감사 이력 기록 오류: <strong<?php echo !empty($audit_error_count['cnt']) ? ' style="color:#d00"' : ''; ?>><?php echo number_format((int) $audit_error_count['cnt']); ?>건</strong> / 통보 허용 IP: <?php echo get_text(implode(', ', inicis_pro_noti_allowed_ips())); ?></p>
</div>
<form method="post" action="./inicislogcheck.php" style="margin-bottom:10px">
<input type="hidden" name="token" value="">
<input type="hidden" name="mode" value="batch">
<button type="submit" class="btn btn_02" onclick="return confirm('확인 필요 거래 중 조회 가능한 최근 5건을 KG이니시스에서 조회하시겠습니까? 주문 생성이나 결제 취소는 실행하지 않습니다.');">확인 필요 거래 KG 대사</button>
</form>
<form class="local_sch03 local_sch" method="get">
<div>
<strong>처리 구분</strong>
<select name="risk">
<option value=""<?php echo get_selected($risk, ''); ?>>전체</option>
<option value="anomaly"<?php echo get_selected($risk, 'anomaly'); ?>>확인 필요</option>
<option value="failed"<?php echo get_selected($risk, 'failed'); ?>>실패</option>
<option value="processing"<?php echo get_selected($risk, 'processing'); ?>>처리 중</option>
<option value="complete"<?php echo get_selected($risk, 'complete'); ?>>정상 완료</option>
<option value="canceled"<?php echo get_selected($risk, 'canceled'); ?>>취소 완료</option>
<option value="abandoned"<?php echo get_selected($risk, 'abandoned'); ?>>결제창 종료·미진행</option>
</select>
<strong>현재 상태</strong>
<select name="status">
<option value="">전체</option>
<?php foreach ($allowed_status as $status_value) { if ($status_value === '') continue; ?>
<option value="<?php echo $status_value; ?>"<?php echo get_selected($status, $status_value); ?>><?php echo get_text(inicis_admin_status_label($status_value)); ?></option>
<?php } ?>
</select>
<strong>기간</strong>
<input type="text" id="fr_date" name="fr_date" value="<?php echo get_text($fr_date); ?>" class="frm_input" size="10" maxlength="10" placeholder="YYYY-MM-DD">
~
<input type="text" id="to_date" name="to_date" value="<?php echo get_text($to_date); ?>" class="frm_input" size="10" maxlength="10" placeholder="YYYY-MM-DD">
</div>
<div>
<select name="sfl">
<option value="ip_oid"<?php echo get_selected($sfl, 'ip_oid'); ?>>주문번호 OID</option>
<option value="ip_tid"<?php echo get_selected($sfl, 'ip_tid'); ?>>승인 TID</option>
<option value="ip_auth_tid"<?php echo get_selected($sfl, 'ip_auth_tid'); ?>>인증 TID</option>
<option value="mb_id"<?php echo get_selected($sfl, 'mb_id'); ?>>회원 ID</option>
</select>
<input type="text" name="stx" value="<?php echo get_text($stx); ?>" class="frm_input" size="30">
<input type="submit" value="검색" class="btn_submit">
</div>
</form>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>KG이니시스 INIpay PRO 결제 처리 현황 목록</caption>
<thead>
<tr>
<th scope="col">최근 처리일시</th>
<th scope="col">주문번호</th>
<th scope="col">승인 TID</th>
<th scope="col">회원</th>
<th scope="col">구분</th>
<th scope="col">결제수단</th>
<th scope="col">금액</th>
<th scope="col">현재 상태</th>
<th scope="col">KG 거래상태</th>
<th scope="col">주문 확인</th>
<th scope="col">이력</th>
<th scope="col">관리</th>
</tr>
</thead>
<tbody>
<?php for ($i = 0; $row = sql_fetch_array($result); $i++) {
$has_order = inicis_admin_has_order($row);
$is_anomaly = inicis_admin_is_anomaly($row);
$order_type_label = $row['ip_order_type'] === 'personal' ? '개인결제' : '주문';
$device_label = $row['ip_device'] === 'MOBILE' ? '모바일' : ($row['ip_device'] === 'WEB' ? 'PC' : $row['ip_device']);
$bg = 'bg'.($i % 2);
?>
<tr class="<?php echo $bg; ?>">
<td class="td_time"><?php echo get_text($row['ip_updated_at']); ?></td>
<td class="td_odrnum2"><a href="./inicislogview.php?oid=<?php echo urlencode($row['ip_oid']); ?>&amp;<?php echo $view_query_string; ?>"><?php echo get_text($row['ip_oid']); ?></a></td>
<td class="td_left"><?php echo $row['ip_tid'] !== '' ? get_text($row['ip_tid']) : '-'; ?></td>
<td class="td_name"><?php echo $row['mb_id'] !== '' ? get_text($row['mb_id']) : '비회원'; ?></td>
<td class="td_center"><?php echo get_text($order_type_label.' / '.$device_label); ?><br><?php
if ($row['ip_environment'] === 'test') echo '<strong style="color:#d00">테스트</strong>';
elseif ($row['ip_environment'] === 'live') echo '<span style="font-size:11px">실결제</span>';
else echo '<span style="font-size:11px;color:#d00">확인 필요</span>';
?></td>
<td class="td_center"><?php echo get_text(inicis_admin_pay_type_label($row['ip_pay_type'], $row['ip_easy_pay'])); ?></td>
<td class="td_price"><?php echo number_format((int) $row['ip_amount']); ?></td>
<td class="td_center"><?php echo get_text(inicis_admin_status_label(inicis_admin_primary_status($row))); ?></td>
<td class="td_center">
<?php if (!empty($row['ip_pg_checked_at'])) { ?>
<?php echo $row['ip_pg_result_code'] === '00' ? get_text(inicis_admin_pg_status_label($row['ip_pg_status'])) : '<strong style="color:#d00">조회 실패</strong>'; ?><br>
<span style="font-size:11px"><?php echo get_text($row['ip_pg_checked_at']); ?></span>
<?php } else { ?>미조회<?php } ?>
</td>
<td class="td_center">
<?php if ($is_anomaly) { ?><strong style="color:#d00">확인 필요</strong>
<?php } elseif ($has_order) { ?><span style="color:#168b3f">정상 연결</span>
<?php } elseif ($row['ip_status'] === 'canceled') { ?>취소됨
<?php } else { ?>미생성<?php } ?>
</td>
<td class="td_num"><?php echo number_format((int) $row['ip_event_count']); ?></td>
<td class="td_mng td_mng_s">
<a href="./inicislogview.php?oid=<?php echo urlencode($row['ip_oid']); ?>&amp;<?php echo $view_query_string; ?>" class="btn btn_03">상세</a>
<?php if ($has_order && $row['ip_order_type'] === 'personal') { ?>
<a href="./personalpayform.php?w=u&amp;pp_id=<?php echo urlencode($row['ip_oid']); ?>" class="btn btn_02">개인</a>
<?php } elseif ($has_order) { ?>
<a href="./orderform.php?od_id=<?php echo urlencode($row['ip_oid']); ?>" class="btn btn_02">주문</a>
<?php } ?>
</td>
</tr>
<?php }
if ($i === 0)
echo '<tr><td colspan="12" class="empty_table">자료가 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
<?php
$paging_url = './inicisloglist.php?'.$query_string.'&amp;page=';
echo get_paging(G5_IS_MOBILE ? $config['cf_mobile_pages'] : $config['cf_write_pages'], $page, $total_page, $paging_url);
?>
<script>
$(function(){
$("#fr_date, #to_date").datepicker({ changeMonth: true, changeYear: true, dateFormat: "yy-mm-dd", showButtonPanel: true, yearRange: "c-99:c+99", maxDate: "+0d" });
});
</script>
<?php
include_once(G5_ADMIN_PATH.'/admin.tail.php');
+148
View File
@@ -0,0 +1,148 @@
<?php
$sub_menu = '400420';
include_once('./_common.php');
auth_check_menu($auth, $sub_menu, 'r');
include_once(G5_SHOP_PATH.'/inicis/pro/inicis_pro.lib.php');
include_once('./inicislog.lib.php');
$oid = isset($_GET['oid']) && !is_array($_GET['oid']) ? inicis_pro_clean_oid($_GET['oid']) : '';
if ($oid === '' || !isset($_GET['oid']) || $oid !== $_GET['oid'])
alert('결제 주문번호가 올바르지 않습니다.', './inicisloglist.php');
$tables = inicis_pro_audit_tables();
if (!inicis_pro_audit_schema_ready())
alert('결제 현황 테이블이 설치되지 않았습니다. DB 업그레이드를 실행해 주십시오.', G5_ADMIN_URL.'/dbupgrade.php');
// 목록으로 돌아갈 때 넘어온 검색 조건과 페이지를 그대로 유지한다.
$list_query = array();
foreach (array('status', 'risk', 'sfl', 'stx', 'fr_date', 'to_date', 'page') as $list_key) {
if (isset($_GET[$list_key]) && !is_array($_GET[$list_key]) && $_GET[$list_key] !== '')
$list_query[$list_key] = (string) $_GET[$list_key];
}
$list_url = './inicisloglist.php'.(count($list_query) ? '?'.http_build_query($list_query, '', '&amp;') : '');
$oid_sql = sql_escape_string($oid);
$order_amount_sql = "(o.od_cart_price + o.od_send_cost + o.od_send_cost2 - o.od_cart_coupon - o.od_coupon - o.od_send_coupon - o.od_receipt_point)";
$sql = " select p.*,
o.od_id as order_oid, o.od_tno as order_tid, o.od_status as order_status, o.od_time as order_time,
o.od_receipt_price as order_receipt_price, o.od_misu as order_misu, o.od_cancel_price as order_cancel_price, o.od_refund_price as order_refund_price,
o.od_settle_case as order_settle_case, $order_amount_sql as order_amount,
pp.pp_id as personal_oid, pp.pp_tno as personal_tid, pp.pp_price as personal_amount, pp.pp_receipt_price as personal_receipt_price, pp.pp_time as personal_time
from `{$tables['summary']}` p
left join {$g5['g5_shop_order_table']} o on p.ip_order_type <> 'personal' and o.od_id = p.ip_oid
left join {$g5['g5_shop_personalpay_table']} pp on p.ip_order_type = 'personal' and pp.pp_id = p.ip_oid
where p.ip_oid = '$oid_sql' ";
$row = sql_fetch($sql);
if (empty($row['ip_id']))
alert('결제 처리 이력을 찾을 수 없습니다.', './inicisloglist.php');
$events = sql_query(" select * from `{$tables['event']}` where ip_oid = '$oid_sql' order by pe_id asc ");
$has_order = inicis_admin_has_order($row);
$is_anomaly = inicis_admin_is_anomaly($row);
$saved_tid = inicis_admin_order_tid($row);
$saved_amount = inicis_admin_order_amount($row);
$legacy_pro_log = empty($row['ip_tid']) ? inicis_pro_get_log($oid) : array();
$legacy_pro_data = isset($legacy_pro_log['pro_data']) && is_array($legacy_pro_log['pro_data']) ? $legacy_pro_log['pro_data'] : array();
// 승인 TID가 있거나 승인 로그에서 복구할 수 있을 때만 조회한다.
// TID를 참조할 수 없는 미완료(인증 전) 거래는 KG에 조회할 대상이 없다.
