com web/master: add profile field for user: fetch/user-profile.php include/functions.inc manage/users.php users.sql
| From: | Peter Cowburn | Date: | Sun, 25 Nov 2012 14:49:04 +0000 |
| Subject: | com web/master: add profile field for user: fetch/user-profile.php include/functions.inc manage/users.php users.sql | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-15000@lists.php.net to get a copy of this message | ||
Commit: ebe049eb4c23324bc6b6ba9b30bef22b50fc9fc1
Author: Peter Cowburn <petercowburn@gmail.com> Thu, 15 Nov 2012 20:08:27 +0000
Parents: 501bfe5d1deff43d856e8dafcafe54da7d67a43b
Branches: master
Link: http://git.php.net/?p=web/master.git;a=commitdiff;h=ebe049eb4c23324bc6b6ba9b30bef22b50fc9fc1
Log:
add profile field for user
Changed paths:
A fetch/user-profile.php
M include/functions.inc
M manage/users.php
M users.sql
Diff:
diff --git a/fetch/user-profile.php b/fetch/user-profile.php
new file mode 100644
index 0000000..95b2bd6
--- /dev/null
+++ b/fetch/user-profile.php
@@ -0,0 +1,52 @@
+<?php // vim: et ts=4 sw=4
+function error($text, $status)
+{
+ switch((int)$status) {
+ default:
+ case 500:
+ header("HTTP/1.0 500 Internal server error");
+ break;
+
+ case 404:
+ header("HTTP/1.0 404 Not Found");
+ break;
+
+ case 401:
+ header("HTTP/1.0 401 Unauthorized");
+ break;
+ }
+ render(array("error" => $text));
+ exit;
+}
+
+function render($result)
+{
+ $json = json_encode($result);
+ header('Content-Type: application/json');
+ header('Content-Length: ' . strlen($json));
+ echo $json;
+}
+
+(!isset($_GET['token']) || md5($_GET['token']) !=
"d3fbcabfcf3648095037175fdeef322f") && error("token not correct.", 401);
+
+$USERNAME = filter_input(INPUT_GET, "username", FILTER_SANITIZE_STRING,
FILTER_FLAG_STRIP_HIGH);
+
+$pdo = new PDO("mysql:host=localhost;dbname=phpmasterdb", "nobody",
"");
+
+$stmt = $pdo->prepare("
+ SELECT u.username, COALESCE(up.markdown, '') AS markdown, COALESCE(up.html,
'') AS html
+ FROM users u
+ LEFT JOIN users_profile up ON u.userid = up.userid
+ WHERE u.username = ? AND cvsaccess
+ LIMIT 1
+");
+if (!$stmt->execute(array($USERNAME))) {
+ error("This error should never happen", 500);
+}
+
+$results = $stmt->fetch(PDO::FETCH_ASSOC);
+if (!$results) {
+ error("No such user", 404);
+}
+
+render($results);
diff --git a/include/functions.inc b/include/functions.inc
index 34d8b58..b6bb56a 100644
--- a/include/functions.inc
+++ b/include/functions.inc
@@ -227,3 +227,6 @@ function get_extension_info($mirror_hostname,$ext=null) {
}
return $exts;
}
+
+// We use markdown for people profiles
+include_once dirname(__FILE__) . '/../vendor/michelf/php-markdown-extra/markdown.php';
diff --git a/manage/users.php b/manage/users.php
index a18127f..4a20c52 100644
--- a/manage/users.php
+++ b/manage/users..php
@@ -134,6 +134,7 @@ the ability to work with others.
mail($userinfo['email'],"VCS Account Request:
$userinfo[username]",$message,"From: PHP Group <group@php.net>",
"-fnoreply@php.net");
mail($mailto . ($cc ? ",$cc" : ""),$userinfo['cvsaccess'] ?
"VCS Account Deleted: $userinfo[username] deleted by $user" : "VCS Account Rejected:
$userinfo[username] rejected by $user","Nuked $userinfo[username]","From: PHP
Group <group@php..net>\nIn-Reply-To: <cvs-account-$id-admin@php.net>",
"-fnoreply@php.net");
db_query("DELETE FROM users_note WHERE userid=$id");
+ db_query("DELETE FROM users_profile WHERE userid=$id");
if (!$noclose) {
echo '<script
language="javascript">window.close();</script>';
exit;
@@ -202,6 +203,16 @@ if ($id && $in) {
$query = "INSERT INTO users_note (userid, note, entered) VALUES ($id,
'$purpose', NOW())";
db_query($query);
}
+
+ if(!empty($in['profile_markdown'])) {
+ $profile_markdown = $in['profile_markdown'];
+ $profile_html = Markdown($profile_markdown);
+ $profile_markdown = mysql_real_escape_string($profile_markdown);
+ $profile_html = mysql_real_escape_string($profile_html);
+ $query = "INSERT INTO users_profile (userid, markdown, html) VALUES ($id,
'$profile_markdown', '$profile_html')
+ ON DUPLICATE KEY UPDATE markdown='$profile_markdown',
html='$profile_html'";
+ db_query($query);
+ }
}
warn("record $id updated");
@@ -326,6 +337,24 @@ table.useredit tr {
<p>Adding/editing the SSH key takes a few minutes to propagate to the server.<br>
Multiple keys are allowed, separated using a newline.</p></td>
</tr>
+<?php
+ if ($id) {
+ $res = db_query("SELECT markdown FROM users_profile WHERE userid=$id");
+ $row['profile_markdown'] = '';
+ if ($profile_row = mysql_fetch_assoc($res)) {
+ $row['profile_markdown'] = $profile_row['markdown'];
+ }
+?>
+<tr>
+ <th align="right">People Profile<br>(<a href="http://people.php.net/user.php?username=<?php
echo urlencode($row['username']);?>"><?php echo
hscr($row['username']);?>'s page</a>)</th>
+ <td>
+ <p>Use <a href="http://michelf.ca/projects/php-markdown/dingus/"
title="PHP Markdown: Dingus">Markdown</a>. Type as much as you like.</p>
+ <div><textarea cols="100" rows="20"
name="in[profile_markdown]"><?php echo
escape(html_entity_decode($row['profile_markdown'], ENT_QUOTES));
?></textarea></div>
+ </td>
+</tr>
+<?php
+ }
+?>
<tr>
<th align="right">Add Note: </th>
<td><textarea cols="50" rows="5"
name="in[purpose]"></textarea></td>
diff --git a/users.sql b/users.sql
index df742c6..3e98734 100644
--- a/users.sql
+++ b/users.sql
@@ -60,3 +60,10 @@ CREATE TABLE users_note (
FULLTEXT KEY note (note)
) TYPE=MyISAM;
+/* the users_profile table contains up to one profile row for each user */
+CREATE TABLE users_profile (
+ userid int(11) NOT NULL,
+ markdown TEXT NOT NULL default '',
+ html TEXT NOT NULL default '',
+ PRIMARY KEY (userid)
+) ENGINE=MyISAM DEFAULT CHARSET=utf8;