$can_inquiry = !empty($row['ip_tid'])
|| (!empty($legacy_pro_data['__pro']) && $legacy_pro_data['__pro'] === '1'
&& isset($legacy_pro_log['P_STATUS']) && $legacy_pro_log['P_STATUS'] === '00' && !empty($legacy_pro_data['P_APPL_TID']));
$g5['title'] = 'KG이니시스 INIpay PRO 결제 처리 상세';
include_once(G5_ADMIN_PATH.'/admin.head.php');
?>
<div class="local_desc01 local_desc">
<p>이 기록은 영카트 서버가 처리한 단계의 감사 이력입니다. 최종 결제·취소 여부는 KG이니시스 상점관리자의 TID 거래내역과 대조하여 확정하십시오.</p>
<p>설정된 보존기간이 지난 단계별 상세 이력은 순차 삭제될 수 있으며, 아래 누적 이력 수에는 삭제 전 기록도 포함됩니다.</p>
<?php if (!empty($row['ip_audit_error'])) { ?><p><strong style="color:#d00">이 거래에서 감사 상세 이력 기록 오류가 감지됐습니다. 서버 오류 로그와 KG이니시스 거래내역을 함께 확인하십시오.</strong></p><?php } ?>
<?php if (!empty($row['ip_refund_required'])) { ?><p><strong style="color:#d00">취소 주문에 입금이 확인되어 환불이 필요합니다. 상품을 발송하지 말고 KG이니시스 상점관리자에서 입금 및 환불 상태를 확인하십시오.</strong></p><?php } ?>
</div>
<div class="local_desc02 local_desc">
<p><strong><?php echo $is_anomaly ? '권장 조치' : '확인 결과'; ?>:</strong> <?php echo get_text(inicis_admin_recommendation($row)); ?></p>
</div>
<div class="tbl_frm01 tbl_wrap">
<table>
<caption>결제 처리 요약</caption>
<tbody>
<tr><th scope="row">주문번호 OID</th><td><?php echo get_text($row['ip_oid']); ?></td><th scope="row">처리 판정</th><td><?php echo $is_anomaly ? '<strong style="color:#d00">확인 필요</strong>' : ($has_order ? '<span style="color:#168b3f">주문 정상 연결</span>' : get_text(inicis_admin_status_label(inicis_admin_primary_status($row)))); ?></td></tr>
<tr><th scope="row">인증 TID</th><td><?php echo $row['ip_auth_tid'] !== '' ? get_text($row['ip_auth_tid']) : '-'; ?></td><th scope="row">승인 TID</th><td><?php echo $row['ip_tid'] !== '' ? get_text($row['ip_tid']) : '-'; ?></td></tr>
<tr><th scope="row">회원 ID</th><td><?php echo $row['mb_id'] !== '' ? get_text($row['mb_id']) : '비회원'; ?></td><th scope="row">MID</th><td><?php echo get_text($row['ip_mid']); ?></td></tr>
<tr><th scope="row">결제금액</th><td><?php echo number_format((int) $row['ip_amount']); ?>원</td><th scope="row">결제수단</th><td><?php echo get_text(inicis_admin_pay_type_label($row['ip_pay_type'], $row['ip_easy_pay'])); ?></td></tr>
<tr><th scope="row">결제환경</th><td><?php echo $row['ip_environment'] === 'test' ? '<strong style="color:#d00">테스트</strong>' : ($row['ip_environment'] === 'live' ? '실결제' : '<strong style="color:#d00">확인 필요</strong>'); ?></td><th scope="row">환불 확인 필요</th><td><?php echo !empty($row['ip_refund_required']) ? '<strong style="color:#d00">예</strong>' : '아니오'; ?></td></tr>
<tr><th scope="row">접속 구분</th><td><?php echo get_text($row['ip_device']); ?></td><th scope="row">결제 구분</th><td><?php echo $row['ip_order_type'] === 'personal' ? '개인결제' : '일반주문'; ?></td></tr>
<tr><th scope="row">현재 상태</th><td><?php echo get_text(inicis_admin_status_label(inicis_admin_primary_status($row))); ?></td><th scope="row">결과 코드</th><td><?php echo $row['ip_result_code'] !== '' ? get_text($row['ip_result_code']) : '-'; ?></td></tr>
<tr><th scope="row">최근 서버 통보</th><td><?php echo $row['ip_noti_status'] !== '' ? get_text(inicis_admin_status_label($row['ip_noti_status'])).($row['ip_noti_code'] !== '' ? ' ('.get_text($row['ip_noti_code']).')' : '') : '-'; ?></td><th scope="row">통보 실패 누계</th><td><?php echo number_format((int) $row['ip_noti_failed_count']); ?>회</td></tr>
<tr><th scope="row">최근 취소 처리</th><td><?php echo $row['ip_cancel_status'] !== '' ? get_text(inicis_admin_status_label($row['ip_cancel_status'])).($row['ip_cancel_code'] !== '' ? ' ('.get_text($row['ip_cancel_code']).')' : '') : '-'; ?></td><th scope="row">가상계좌 입금기한</th><td><?php echo !empty($row['ip_vbank_due_at']) ? get_text($row['ip_vbank_due_at']) : '-'; ?></td></tr>
<tr><th scope="row">통보 메시지</th><td><?php echo $row['ip_noti_message'] !== '' ? get_text($row['ip_noti_message']) : '-'; ?></td><th scope="row">취소 메시지</th><td><?php echo $row['ip_cancel_message'] !== '' ? get_text($row['ip_cancel_message']) : '-'; ?></td></tr>
<tr><th scope="row">감사 이력 상태</th><td><?php echo !empty($row['ip_audit_error']) ? '<strong style="color:#d00">상세 기록 오류</strong>' : '정상'; ?></td><th scope="row">최근 이상 알림</th><td><?php echo !empty($row['ip_alerted_at']) ? get_text($row['ip_alerted_at']) : '-'; ?></td></tr>
<tr><th scope="row">마지막 메시지</th><td colspan="3"><?php echo $row['ip_result_message'] !== '' ? get_text($row['ip_result_message']) : '-'; ?></td></tr>
<tr><th scope="row">승인 일시</th><td><?php echo !empty($row['ip_approved_at']) ? get_text($row['ip_approved_at']) : '-'; ?></td><th scope="row">주문 저장 일시</th><td><?php echo !empty($row['ip_ordered_at']) ? get_text($row['ip_ordered_at']) : '-'; ?></td></tr>
<tr><th scope="row">통보 일시</th><td><?php echo !empty($row['ip_notified_at']) ? get_text($row['ip_notified_at']) : '-'; ?></td><th scope="row">취소 일시</th><td><?php echo !empty($row['ip_canceled_at']) ? get_text($row['ip_canceled_at']) : '-'; ?></td></tr>
<tr><th scope="row">주문 DB의 TID</th><td><?php echo $has_order ? get_text($saved_tid) : '-'; ?></td><th scope="row">주문 DB의 금액</th><td><?php echo $has_order ? number_format($saved_amount).'원' : '-'; ?></td></tr>
<?php if ($row['ip_order_type'] !== 'personal') { ?><tr><th scope="row">주문 상태/입금액</th><td><?php echo $has_order ? get_text($row['order_status']).' / '.number_format((int) $row['order_receipt_price']).'원' : '-'; ?></td><th scope="row">주문 미수금/취소액</th><td><?php echo $has_order ? number_format((int) $row['order_misu']).'원 / '.number_format((int) $row['order_cancel_price']).'원' : '-'; ?></td></tr><?php } ?>
<tr><th scope="row">KG 거래조회 상태</th><td><?php echo !empty($row['ip_pg_checked_at']) ? ($row['ip_pg_result_code'] === '00' ? get_text(inicis_admin_pg_status_label($row['ip_pg_status'])) : '조회 실패 ('.get_text($row['ip_pg_result_code']).')') : '미조회'; ?></td><th scope="row">KG 거래조회 일시</th><td><?php echo !empty($row['ip_pg_checked_at']) ? get_text($row['ip_pg_checked_at']) : '-'; ?></td></tr>
<tr><th scope="row">KG 조회 TID</th><td><?php echo !empty($row['ip_pg_tid']) ? get_text($row['ip_pg_tid']) : '-'; ?></td><th scope="row">KG 조회 금액</th><td><?php echo (int) $row['ip_pg_amount'] > 0 ? number_format((int) $row['ip_pg_amount']).'원' : '-'; ?></td></tr>
<tr><th scope="row">KG 조회 메시지</th><td colspan="3"><?php echo !empty($row['ip_pg_message']) ? get_text($row['ip_pg_message']) : '-'; ?></td></tr>
</tbody>
</table>
</div>
<div class="btn_fixed_top">
<a href="<?php echo $list_url; ?>" class="btn btn_02">목록</a>
<?php if ($can_inquiry) { ?>
<form method="post" action="./inicislogcheck.php" style="display:inline">
<input type="hidden" name="token" value="">
<input type="hidden" name="mode" value="single">
<input type="hidden" name="oid" value="<?php echo get_text($row['ip_oid']); ?>">
<button type="submit" class="btn btn_02" onclick="return confirm('이 거래를 KG이니시스에서 조회하시겠습니까? 주문 생성이나 결제 취소는 실행하지 않습니다.');">KG 거래조회</button>
</form>
<?php } ?>
<?php if ($has_order && $row['ip_order_type'] === 'personal') { ?>
<a href="./personalpayform.php?w=u&amp;pp_id=<?php echo urlencode($row['ip_oid']); ?>" class="btn btn_03">개인결제 보기</a>
<?php } elseif ($has_order) { ?>
<a href="./orderform.php?od_id=<?php echo urlencode($row['ip_oid']); ?>" class="btn btn_03">주문 보기</a>
<?php } ?>
</div>
<div class="tbl_head01 tbl_wrap">
<table>
<caption>결제 단계별 처리 이력</caption>
<thead>
<tr>
<th scope="col">순서</th>
<th scope="col">처리일시</th>
<th scope="col">경로</th>
<th scope="col">단계</th>
<th scope="col">결과</th>
<th scope="col">코드</th>
<th scope="col">메시지</th>
<th scope="col">IP</th>
</tr>
</thead>
<tbody>
<?php for ($i = 1; $event = sql_fetch_array($events); $i++) { ?>
<tr class="bg<?php echo ($i - 1) % 2; ?>">
<td class="td_num"><?php echo $i; ?></td>
<td class="td_time"><?php echo get_text($event['pe_created_at']); ?></td>
<td class="td_center"><?php echo get_text(inicis_admin_source_label($event['pe_source'])); ?></td>
<td class="td_center"><?php echo get_text(inicis_admin_stage_label($event['pe_stage'])); ?></td>
<td class="td_center"><?php echo get_text(inicis_admin_status_label($event['pe_status'])); ?></td>
<td class="td_center"><?php echo $event['pe_code'] !== '' ? get_text($event['pe_code']) : '-'; ?></td>
<td class="td_left"><?php echo $event['pe_message'] !== '' ? get_text($event['pe_message']) : '-'; ?></td>
<td class="td_center"><?php echo get_text($event['pe_ip']); ?></td>
</tr>
<?php }
if ($i === 1)
echo '<tr><td colspan="8" class="empty_table">단계별 이력이 없습니다.</td></tr>';
?>
</tbody>
</table>
</div>
<?php
include_once(G5_ADMIN_PATH.'/admin.tail.php');
+12 -10
View File
@@ -20,6 +20,8 @@ if (!$od['od_id']) {
// 주문정보
$data = unserialize(base64_decode($od['dt_data']));
$data_od_cp_id = isset($data['od_cp_id']) ? safe_replace_regex($data['od_cp_id'], 'cp_id') : '';
$data_sc_cp_id = isset($data['sc_cp_id']) ? safe_replace_regex($data['sc_cp_id'], 'cp_id') : '';
$sql_common = " from {$g5['g5_shop_cart_table']} where od_id = '{$od['cart_id']}' and ct_status = '쇼핑' and ct_select = '1' ";
@@ -38,8 +40,8 @@ if($od['mb_id']) {
$it_cp_cnt = (isset($data['cp_id']) && is_array($data['cp_id'])) ? count($data['cp_id']) : 0;
$arr_it_cp_prc = array();
for($i=0; $i<$it_cp_cnt; $i++) {
$cid = $data['cp_id'][$i];
$it_id = $data['it_id'][$i];
$cid = isset($data['cp_id'][$i]) ? safe_replace_regex($data['cp_id'][$i], 'cp_id') : '';
$it_id = isset($data['it_id'][$i]) ? safe_replace_regex($data['it_id'][$i], 'it_id') : '';
$sql = " select cp_id, cp_method, cp_target, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
from {$g5['g5_shop_coupon_table']}
where cp_id = '$cid'
@@ -98,10 +100,10 @@ if($od['mb_id']) {
$tot_od_price -= $tot_it_cp_price;
// 주문쿠폰
if(isset($data['od_cp_id']) && $data['od_cp_id']) {
if($data_od_cp_id) {
$sql = " select cp_id, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
from {$g5['g5_shop_coupon_table']}
where cp_id = '{$data['od_cp_id']}'
where cp_id = '$data_od_cp_id'
and mb_id IN ( '{$od['mb_id']}', '전체회원' )
and cp_method = '2' ";
$cp = sql_fetch($sql);
@@ -134,10 +136,10 @@ $od_send_cost = get_sendcost($od['cart_id']);
$tot_sc_cp_price = 0;
if($od['mb_id'] && $od_send_cost > 0) {
// 배송쿠폰
if($data['sc_cp_id']) {
if($data_sc_cp_id) {
$sql = " select cp_id, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
from {$g5['g5_shop_coupon_table']}
where cp_id = '{$data['sc_cp_id']}'
where cp_id = '$data_sc_cp_id'
and mb_id IN ( '{$od['mb_id']}', '전체회원' )
and cp_method = '3' ";
$cp = sql_fetch($sql);
@@ -485,7 +487,7 @@ $pg_anchor = '<ul class="anchor">
<tr>
<th scope="row"><span class="sound_only">주문하시는 분 </span>주소</th>
<td>
<span><?php echo $data['od_zip']; ?></span>
<span><?php echo get_text($data['od_zip']); ?></span>
<span><?php echo get_text($data['od_addr1']); ?></span>
<span><?php echo get_text($data['od_addr2']); ?></span>
<span><?php echo get_text($data['od_addr3']); ?></span>
@@ -526,7 +528,7 @@ $pg_anchor = '<ul class="anchor">
<tr>
<th scope="row"><span class="sound_only">받으시는 분 </span>주소</th>
<td>
<span><?php echo $data['od_b_zip']; ?></span>
<span><?php echo get_text($data['od_b_zip']); ?></span>
<span><?php echo get_text($data['od_b_addr1']); ?></span>
<span><?php echo get_text($data['od_b_addr2']); ?></span>
<span><?php echo get_text($data['od_b_addr3']); ?></span>
@@ -536,7 +538,7 @@ $pg_anchor = '<ul class="anchor">
<?php if ($default['de_hope_date_use']) { ?>
<tr>
<th scope="row">희망배송일</th>
<td><?php echo $data['od_hope_date']; ?> (<?php echo get_yoil($data['od_hope_date']); ?>)</td>
<td><?php echo get_text($data['od_hope_date']); ?> (<?php echo get_yoil($data['od_hope_date']); ?>)</td>
</tr>
<?php } ?>
<tr>
@@ -571,4 +573,4 @@ function del_confirm()
</script>
<?php
include_once(G5_ADMIN_PATH.'/admin.tail.php');
include_once(G5_ADMIN_PATH.'/admin.tail.php');
+41 -33
View File
@@ -30,6 +30,8 @@ if($w == 'd') {
// 주문정보
$data = unserialize(base64_decode($od['dt_data']));
$data_od_cp_id = isset($data['od_cp_id']) ? safe_replace_regex($data['od_cp_id'], 'cp_id') : '';
$data_sc_cp_id = isset($data['sc_cp_id']) ? safe_replace_regex($data['sc_cp_id'], 'cp_id') : '';
$sql_common = " from {$g5['g5_shop_cart_table']} where od_id = '{$od['cart_id']}' and ct_status = '쇼핑' ";
@@ -53,8 +55,8 @@ if($od['mb_id']) {
$it_cp_cnt = (isset($data['cp_id']) && is_array($data['cp_id'])) ? count($data['cp_id']) : 0;
$arr_it_cp_prc = array();
for($i=0; $i<$it_cp_cnt; $i++) {
$cid = $data['cp_id'][$i];
$it_id = $data['it_id'][$i];
$cid = isset($data['cp_id'][$i]) ? safe_replace_regex($data['cp_id'][$i], 'cp_id') : '';
$it_id = isset($data['it_id'][$i]) ? safe_replace_regex($data['it_id'][$i], 'it_id') : '';
$sql = " select cp_id, cp_method, cp_target, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
from {$g5['g5_shop_coupon_table']}
where cp_id = '$cid'
@@ -113,10 +115,10 @@ if($od['mb_id']) {
$tot_od_price -= $tot_it_cp_price;
// 주문쿠폰
if(isset($data['od_cp_id']) && $data['od_cp_id']) {
if($data_od_cp_id) {
$sql = " select cp_id, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
from {$g5['g5_shop_coupon_table']}
where cp_id = '{$data['od_cp_id']}'
where cp_id = '$data_od_cp_id'
and mb_id IN ( '{$od['mb_id']}', '전체회원' )
and cp_method = '2' ";
$cp = sql_fetch($sql);
@@ -149,10 +151,10 @@ $od_send_cost = get_sendcost($od['cart_id']);
$tot_sc_cp_price = 0;
if($od['mb_id'] && $od_send_cost > 0) {
// 배송쿠폰
if($data['sc_cp_id']) {
if($data_sc_cp_id) {
$sql = " select cp_id, cp_type, cp_price, cp_trunc, cp_minimum, cp_maximum
from {$g5['g5_shop_coupon_table']}
where cp_id = '{$data['sc_cp_id']}'
where cp_id = '$data_sc_cp_id'
and mb_id IN ( '{$od['mb_id']}', '전체회원' )
and cp_method = '3' ";
$cp = sql_fetch($sql);
@@ -212,38 +214,38 @@ if($data['od_settle_case'] == 'KAKAOPAY')
$od_pg = 'KAKAOPAY';
$od_email = get_email_address($data['od_email']);
$od_name = clean_xss_tags($data['od_name']);
$od_tel = clean_xss_tags($data['od_tel']);
$od_hp = clean_xss_tags($data['od_hp']);
$od_name = addslashes(clean_xss_tags($data['od_name']));
$od_tel = addslashes(clean_xss_tags($data['od_tel']));
$od_hp = addslashes(clean_xss_tags($data['od_hp']));
$od_zip = preg_replace('/[^0-9]/', '', $data['od_zip']);
$od_zip1 = substr($od_zip, 0, 3);
$od_zip2 = substr($od_zip, 3);
$od_addr1 = clean_xss_tags($data['od_addr1']);
$od_addr2 = clean_xss_tags($data['od_addr2']);
$od_addr3 = clean_xss_tags($data['od_addr3']);
$od_addr_jibeon = preg_match("/^(N|R)$/", $data['od_addr_jibeon']) ? $data['od_addr_jibeon'] : '';
$od_b_name = clean_xss_tags($data['od_b_name']);
$od_b_tel = clean_xss_tags($data['od_b_tel']);
$od_b_hp = clean_xss_tags($data['od_b_hp']);
$od_addr1 = addslashes(clean_xss_tags($data['od_addr1']));
$od_addr2 = addslashes(clean_xss_tags($data['od_addr2']));
$od_addr3 = addslashes(clean_xss_tags($data['od_addr3']));
$od_addr_jibeon = preg_match("/^(N|R|J)$/", $data['od_addr_jibeon']) ? $data['od_addr_jibeon'] : '';
$od_b_name = addslashes(clean_xss_tags($data['od_b_name']));
$od_b_tel = addslashes(clean_xss_tags($data['od_b_tel']));
$od_b_hp = addslashes(clean_xss_tags($data['od_b_hp']));
$od_b_zip = preg_replace('/[^0-9]/', '', $data['od_b_zip']);
$od_b_zip1 = substr($od_b_zip, 0, 3);
$od_b_zip2 = substr($od_b_zip, 3);
$od_b_addr1 = clean_xss_tags($data['od_b_addr1']);
$od_b_addr2 = clean_xss_tags($data['od_b_addr2']);
$od_b_addr3 = clean_xss_tags($data['od_b_addr3']);
$od_b_addr_jibeon = preg_match("/^(N|R)$/", $data['od_b_addr_jibeon']) ? $data['od_b_addr_jibeon'] : '';
$od_memo = clean_xss_tags($data['od_memo'], 0, 1, 0, 0);
$od_deposit_name = clean_xss_tags($data['od_deposit_name']);
$od_b_addr1 = addslashes(clean_xss_tags($data['od_b_addr1']));
$od_b_addr2 = addslashes(clean_xss_tags($data['od_b_addr2']));
$od_b_addr3 = addslashes(clean_xss_tags($data['od_b_addr3']));
$od_b_addr_jibeon = preg_match("/^(N|R|J)$/", $data['od_b_addr_jibeon']) ? $data['od_b_addr_jibeon'] : '';
$od_memo = addslashes(clean_xss_tags($data['od_memo'], 0, 1, 0, 0));
$od_deposit_name = addslashes(clean_xss_tags($data['od_deposit_name']));
$od_tax_flag = $default['de_tax_flag_use'];
$od_receipt_price = $tot_ct_price + $od_send_cost + $od_send_cost2 - ($od_temp_point + $tot_cp_price + $tot_sc_cp_price);
$od_receipt_point = $od_temp_point;
$od_receipt_time = $od['dt_time'];
$od_misu = 0;
$od_status = '입금';
$od_bank_account = isset($data['od_bank_account']) ? clean_xss_tags($data['od_bank_account'], 1, 1) : '';
$od_bank_account = isset($data['od_bank_account']) ? addslashes(clean_xss_tags(stripslashes($data['od_bank_account']), 1, 1)) : '';
$od_tno = '';
$od_app_no = '';
$od_hope_date = isset($data['od_hope_date']) ? clean_xss_tags($data['od_hope_date'], 1, 1) : '';
$od_hope_date = isset($data['od_hope_date']) ? addslashes(clean_xss_tags(stripslashes($data['od_hope_date']), 1, 1)) : '';
// 주문서에 입력
$sql = " insert {$g5['g5_shop_order_table']}
@@ -321,8 +323,8 @@ if ($od['mb_id'] && $od_receipt_point)
if($od['mb_id']) {
$it_cp_cnt = (isset($data['cp_id']) && is_array($data['cp_id'])) ? count($data['cp_id']) : 0;
for($i=0; $i<$it_cp_cnt; $i++) {
$cid = $data['cp_id'][$i];
$cp_it_id = $data['it_id'][$i];
$cid = isset($data['cp_id'][$i]) ? safe_replace_regex($data['cp_id'][$i], 'cp_id') : '';
$cp_it_id = isset($data['it_id'][$i]) ? safe_replace_regex($data['it_id'][$i], 'it_id') : '';
$cp_prc = isset($arr_it_cp_prc[$cp_it_id]) ? (int) $arr_it_cp_prc[$cp_it_id] : 0;
if(trim($cid)) {
@@ -346,9 +348,9 @@ if($od['mb_id']) {
sql_query($sql);
}
if(isset($data['od_cp_id']) && $data['od_cp_id']) {
if($data_od_cp_id) {
$sql = " insert into {$g5['g5_shop_coupon_log_table']}
set cp_id = '{$data['od_cp_id']}',
set cp_id = '$data_od_cp_id',
mb_id = '{$od['mb_id']}',
od_id = '$od_id',
cp_price = '$tot_od_cp_price',
@@ -356,9 +358,9 @@ if($od['mb_id']) {
sql_query($sql);
}
if(isset($data['sc_cp_id']) && $data['sc_cp_id']) {
if($data_sc_cp_id) {
$sql = " insert into {$g5['g5_shop_coupon_log_table']}
set cp_id = '{$data['sc_cp_id']}',
set cp_id = '$data_sc_cp_id',
mb_id = '{$od['mb_id']}',
od_id = '$od_id',
cp_price = '$tot_sc_cp_price',
@@ -384,10 +386,16 @@ sql_query($sql);
$sql = " delete from {$g5['g5_shop_order_data_table']} where od_id = '$od_id' and dt_pg = '$od_pg' ";
sql_query($sql, true);
$orderform_url = './orderform.php?od_id='.$od_id;
$inorderlist_url = './inorderlist.php?'.str_replace('&amp;', '&', $qstr);
$js_replace = array('\\' => '\\\\', '"' => '\\"', "'" => '\\u0027', '/' => '\\/', "\r" => '\\r', "\n" => '\\n', "\t" => '\\t', '<' => '\\u003C', '>' => '\\u003E', '&' => '\\u0026', "\xE2\x80\xA8" => '\\u2028', "\xE2\x80\xA9" => '\\u2029');
$js_orderform_url = function_exists('get_js_safe_string') ? get_js_safe_string($orderform_url) : '"'.strtr((string)$orderform_url, $js_replace).'"';
$js_inorderlist_url = function_exists('get_js_safe_string') ? get_js_safe_string($inorderlist_url) : '"'.strtr((string)$inorderlist_url, $js_replace).'"';
echo '<meta http-equiv="content-type" content="text/html; charset=utf-8">'.PHP_EOL;
echo '<script>'.PHP_EOL;
echo 'if(confirm("복구하신 주문 상세페이지로 이동하시겠습니까?"))'.PHP_EOL;
echo 'document.location.href = "./orderform.php?od_id='.$od_id.'";'.PHP_EOL;
echo 'document.location.href = '.$js_orderform_url.';'.PHP_EOL;
echo 'else'.PHP_EOL;
echo 'document.location.href = "./inorderlist.php?'.str_replace('&amp;', '&', $qstr).'";'.PHP_EOL;
echo '</script>'.PHP_EOL;
echo 'document.location.href = '.$js_inorderlist_url.';'.PHP_EOL;
echo '</script>'.PHP_EOL;
+10 -1
View File
@@ -24,6 +24,9 @@ if (!$sst) {
$sst = "od_id";
$sod = "desc";
}
$allowed_sst = array('od_id');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'od_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt
@@ -104,6 +107,12 @@ $colspan = 10;
case 'lg':
$pg = 'LGU+';
break;
case 'toss':
$pg = '토스페이먼츠';
break;
case 'nicepay':
$pg = 'NICEPAY';
break;
default:
$pg = 'KCP';
break;
@@ -127,7 +136,7 @@ $colspan = 10;
<td class="td_center"><?php echo get_text($data['od_tel']); ?></td>
<td class="td_name"><?php echo get_text($data['od_b_name']); ?></td>
<td class="td_price"><?php echo number_format($ct['price']); ?></td>
<td class="td_center"><?php echo $data['od_settle_case']; ?></td>
<td class="td_center"><?php echo get_text($data['od_settle_case']); ?></td>
<td class="td_time"><?php echo $row['dt_time']; ?></td>
<td class="td_mng td_mng_m">
<a href="./inorderform.php?od_id=<?php echo $row['od_id']; ?>&amp;<?php echo $qstr; ?>" class="btn btn_03"><span class="sound_only"><?php echo $row['od_id']; ?> </span>보기</a>
+3 -1
View File
@@ -67,7 +67,9 @@ for ($i=0; $row=sql_fetch_array($result); $i++)
for ($i=0; $i<$len; $i++)
$nbsp .= "&nbsp;&nbsp;&nbsp;";
$category_select .= "<option value=\"{$row['ca_id']}\">$nbsp{$row['ca_name']}</option>\n";
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row['ca_id']) : $row['ca_name'];
$category_select .= "<option value=\"{$row['ca_id']}\">$nbsp{$category_path}</option>\n";
}
// 모바일 1줄당 이미지수 필드 추가
+2 -2
View File
@@ -33,7 +33,7 @@ $ev_mobile_list_row = isset($_POST['ev_mobile_list_row']) ? (int) $_POST['ev_mob
$ev_use = isset($_POST['ev_use']) ? (int) $_POST['ev_use'] : 0;
$ev_subject_strong = isset($_POST['ev_subject_strong']) ? (int) $_POST['ev_subject_strong'] : 0;
$ev_subject = isset($_POST['ev_subject']) ? clean_xss_tags($_POST['ev_subject'], 1, 1) : '';
$ev_subject = isset($_POST['ev_subject']) ? addslashes(clean_xss_tags(stripslashes($_POST['ev_subject']), 1, 1)) : '';
$ev_head_html = isset($_POST['ev_head_html']) ? $_POST['ev_head_html'] : '';
$ev_tail_html = isset($_POST['ev_tail_html']) ? $_POST['ev_tail_html'] : '';
@@ -129,4 +129,4 @@ if ($w == "" || $w == "u")
else
{
goto_url("./itemevent.php");
}
}
+3 -1
View File
@@ -107,7 +107,9 @@ if($ev_id) {
$len = strlen($row1['ca_id']) / 2 - 1;
$nbsp = "";
for ($i=0; $i<$len; $i++) $nbsp .= "&nbsp;&nbsp;&nbsp;";
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
}
?>
</select>
+2
View File
@@ -6,6 +6,8 @@ check_demo();
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
$post_it_id_count = (isset($_POST['it_id']) && is_array($_POST['it_id'])) ? count($_POST['it_id']) : 0;
for ($i=0; $i<$post_it_id_count; $i++)
+2
View File
@@ -8,6 +8,8 @@ ini_set('memory_limit', '50M');
auth_check_menu($auth, $sub_menu, "w");
if (function_exists('check_request_origin')) check_request_origin(G5_ADMIN_URL);
function only_number($n)
{
return preg_replace('/[^0-9]/', '', (string)$n);
+10 -6
View File
@@ -105,7 +105,7 @@ else if ($w == "u")
and b.ca_mb_id = '{$member['mb_id']}' ";
$row = sql_fetch($sql);
if (!$row['it_id'])
alert("\'{$member['mb_id']}\' 님께서 수정 할 권한이 없는 상품입니다.");
alert("'{$member['mb_id']}' 님께서 수정 할 권한이 없는 상품입니다.");
}
$it = get_shop_item($it_id);
@@ -146,9 +146,11 @@ for ($i=0; $row=sql_fetch_array($result); $i++)
$nbsp = "";
for ($i=0; $i<$len; $i++)
$nbsp .= "&nbsp;&nbsp;&nbsp;";
$category_select .= "<option value=\"{$row['ca_id']}\">$nbsp{$row['ca_name']}</option>\n";
// 전체 카테고리 경로 표시 (예: 남성의류 > 상의 > 셔츠)
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row['ca_id']) : $row['ca_name'];
$category_select .= "<option value=\"{$row['ca_id']}\">$nbsp{$category_path}</option>\n";
$script .= "ca_use['{$row['ca_id']}'] = {$row['ca_use']};\n";
$script .= "ca_stock_qty['{$row['ca_id']}'] = {$row['ca_stock_qty']};\n";
//$script .= "ca_explan_html['$row[ca_id]'] = $row[ca_explan_html];\n";
@@ -1394,7 +1396,9 @@ $(function(){
for ($i=0; $i<$len; $i++)
$nbsp .= "&nbsp;&nbsp;&nbsp;";
echo "<option value=\"{$row['ca_id']}\">$nbsp{$row['ca_name']}</option>\n";
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row['ca_id']) : $row['ca_name'];
echo "<option value=\"{$row['ca_id']}\">$nbsp{$category_path}</option>\n";
}
?>
</select>
@@ -1897,4 +1901,4 @@ categorychange(document.fitemform);
</script>
<?php
include_once (G5_ADMIN_PATH.'/admin.tail.php');
include_once (G5_ADMIN_PATH.'/admin.tail.php');
+48 -8
View File
@@ -235,6 +235,14 @@ sql_query(" delete from {$g5['g5_shop_event_item_table']} where it_id = '$it_id'
// 선택옵션
sql_query(" delete from {$g5['g5_shop_item_option_table']} where io_type = '0' and it_id = '$it_id' "); // 기존선택옵션삭제
// 금지할 패턴 목록
$forbidden_patterns = array(
'/<\s*script/i', // <script>
'/<\s*iframe/i', // <iframe>
'/on\w+\s*=/i', // onclick=, onerror= 등 이벤트 핸들러
'/javascript:/i' // javascript: 프로토콜
);
$option_count = (isset($_POST['opt_id']) && is_array($_POST['opt_id'])) ? count($_POST['opt_id']) : array();
$it_option_subject = '';
$it_supply_subject = '';
@@ -243,8 +251,18 @@ if($option_count) {
// 옵션명
$opt1_cnt = $opt2_cnt = $opt3_cnt = 0;
for($i=0; $i<$option_count; $i++) {
$post_opt_id = isset($_POST['opt_id'][$i]) ? preg_replace(G5_OPTION_ID_FILTER, '', strip_tags($_POST['opt_id'][$i])) : '';
$post_opt_id = isset($_POST['opt_id'][$i]) ? $_POST['opt_id'][$i] : '';
foreach ($forbidden_patterns as $pattern) {
if (preg_match($pattern, $post_opt_id)) {
$post_opt_id = '';
$_POST['opt_id'][$i] = '';
continue 2;
}
}
$post_opt_id = preg_replace(G5_OPTION_ID_FILTER, '', strip_tags($post_opt_id));
$opt_val = explode(chr(30), $post_opt_id);
if(isset($opt_val[0]) && $opt_val[0])
$opt1_cnt++;
@@ -271,8 +289,18 @@ if($supply_count) {
// 추가옵션명
$arr_spl = array();
for($i=0; $i<$supply_count; $i++) {
$post_spl_id = isset($_POST['spl_id'][$i]) ? preg_replace(G5_OPTION_ID_FILTER, '', strip_tags($_POST['spl_id'][$i])) : '';
$post_spl_id = isset($_POST['spl_id'][$i]) ? $_POST['spl_id'][$i] : '';
foreach ($forbidden_patterns as $pattern) {
if (preg_match($pattern, $post_spl_id)) {
$post_spl_id = '';
$_POST['spl_id'][$i] = '';
continue 2;
}
}
$post_spl_id = preg_replace(G5_OPTION_ID_FILTER, '', strip_tags($post_spl_id));
$spl_val = explode(chr(30), $post_spl_id);
if(!in_array($spl_val[0], $arr_spl))
$arr_spl[] = $spl_val[0];
@@ -291,7 +319,7 @@ for($i=0; $i<$count_ii_article; $i++) {
}
$it_info_value = addslashes(serialize($value_array));
$it_name = isset($_POST['it_name']) ? strip_tags(clean_xss_attributes(trim($_POST['it_name']))) : '';
$it_name = isset($_POST['it_name']) ? addslashes(strip_tags(clean_xss_attributes(trim(stripslashes($_POST['it_name']))))) : '';
// KVE-2019-0708
$check_sanitize_keys = array(
@@ -328,7 +356,7 @@ $check_sanitize_keys = array(
);
foreach( $check_sanitize_keys as $key ){
$$key = isset($_POST[$key]) ? strip_tags(clean_xss_attributes($_POST[$key])) : '';
$$key = isset($_POST[$key]) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST[$key])))) : '';
}
$it_basic = preg_replace('#<script(.*?)>(.*?)<\/script>#is', '', $it_basic);
@@ -337,6 +365,18 @@ $it_explan = isset($_POST['it_explan']) ? $_POST['it_explan'] : '';
if ($it_name == "")
alert("상품명을 입력해 주십시오.");
// 상품 스킨은 파일 경로가 아니라 스킨 디렉토리명(basic, theme/basic 등)을 저장한다.
$it_skin = isset($_POST['it_skin']) ? trim(strip_tags(clean_xss_attributes(stripslashes($_POST['it_skin'])))) : '';
$it_mobile_skin = isset($_POST['it_mobile_skin']) ? trim(strip_tags(clean_xss_attributes(stripslashes($_POST['it_mobile_skin'])))) : '';
if (function_exists('check_shop_skin_dir')) {
check_shop_skin_dir($it_skin, 'PC용 스킨');
check_shop_skin_dir($it_mobile_skin, '모바일용 스킨', true);
}
$it_skin = addslashes($it_skin);
$it_mobile_skin = addslashes($it_mobile_skin);
$sql_common = " ca_id = '$ca_id',
ca_id2 = '$ca_id2',
ca_id3 = '$ca_id3',
@@ -356,7 +396,7 @@ $sql_common = " ca_id = '$ca_id',
it_type5 = '$it_type5',
it_basic = '$it_basic',
it_explan = '$it_explan',
it_explan2 = '".strip_tags(trim(clean_xss_attributes($it_explan)))."',
it_explan2 = '".addslashes(strip_tags(trim(clean_xss_attributes(stripslashes($it_explan)))))."',
it_mobile_explan = '$it_mobile_explan',
it_cust_price = '$it_cust_price',
it_price = '$it_price',
@@ -459,7 +499,7 @@ else if ($w == "d")
and b.ca_mb_id = '{$member['mb_id']}' ";
$row = sql_fetch($sql);
if (!$row['it_id'])
alert("\'{$member['mb_id']}\' 님께서 삭제 할 권한이 없는 상품입니다.");
alert("'{$member['mb_id']}' 님께서 삭제 할 권한이 없는 상품입니다.");
}
itemdelete($it_id);
+8 -2
View File
@@ -25,7 +25,8 @@ for ($i=0; $row=sql_fetch_array($result); $i++)
for ($i=0; $i<$len; $i++) {
$nbsp .= '&nbsp;&nbsp;&nbsp;';
}
$ca_list .= '<option value="'.$row['ca_id'].'">'.$nbsp.$row['ca_name'].'</option>'.PHP_EOL;
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row['ca_id']) : $row['ca_name'];
$ca_list .= '<option value="'.$row['ca_id'].'">'.$nbsp.$category_path.'</option>'.PHP_EOL;
}
$where = " and ";
@@ -67,6 +68,9 @@ if (!$sst) {
$sst = "it_id";
$sod = "desc";
}
$allowed_sst = array('it_id', 'it_name', 'it_order', 'it_use', 'it_soldout', 'it_hit', 'it_price', 'it_cust_price', 'it_point', 'it_stock_qty');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'it_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = "order by $sst $sod";
@@ -100,7 +104,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
$len = strlen($row1['ca_id']) / 2 - 1;
$nbsp = '';
for ($i=0; $i<$len; $i++) $nbsp .= '&nbsp;&nbsp;&nbsp;';
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sca, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sca, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
}
?>
</select>
+9 -4
View File
@@ -29,17 +29,22 @@ if ($post_act_button == "선택수정") {
$p_ca_id = (isset($_POST['ca_id']) && is_array($_POST['ca_id'])) ? strip_tags($_POST['ca_id'][$k]) : '';
$p_ca_id2 = (isset($_POST['ca_id2']) && is_array($_POST['ca_id2'])) ? strip_tags($_POST['ca_id2'][$k]) : '';
$p_ca_id3 = (isset($_POST['ca_id3']) && is_array($_POST['ca_id3'])) ? strip_tags($_POST['ca_id3'][$k]) : '';
$p_it_name = (isset($_POST['it_name']) && is_array($_POST['it_name'])) ? strip_tags(clean_xss_attributes($_POST['it_name'][$k])) : '';
$p_it_name = (isset($_POST['it_name']) && is_array($_POST['it_name'])) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['it_name'][$k])))) : '';
$p_it_cust_price = (isset($_POST['it_cust_price']) && is_array($_POST['it_cust_price'])) ? strip_tags($_POST['it_cust_price'][$k]) : '';
$p_it_price = (isset($_POST['it_price']) && is_array($_POST['it_price'])) ? strip_tags($_POST['it_price'][$k]) : '';
$p_it_stock_qty = (isset($_POST['it_stock_qty']) && is_array($_POST['it_stock_qty'])) ? strip_tags($_POST['it_stock_qty'][$k]) : '';
$p_it_skin = (isset($_POST['it_skin']) && is_array($_POST['it_skin'])) ? strip_tags($_POST['it_skin'][$k]) : '';
$p_it_mobile_skin = (isset($_POST['it_mobile_skin']) && is_array($_POST['it_mobile_skin'])) ? strip_tags($_POST['it_mobile_skin'][$k]) : '';
$p_it_skin = (isset($_POST['it_skin']) && is_array($_POST['it_skin'])) ? trim(strip_tags(clean_xss_attributes(stripslashes($_POST['it_skin'][$k])))) : '';
$p_it_mobile_skin = (isset($_POST['it_mobile_skin']) && is_array($_POST['it_mobile_skin'])) ? trim(strip_tags(clean_xss_attributes(stripslashes($_POST['it_mobile_skin'][$k])))) : '';
$p_it_use = isset($_POST['it_use'][$k]) ? clean_xss_tags($_POST['it_use'][$k], 1, 1) : 0;
$p_it_soldout = isset($_POST['it_soldout'][$k]) ? clean_xss_tags($_POST['it_soldout'][$k], 1, 1) : 0;
$p_it_order = (isset($_POST['it_order']) && is_array($_POST['it_order'])) ? strip_tags($_POST['it_order'][$k]) : '';
$p_it_id = isset($_POST['it_id'][$k]) ? preg_replace('/[^a-z0-9_\-]/i', '', $_POST['it_id'][$k]) : '';
if (function_exists('check_shop_skin_dir')) {
check_shop_skin_dir($p_it_skin, 'PC용 스킨');
check_shop_skin_dir($p_it_mobile_skin, '모바일용 스킨', true);
}
if ($is_admin != 'super') { // 최고관리자가 아니면 체크
$sql = "select a.it_id, b.ca_mb_id from {$g5['g5_shop_item_table']} a , {$g5['g5_shop_category_table']} b where (a.ca_id = b.ca_id) and a.it_id = '$p_it_id'";
$checks = sql_fetch($sql);
@@ -89,4 +94,4 @@ if ($post_act_button == "선택수정") {
}
}
goto_url("./itemlist.php?sca=$sca&amp;sst=$sst&amp;sod=$sod&amp;sfl=$sfl&amp;stx=$stx&amp;page=$page");
goto_url("./itemlist.php?sca=$sca&amp;sst=$sst&amp;sod=$sod&amp;sfl=$sfl&amp;stx=$stx&amp;page=$page");
+2 -2
View File
@@ -84,11 +84,11 @@ if($po_run) {
?>
<tr>
<td class="td_chk">
<input type="hidden" name="opt_id[]" value="<?php echo $opt_id; ?>">
<input type="hidden" name="opt_id[]" value="<?php echo get_text($opt_id); ?>">
<label for="opt_chk_<?php echo $i; ?>" class="sound_only"></label>
<input type="checkbox" name="opt_chk[]" id="opt_chk_<?php echo $i; ?>" value="1">
</td>
<td class="opt-cell"><?php echo $opt_1; if ($opt_2_len) echo ' <small>&gt;</small> '.$opt_2; if ($opt_3_len) echo ' <small>&gt;</small> '.$opt_3; ?></td>
<td class="opt-cell"><?php echo get_text($opt_1); if ($opt_2_len) echo ' <small>&gt;</small> '.get_text($opt_2); if ($opt_3_len) echo ' <small>&gt;</small> '.get_text($opt_3); ?></td>
<td class="td_numsmall">
<label for="opt_price_<?php echo $i; ?>" class="sound_only"></label>
<input type="text" name="opt_price[]" value="<?php echo $opt_price; ?>" id="opt_price_<?php echo $i; ?>" class="frm_input" size="9">
+6 -1
View File
@@ -31,6 +31,9 @@ if (!$sst) {
$sst = "iq_id";
$sod = "desc";
}
$allowed_sst = array('iq_id', 'a.it_id', 'it_name', 'iq_time');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'iq_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_common = " from {$g5['g5_shop_item_qa_table']} a
left join {$g5['g5_shop_item_table']} b on (a.it_id = b.it_id)
@@ -79,7 +82,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
$nbsp = "";
for ($i=0; $i<$len; $i++) $nbsp .= "&nbsp;&nbsp;&nbsp;";
$selected = ($row1['ca_id'] == $sca) ? ' selected="selected"' : '';
echo '<option value="'.$row1['ca_id'].'"'.$selected.'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
echo '<option value="'.$row1['ca_id'].'"'.$selected.'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
}
?>
</select>
+7 -5
View File
@@ -68,10 +68,10 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
</div>
<form name="flist" class="local_sch01 local_sch">
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
<input type="hidden" name="page" value="<?php echo $page; ?>">
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
<label for="sel_ca_id" class="sound_only">검색대상</label>
<select name="sel_ca_id" id="sel_ca_id">
@@ -83,7 +83,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
$len = strlen($row1['ca_id']) / 2 - 1;
$nbsp = "";
for ($i=0; $i<$len; $i++) $nbsp .= "&nbsp;&nbsp;&nbsp;";
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
}
?>
</select>
+7 -5
View File
@@ -67,10 +67,10 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
</div>
<form name="flist" class="local_sch01 local_sch">
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
<input type="hidden" name="page" value="<?php echo $page; ?>">
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
<label for="sel_ca_id" class="sound_only">분류선택</label>
<select name="sel_ca_id" id="sel_ca_id">
@@ -82,7 +82,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
$len = strlen($row1['ca_id']) / 2 - 1;
$nbsp = "";
for ($i=0; $i<$len; $i++) $nbsp .= "&nbsp;&nbsp;&nbsp;";
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
}
?>
</select>
+13 -10
View File
@@ -74,10 +74,10 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
</div>
<form name="flist" class="local_sch01 local_sch">
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
<input type="hidden" name="page" value="<?php echo $page; ?>">
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
<label for="sel_field" class="sound_only">검색대상</label>
<select name="sel_field" id="sel_field">
@@ -170,13 +170,16 @@ function fitemstocksms_submit(f)
return false;
}
if(document.pressed == "선택삭제") {
if(!confirm("선택한 자료를 정말 삭제하시겠습니까?")) {
return false;
}
}
var action = document.pressed;
return true;
switch (action) {
case "선택삭제":
return confirm("선택한 자료를 정말 삭제하시겠습니까?");
case "선택SMS전송":
return confirm("선택한 자료에 대해서 SMS로 재입고 알림을 전송하시겠습니까?");
default:
return true;
}
}
</script>
+4 -4
View File
@@ -55,12 +55,12 @@ if($ps_run) {
?>
<tr>
<td class="td_chk">
<input type="hidden" name="spl_id[]" value="<?php echo $spl_id; ?>">
<label for="spl_chk_<?php echo $i; ?>" class="sound_only"><?php echo $spl_subject.' '.$spl; ?></label>
<input type="hidden" name="spl_id[]" value="<?php echo get_text($spl_id); ?>">
<label for="spl_chk_<?php echo $i; ?>" class="sound_only"><?php echo get_text($spl_subject.' '.$spl); ?></label>
<input type="checkbox" name="spl_chk[]" id="spl_chk_<?php echo $i; ?>" value="1">
</td>
<td class="spl-subject-cell"><?php echo $spl_subject; ?></td>
<td class="spl-cell"><?php echo $spl; ?></td>
<td class="spl-subject-cell"><?php echo get_text($spl_subject); ?></td>
<td class="spl-cell"><?php echo get_text($spl); ?></td>
<td class="td_numsmall">
<label for="spl_price_<?php echo $i; ?>" class="sound_only">상품금액</label>
<input type="text" name="spl_price[]" value="<?php echo $spl_price; ?>" id="spl_price_<?php echo $i; ?>" class="frm_input" size="5">
+8 -3
View File
@@ -46,6 +46,9 @@ if (!$sst) {
$sst = "it_id";
$sod = "desc";
}
$allowed_sst = array('it_id', 'it_name', 'it_type1', 'it_type2', 'it_type3', 'it_type4', 'it_type5', 'ca_id');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'it_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_order = "order by $sst $sod";
$sql_common = " from {$g5['g5_shop_item_table']} ";
@@ -85,8 +88,8 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
</div>
<form name="flist" class="local_sch01 local_sch">
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
<input type="hidden" name="page" value="<?php echo $page; ?>">
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
<label for="sca" class="sound_only">분류선택</label>
<select name="sca" id="sca">
@@ -98,7 +101,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
$len = strlen($row1['ca_id']) / 2 - 1;
$nbsp = "";
for ($i=0; $i<$len; $i++) $nbsp .= "&nbsp;&nbsp;&nbsp;";
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sca, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].PHP_EOL;
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sca, $row1['ca_id']).'>'.$nbsp.$category_path.PHP_EOL;
}
?>
</select>
+4 -2
View File
@@ -18,8 +18,10 @@ foreach($check_keys as $key){
if( in_array($key, array('is_content', 'is_reply_content')) ){
$posts[$key] = isset($_POST[$key]) ? $_POST[$key] : '';
} else if( $key === 'is_id' ) {
$posts[$key] = isset($_POST[$key]) ? (int) $_POST[$key] : 0;
} else {
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
}
}
@@ -46,4 +48,4 @@ if ($w == "u")
else
{
alert();
}
}
+6 -1
View File
@@ -33,6 +33,9 @@ if (!$sst) {
$sst = "is_id";
$sod = "desc";
}
$allowed_sst = array('is_id', 'a.it_id', 'it_name', 'is_name', 'is_score', 'is_time');
if ($sst && !in_array($sst, $allowed_sst)) $sst = 'is_id';
if ($sod && !in_array(strtolower($sod), array('asc', 'desc'))) $sod = '';
$sql_common = " from {$g5['g5_shop_item_use_table']} a
left join {$g5['g5_shop_item_table']} b on (a.it_id = b.it_id)
@@ -81,7 +84,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
$nbsp = "";
for ($i=0; $i<$len; $i++) $nbsp .= "&nbsp;&nbsp;&nbsp;";
$selected = ($row1['ca_id'] == $sca) ? ' selected="selected"' : '';
echo '<option value="'.$row1['ca_id'].'"'.$selected.'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
echo '<option value="'.$row1['ca_id'].'"'.$selected.'>'.$nbsp.$category_path.PHP_EOL;
}
?>
</select>
+7 -5
View File
@@ -69,10 +69,10 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
</div>
<form name="flist" class="local_sch01 local_sch">
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
<input type="hidden" name="page" value="<?php echo $page; ?>">
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
<label for="sel_ca_id" class="sound_only">분류선택</label>
<select name="sel_ca_id" id="sel_ca_id">
@@ -84,7 +84,9 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
$len = strlen($row1['ca_id']) / 2 - 1;
$nbsp = "";
for ($i=0; $i<$len; $i++) $nbsp .= "&nbsp;&nbsp;&nbsp;";
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$row1['ca_name'].'</option>'.PHP_EOL;
// 전체 카테고리 경로 표시
$category_path = function_exists('get_shop_category_path') ? get_shop_category_path($row1['ca_id']) : $row1['ca_name'];
echo '<option value="'.$row1['ca_id'].'" '.get_selected($sel_ca_id, $row1['ca_id']).'>'.$nbsp.$category_path.'</option>'.PHP_EOL;
}
?>
</select>
+11 -11
View File
@@ -30,17 +30,17 @@ if(! function_exists('column_char')) {
$rows = array();
for($i=1; $row=sql_fetch_array($result); $i++) {
$rows[] =
array(' '.$row['od_id'],
$row['od_name'],
' '.$row['od_tel'],
' '.$row['od_hp'],
$row['od_b_name'],
' '.$row['od_b_tel'],
' '.$row['od_b_hp'],
print_address($row['od_b_addr1'], $row['od_b_addr2'], $row['od_b_addr3'], $row['od_b_addr_jibeon']),
$row['od_delivery_company'],
$row['od_invoice']);
$rows[] =
array(' '.$row['od_id'],
function_exists('csv_safe_cell') ? csv_safe_cell($row['od_name']) : $row['od_name'],
' '.$row['od_tel'],
' '.$row['od_hp'],
function_exists('csv_safe_cell') ? csv_safe_cell($row['od_b_name']) : $row['od_b_name'],
' '.$row['od_b_tel'],
' '.$row['od_b_hp'],
function_exists('csv_safe_cell') ? csv_safe_cell(print_address($row['od_b_addr1'], $row['od_b_addr2'], $row['od_b_addr3'], $row['od_b_addr_jibeon'])) : print_address($row['od_b_addr1'], $row['od_b_addr2'], $row['od_b_addr3'], $row['od_b_addr_jibeon']),
function_exists('csv_safe_cell') ? csv_safe_cell($row['od_delivery_company']) : $row['od_delivery_company'],
function_exists('csv_safe_cell') ? csv_safe_cell($row['od_invoice']) : $row['od_invoice']);
}
$data = array_merge(array($headers), $rows);
+2
View File
@@ -6,6 +6,8 @@ include_once(G5_LIB_PATH.'/mailer.lib.php');
auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
define("_ORDERMAIL_", true);
$sms_count = 0;
+27 -19
View File
@@ -382,8 +382,8 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<input type="hidden" name="sel_field" value="<?php echo $sel_field; ?>">
<input type="hidden" name="search" value="<?php echo $search; ?>">
<input type="hidden" name="page" value="<?php echo $page; ?>">
<input type="hidden" name="od_name" value="<?php echo $od['od_name']; ?>">
<input type="hidden" name="od_hp" value="<?php echo $od['od_hp']; ?>">
<input type="hidden" name="od_name" value="<?php echo get_text($od['od_name']); ?>">
<input type="hidden" name="od_hp" value="<?php echo get_text($od['od_hp']); ?>">
<input type="hidden" name="od_tno" value="<?php echo $od['od_tno']; ?>">
<input type="hidden" name="od_escrow" value="<?php echo $od['od_escrow']; ?>">
<input type="hidden" name="od_pg" value="<?php echo $od['od_pg']; ?>">
@@ -509,35 +509,33 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<?php
if ($od['od_settle_case'] != '무통장') {
switch($od['od_pg']) {
case 'lg':
$pg_url = 'https://app.tosspayments.com';
$pg_test = '토스페이먼츠';
if ($default['de_card_test']) {
$pg_url = 'https://pgweb.tosspayments.com/tmert';
$pg_test .= ' 테스트 ';
}
break;
case 'inicis':
$pg_url = 'https://iniweb.inicis.com/';
$pg_test = 'KG이니시스';
$pg_test = 'KG이니시스 ';
break;
case 'KAKAOPAY':
$pg_url = 'https://mms.cnspay.co.kr';
$pg_test = 'KAKAOPAY';
$pg_test = 'KAKAOPAY ';
break;
case 'nicepay':
$pg_url = 'https://npg.nicepay.co.kr/';
$pg_test = 'NICEPAY';
$pg_test = 'NICEPAY ';
break;
case 'lg':
case 'toss':
$pg_url = 'https://app.tosspayments.com';
$pg_test = '토스페이먼츠 ';
// 상점관리자 로그인 후 상단 '테스트 모드' 활성화 시 테스트 화면 노출
break;
default:
$pg_url = 'http://admin8.kcp.co.kr';
$pg_test = 'KCP';
$pg_url = 'https://partner.kcp.co.kr';
$pg_test = 'KCP ';
if ($default['de_card_test']) {
// 로그인 아이디 / 비번
// 일반 : test1234 / test12345
// 에스크로 : escrow / escrow913
$pg_url = 'http://testadmin8.kcp.co.kr';
$pg_test .= ' 테스트 ';
$pg_url = 'https://testpartner.kcp.co.kr';
$pg_test .= '테스트 ';
}
}
@@ -630,6 +628,8 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
break;
}
$cash_receipt_script = 'javascript:showCashReceipts(\''.$LGD_MID.'\',\''.$od['od_id'].'\',\''.$od['od_casseqno'].'\',\''.$trade_type.'\',\''.$CST_PLATFORM.'\');';
} else if($od['od_pg'] == 'toss') {
$cash_receipt_script = 'window.open(\'https://dashboard.tosspayments.com/receipt/mids/si_'.$config['cf_lg_mid'].'/orders/'.$od['od_id'].'/cash-receipt?ref=dashboard\',\'receipt\',\'width=430,height=700\');';
} else if($od['od_pg'] == 'inicis') {
$cash = unserialize($od['od_cash_info']);
$cash_receipt_script = 'window.open(\'https://iniweb.inicis.com/DefaultWebApp/mall/cr/cm/Cash_mCmReceipt.jsp?noTid='.$cash['TID'].'&clpaymethod=22\',\'showreceipt\',\'width=380,height=540,scrollbars=no,resizable=no\');';
@@ -719,6 +719,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<label for="od_sms_ipgum_check">SMS 입금 문자전송</label>
<br>
<?php } ?>
<input type="text" name="od_deposit_name" value="<?php echo get_text($od['od_deposit_name']); ?>" id="od_deposit_name" class="frm_input">
</td>
</tr>
@@ -826,6 +827,7 @@ add_javascript(G5_POSTCODE_JS, 0); //다음 주소 js
<label for="od_sms_baesong_check">SMS 배송 문자전송</label>
<br>
<?php } ?>
<input type="text" name="od_invoice" value="<?php echo $od['od_invoice']; ?>" id="od_invoice" class="frm_input">
</td>
</tr>
@@ -1108,7 +1110,13 @@ function form_submit(f)
var cancel_pg = "PG사의 <?php echo $od['od_settle_case']; ?>";
<?php } ?>
if(chk_cnt == chked_cnt) {
// 체크하지 않은 나머지 품목이 모두 취소류 상태이면 이번 처리로 주문 전체가 취소된다.
var remain_active_cnt = $ct_chk.not(":checked").filter(function() {
var row_status = $.trim($(this).closest("tr").find("td.td_mngsmall").first().text());
return row_status != "취소" && row_status != "반품" && row_status != "품절";
}).length;
if(chked_cnt > 0 && remain_active_cnt == 0) {
if(confirm(cancel_pg+" 결제를 함께 취소하시겠습니까?\n\n한번 취소한 결제는 다시 복구할 수 없습니다.")) {
f.pg_cancel.value = 1;
msg = cancel_pg+" 결제 취소와 함께 ";
@@ -1162,4 +1170,4 @@ function chk_receipt_price()
</script>
<?php
include_once(G5_ADMIN_PATH.'/admin.tail.php');
include_once(G5_ADMIN_PATH.'/admin.tail.php');
+147 -9
View File
@@ -19,6 +19,133 @@ if (in_array($_POST['ct_status'], $status_normal) || in_array($_POST['ct_status'
alert('변경할 상태가 올바르지 않습니다.');
}
// INIpay PRO 전체취소는 로컬 상품상태를 바꾸기 전에 PG 취소를 먼저 확정한다.
// PG 취소 실패 후에도 주문만 취소되어 가상계좌 입금이 남는 상태를 방지한다.
$inicis_pro_cancel_preprocessed = false;
$inicis_pro_order_lock = '';
if (in_array($_POST['ct_status'], $status_cancel)) {
$selected_ct_ids = array();
$posted_ct_count = isset($_POST['ct_id']) && is_array($_POST['ct_id']) ? count($_POST['ct_id']) : 0;
for ($pre_i = 0; $pre_i < $posted_ct_count; $pre_i++) {
$pre_k = isset($_POST['ct_chk'][$pre_i]) ? (int) $_POST['ct_chk'][$pre_i] : -1;
if ($pre_k < 0 || !isset($_POST['ct_id'][$pre_k]))
continue;
$pre_ct_id = (int) $_POST['ct_id'][$pre_k];
if ($pre_ct_id > 0)
$selected_ct_ids[$pre_ct_id] = $pre_ct_id;
}
if (count($selected_ct_ids)) {
$selected_ct_sql = implode(',', array_values($selected_ct_ids));
$future = sql_fetch(" select count(*) as total_count,
sum(if(ct_status in ('취소','반품','품절') or ct_id in ($selected_ct_sql), 1, 0)) as cancel_count
from {$g5['g5_shop_cart_table']}
where od_id = '".sql_escape_string($od_id)."' ");
if ((int) $future['total_count'] > 0 && (int) $future['total_count'] === (int) $future['cancel_count']) {
$pre_od = sql_fetch(" select * from {$g5['g5_shop_order_table']} where od_id = '".sql_escape_string($od_id)."' ");
if (!empty($pre_od['od_tno']) && $pre_od['od_pg'] === 'inicis') {
include_once(G5_SHOP_PATH.'/inicis/pro/inicis_pro.lib.php');
$pro_tables = inicis_pro_audit_tables();
$pro_summary = sql_fetch(" select * from `{$pro_tables['summary']}`
where ip_oid = '".sql_escape_string($pre_od['od_id'])."'
and ip_tid = '".sql_escape_string($pre_od['od_tno'])."' ", false);
if (!empty($pro_summary['ip_id'])) {
$inicis_pro_order_lock = inicis_pro_lock($pre_od['od_id']);
if ($inicis_pro_order_lock === '')
alert('동일 주문의 결제 또는 통보 처리가 진행 중입니다. 잠시 후 다시 취소해 주십시오.');
// KG이니시스 상점관리자에서 이미 취소한 거래이면 PG 취소 없이 주문 취소만 진행한다.
$pre_inquiry = inicis_pro_inquiry($pre_od['od_tno'], $pre_od['od_id'], $pro_summary);
$pre_inquiry_data = isset($pre_inquiry['data']) && is_array($pre_inquiry['data']) ? $pre_inquiry['data'] : array();
$pre_pg_status = isset($pre_inquiry_data['status']) ? strtoupper(preg_replace('/[^A-Za-z0-9_]/', '', (string) $pre_inquiry_data['status'])) : '';
if (!empty($pre_inquiry['success']) && in_array($pre_pg_status, array('1', 'C', 'CANCEL', 'DEPOSIT_CANCELED', 'REFUND_COMPLETED'))) {
inicis_pro_save_inquiry($pre_od['od_id'], $pre_inquiry, 'admin');
inicis_pro_audit_write($pre_od['od_id'], 'cancel', 'canceled', array(
'tid' => $pre_od['od_tno'],
'mid' => $pro_summary['ip_mid'],
'amount' => isset($pro_summary['ip_amount']) ? (int) $pro_summary['ip_amount'] : 0,
'pay_type' => isset($pro_summary['ip_pay_type']) ? $pro_summary['ip_pay_type'] : '',
'source' => 'admin',
'code' => $pre_pg_status,
'message' => 'KG이니시스에서 이미 취소된 거래로 확인되어 주문 취소만 진행합니다.'
));
$inicis_pro_cancel_preprocessed = true;
} else {
$pre_refunded = (int) $pre_od['od_refund_price'];
$pre_remaining = (int) $pre_od['od_receipt_price'] - $pre_refunded;
if ($pre_refunded > 0 && $pre_remaining <= 0) {
// 이전 부분취소로 결제금액이 모두 환불된 주문은 PG 취소 없이 주문 취소만 진행한다.
inicis_pro_audit_write($pre_od['od_id'], 'cancel', 'canceled', array(
'tid' => $pre_od['od_tno'],
'mid' => $pro_summary['ip_mid'],
'amount' => isset($pro_summary['ip_amount']) ? (int) $pro_summary['ip_amount'] : 0,
'pay_type' => isset($pro_summary['ip_pay_type']) ? $pro_summary['ip_pay_type'] : '',
'source' => 'admin',
'message' => '이전 부분취소로 결제금액이 모두 환불되어 주문 취소만 진행합니다.'
));
$inicis_pro_cancel_preprocessed = true;
} elseif (!isset($_POST['pg_cancel']) || (int) $_POST['pg_cancel'] !== 1) {
// PG 승인취소 없이 주문만 취소하는 선택을 이력에 남긴다. 결제는 KG이니시스에 승인 상태로 남는다.
inicis_pro_audit_write($pre_od['od_id'], 'cancel', 'canceled', array(
'tid' => $pre_od['od_tno'],
'mid' => $pro_summary['ip_mid'],
'amount' => isset($pro_summary['ip_amount']) ? (int) $pro_summary['ip_amount'] : 0,
'pay_type' => isset($pro_summary['ip_pay_type']) ? $pro_summary['ip_pay_type'] : '',
'source' => 'admin',
'message' => 'PG 승인취소 없이 주문만 취소했습니다. 결제는 KG이니시스에 남아 있습니다.',
'event_only' => '1'
));
} else {
$pro_environment = !empty($pro_summary['ip_environment']) ? $pro_summary['ip_environment'] : inicis_pro_environment();
if ($pro_summary['ip_mid'] !== inicis_pro_get_mid(!empty($pro_summary['ip_pay_type']) ? $pro_summary['ip_pay_type'] : null) || $pro_environment !== inicis_pro_environment())
alert('거래 당시 MID 또는 결제환경과 현재 설정이 달라 PG 취소를 실행할 수 없습니다. KG이니시스 상점관리자에서 원거래를 확인해 주십시오.');
include_once(G5_SHOP_PATH.'/settle_inicis.inc.php');
$pre_cancel_args = array(
'paymethod' => get_type_inicis_paymethod($pre_od['od_settle_case']),
'tid' => $pre_od['od_tno'],
'mid' => $pro_summary['ip_mid'],
'audit_oid' => $pre_od['od_id'],
'audit_source' => 'admin',
'msg' => '쇼핑몰 운영자 승인 취소',
'url' => $pro_environment === 'test' ? 'https://stginiapi.inicis.com/api/v1/refund' : 'https://iniapi.inicis.com/api/v1/refund'
);
// 부분취소 이력이 있는 거래는 전체취소 요청이 거부되므로 잔여 금액을 부분취소로 처리한다.
$pre_cancel_is_part = $pre_refunded > 0 && $pre_remaining > 0;
if ($pre_cancel_is_part) {
$pre_cancel_args['msg'] = '쇼핑몰 운영자 승인 취소(잔여금액)';
$pre_cancel_args['price'] = $pre_remaining;
$pre_cancel_args['confirmPrice'] = 0;
}
$pre_cancel_response = inicis_tid_cancel($pre_cancel_args, $pre_cancel_is_part);
$pre_cancel_result = json_decode($pre_cancel_response, true);
if (!isset($pre_cancel_result['resultCode']) || $pre_cancel_result['resultCode'] !== '00') {
$pre_cancel_code = !empty($pre_cancel_result['resultCode']) ? $pre_cancel_result['resultCode'] : 'COMMUNICATION_FAILED';
$pre_cancel_message = !empty($pre_cancel_result['resultMsg']) ? $pre_cancel_result['resultMsg'] : 'KG이니시스 취소 응답을 확인하지 못했습니다.';
alert($pre_cancel_message.' 코드 : '.$pre_cancel_code);
}
if ($pre_cancel_is_part) {
inicis_pro_audit_write($pre_od['od_id'], 'cancel', 'canceled', array(
'tid' => $pre_od['od_tno'],
'mid' => $pro_summary['ip_mid'],
'amount' => isset($pro_summary['ip_amount']) ? (int) $pro_summary['ip_amount'] : 0,
'pay_type' => isset($pro_summary['ip_pay_type']) ? $pro_summary['ip_pay_type'] : '',
'source' => 'admin',
'code' => '00',
'message' => '잔여 금액 부분취소로 전체취소를 완료했습니다.'
));
}
$inicis_pro_cancel_preprocessed = true;
}
}
}
}
}
}
}
$search = isset($_REQUEST['search']) ? get_search_string($_REQUEST['search']) : '';
$sort1 = isset($_REQUEST['sort1']) ? clean_xss_tags($_REQUEST['sort1'], 1, 1) : '';
$sort2 = isset($_REQUEST['sort2']) ? clean_xss_tags($_REQUEST['sort2'], 1, 1) : '';
@@ -220,18 +347,26 @@ if (in_array($_POST['ct_status'], $status_cancel)) {
$pg_res_msg = $xpay->Response_Msg();
}
break;
case 'toss':
$cancel_msg = '쇼핑몰 운영자 승인 취소';
include_once(G5_SHOP_PATH.'/toss/toss_cancel.php');
break;
case 'inicis':
include_once(G5_SHOP_PATH.'/settle_inicis.inc.php');
$cancel_msg = '쇼핑몰 운영자 승인 취소';
$args = array(
'paymethod' => get_type_inicis_paymethod($od['od_settle_case']),
'tid' => $od['od_tno'],
'msg' => $cancel_msg
);
$response = inicis_tid_cancel($args);
$result = json_decode($response, true);
if ($inicis_pro_cancel_preprocessed) {
$result = array('resultCode' => '00', 'resultMsg' => 'INIpay PRO PG 취소 선처리 완료');
} else {
$args = array(
'paymethod' => get_type_inicis_paymethod($od['od_settle_case']),
'tid' => $od['od_tno'],
'msg' => $cancel_msg
);
$response = inicis_tid_cancel($args);
$result = json_decode($response, true);
}
if (isset($result['resultCode'])) {
if ($result['resultCode'] != '00') {
@@ -372,6 +507,9 @@ $qstr = "sort1=$sort1&amp;sort2=$sort2&amp;sel_field=$sel_field&amp;search=$sear
$url = "./orderform.php?od_id=$od_id&amp;$qstr";
if ($inicis_pro_order_lock !== '')
inicis_pro_unlock($inicis_pro_order_lock);
// 신용카드 취소 때 오류가 있으면 알림
if($pg_cancel == 1 && $pg_res_cd && $pg_res_msg) {
alert('오류코드 : '.$pg_res_cd.' 오류내용 : '.$pg_res_msg, $url);
@@ -382,4 +520,4 @@ if($pg_cancel == 1 && $pg_res_cd && $pg_res_msg) {
alert("포인트로 결제한 주문은,\\n\\n주문상태 변경으로 인해 포인트의 가감이 발생하는 경우\\n\\n회원관리 > 포인트관리에서 수작업으로 포인트를 맞추어 주셔야 합니다.", $url);
else
goto_url($url);
}
}
+2 -2
View File
@@ -35,7 +35,7 @@ $check_keys = array(
$posts = array();
foreach($check_keys as $key){
$posts[$key] = isset($_POST[$key]) ? clean_xss_tags($_POST[$key], 1, 1) : '';
$posts[$key] = isset($_POST[$key]) ? addslashes(clean_xss_tags(stripslashes($_POST[$key]), 1, 1)) : '';
}
$od_send_mail = $posts['od_send_mail'];
@@ -175,4 +175,4 @@ if($posts['od_tno'] && $posts['od_escrow'] == 1)
$qstr = "sort1=$sort1&amp;sort2=$sort2&amp;sel_field=$sel_field&amp;search=$search&amp;page=$page";
goto_url("./orderform.php?od_id=$od_id&amp;$qstr");
goto_url("./orderform.php?od_id=$od_id&amp;$qstr");
+20 -18
View File
@@ -2,9 +2,11 @@
$sub_menu = '400400';
include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
$od_shop_memo = isset($_POST['od_shop_memo']) ? strip_tags($_POST['od_shop_memo']) : '';
$od_shop_memo = isset($_POST['od_shop_memo']) ? addslashes(strip_tags(stripslashes($_POST['od_shop_memo']))) : '';
$od_id = isset($_POST['od_id']) ? safe_replace_regex($_POST['od_id'], 'od_id') : '';
$search = isset($_REQUEST['search']) ? get_search_string($_REQUEST['search']) : '';
@@ -17,22 +19,22 @@ if(isset($_POST['mod_type']) && $_POST['mod_type'] === 'info') {
$od_zip2 = isset($_POST['od_zip']) ? preg_replace('/[^0-9]/', '', substr($_POST['od_zip'], 3)) : '';
$od_b_zip1 = isset($_POST['od_b_zip']) ? preg_replace('/[^0-9]/', '', substr($_POST['od_b_zip'], 0, 3)) : '';
$od_b_zip2 = isset($_POST['od_b_zip']) ? preg_replace('/[^0-9]/', '', substr($_POST['od_b_zip'], 3)) : '';
$od_email = isset($_POST['od_email']) ? strip_tags(clean_xss_attributes($_POST['od_email'])) : '';
$od_name = isset($_POST['od_name']) ? clean_xss_tags($_POST['od_name'], 1, 1) : '';
$od_tel = isset($_POST['od_tel']) ? clean_xss_tags($_POST['od_tel'], 1, 1) : '';
$od_hp = isset($_POST['od_hp']) ? clean_xss_tags($_POST['od_hp'], 1, 1) : '';
$od_addr1 = isset($_POST['od_addr1']) ? clean_xss_tags($_POST['od_addr1'], 1, 1) : '';
$od_addr2 = isset($_POST['od_addr2']) ? clean_xss_tags($_POST['od_addr2'], 1, 1) : '';
$od_addr3 = isset($_POST['od_addr3']) ? clean_xss_tags($_POST['od_addr3'], 1, 1) : '';
$od_addr_jibeon = isset($_POST['od_addr_jibeon']) ? clean_xss_tags($_POST['od_addr_jibeon'], 1, 1) : '';
$od_b_name = isset($_POST['od_b_name']) ? clean_xss_tags($_POST['od_b_name'], 1, 1) : '';
$od_b_tel = isset($_POST['od_b_tel']) ? clean_xss_tags($_POST['od_b_tel'], 1, 1) : '';
$od_b_hp = isset($_POST['od_b_hp']) ? clean_xss_tags($_POST['od_b_hp'], 1, 1) : '';
$od_b_addr1 = isset($_POST['od_b_addr1']) ? clean_xss_tags($_POST['od_b_addr1'], 1, 1) : '';
$od_b_addr2 = isset($_POST['od_b_addr2']) ? clean_xss_tags($_POST['od_b_addr2'], 1, 1) : '';
$od_b_addr3 = isset($_POST['od_b_addr3']) ? clean_xss_tags($_POST['od_b_addr3'], 1, 1) : '';
$od_b_addr_jibeon = isset($_POST['od_b_addr_jibeon']) ? clean_xss_tags($_POST['od_b_addr_jibeon'], 1, 1) : '';
$od_hope_date = isset($_POST['od_hope_date']) ? clean_xss_tags($_POST['od_hope_date'], 1, 1) : '';
$od_email = isset($_POST['od_email']) ? addslashes(strip_tags(clean_xss_attributes(stripslashes($_POST['od_email'])))) : '';
$od_name = isset($_POST['od_name']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_name']), 1, 1)) : '';
$od_tel = isset($_POST['od_tel']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_tel']), 1, 1)) : '';
$od_hp = isset($_POST['od_hp']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_hp']), 1, 1)) : '';
$od_addr1 = isset($_POST['od_addr1']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_addr1']), 1, 1)) : '';
$od_addr2 = isset($_POST['od_addr2']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_addr2']), 1, 1)) : '';
$od_addr3 = isset($_POST['od_addr3']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_addr3']), 1, 1)) : '';
$od_addr_jibeon = isset($_POST['od_addr_jibeon']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_addr_jibeon']), 1, 1)) : '';
$od_b_name = isset($_POST['od_b_name']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_name']), 1, 1)) : '';
$od_b_tel = isset($_POST['od_b_tel']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_tel']), 1, 1)) : '';
$od_b_hp = isset($_POST['od_b_hp']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_hp']), 1, 1)) : '';
$od_b_addr1 = isset($_POST['od_b_addr1']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_addr1']), 1, 1)) : '';
$od_b_addr2 = isset($_POST['od_b_addr2']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_addr2']), 1, 1)) : '';
$od_b_addr3 = isset($_POST['od_b_addr3']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_addr3']), 1, 1)) : '';
$od_b_addr_jibeon = isset($_POST['od_b_addr_jibeon']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_b_addr_jibeon']), 1, 1)) : '';
$od_hope_date = isset($_POST['od_hope_date']) ? addslashes(clean_xss_tags(stripslashes($_POST['od_hope_date']), 1, 1)) : '';
$sql = " update {$g5['g5_shop_order_table']}
set od_name = '$od_name',
@@ -66,4 +68,4 @@ sql_query($sql);
$qstr = "sort1=$sort1&amp;sort2=$sort2&amp;sel_field=$sel_field&amp;search=$search&amp;page=$page";
goto_url("./orderform.php?od_id=$od_id&amp;$qstr");
goto_url("./orderform.php?od_id=$od_id&amp;$qstr");
+9 -8
View File
@@ -16,6 +16,7 @@ $sort2 = (isset($_GET['sort2']) && in_array($_GET['sort2'], array('desc', 'asc')
$sel_field = (isset($_GET['sel_field']) && in_array($_GET['sel_field'], array('od_id', 'mb_id', 'od_name', 'od_tel', 'od_hp', 'od_b_name', 'od_b_tel', 'od_b_hp', 'od_deposit_name', 'od_invoice')) ) ? $_GET['sel_field'] : '';
$od_status = isset($_GET['od_status']) ? get_search_string($_GET['od_status']) : '';
$search = isset($_GET['search']) ? get_search_string($_GET['search']) : '';
$save_search = isset($_GET['save_search']) ? get_search_string($_GET['save_search']) : '';
$fr_date = (isset($_GET['fr_date']) && preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $_GET['fr_date'])) ? $_GET['fr_date'] : '';
$to_date = (isset($_GET['to_date']) && preg_match("/^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[1-2][0-9]|3[0-1])$/", $_GET['to_date'])) ? $_GET['to_date'] : '';
@@ -25,8 +26,8 @@ $od_cancel_price = isset($_GET['od_cancel_price']) ? preg_replace('/[^0-9a-z]/i'
$od_refund_price = isset($_GET['od_refund_price']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_refund_price']) : '';
$od_receipt_point = isset($_GET['od_receipt_point']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_receipt_point']) : '';
$od_coupon = isset($_GET['od_coupon']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_coupon']) : '';
$od_settle_case = isset($_GET['od_settle_case']) ? clean_xss_tags($_GET['od_settle_case'], 1, 1) : '';
$od_escrow = isset($_GET['od_escrow']) ? clean_xss_tags($_GET['od_escrow'], 1, 1) : '';
$od_settle_case = isset($_GET['od_settle_case']) ? addslashes(clean_xss_tags(stripslashes($_GET['od_settle_case']), 1, 1)) : '';
$od_escrow = isset($_GET['od_escrow']) ? addslashes(clean_xss_tags(stripslashes($_GET['od_escrow']), 1, 1)) : '';
$tot_itemcount = $tot_orderprice = $tot_receiptprice = $tot_ordercancel = $tot_misu = $tot_couponprice = 0;
$sql_search = "";
@@ -160,11 +161,11 @@ if( function_exists('pg_setting_check') ){
</div>
<form name="frmorderlist" class="local_sch01 local_sch">
<input type="hidden" name="doc" value="<?php echo $doc; ?>">
<input type="hidden" name="sort1" value="<?php echo $sort1; ?>">
<input type="hidden" name="sort2" value="<?php echo $sort2; ?>">
<input type="hidden" name="page" value="<?php echo $page; ?>">
<input type="hidden" name="save_search" value="<?php echo $search; ?>">
<input type="hidden" name="doc" value="<?php echo get_sanitize_input($doc); ?>">
<input type="hidden" name="sort1" value="<?php echo get_sanitize_input($sort1); ?>">
<input type="hidden" name="sort2" value="<?php echo get_sanitize_input($sort2); ?>">
<input type="hidden" name="page" value="<?php echo get_sanitize_input($page); ?>">
<input type="hidden" name="save_search" value="<?php echo get_sanitize_input($search); ?>">
<label for="sel_field" class="sound_only">검색대상</label>
<select name="sel_field" id="sel_field">
@@ -349,7 +350,7 @@ if( function_exists('pg_setting_check') ){
if($default['de_escrow_use'] && $row['od_escrow'])
$od_paytype .= '<span class="list_escrow">에스크로</span>';
$uid = md5($row['od_id'].$row['od_time'].$row['od_ip']);
$uid = function_exists('get_shop_uid') ? get_shop_uid('order', $row['od_id'], $row['od_time'], $row['od_ip']) : md5($row['od_id'].$row['od_time'].$row['od_ip']);
$invoice_time = is_null_time($row['od_invoice_time']) ? G5_TIME_YMDHIS : $row['od_invoice_time'];
$delivery_company = $row['od_delivery_company'] ? $row['od_delivery_company'] : $default['de_delivery_company'];
+2
View File
@@ -4,6 +4,8 @@ include_once('./_common.php');
//print_r2($_POST); exit;
auth_check_menu($auth, $sub_menu, "d");
check_admin_token();
$count_post_chk = (isset($_POST['chk']) && is_array($_POST['chk'])) ? count($_POST['chk']) : 0;
+2
View File
@@ -4,6 +4,8 @@ include_once('./_common.php');
include_once('./admin.shop.lib.php');
include_once(G5_LIB_PATH.'/mailer.lib.php');
auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
define("_ORDERMAIL_", true);

Some files were not shown because too many files have changed in this diff Show More