com web/master: add profile field for user: fetch/user-profile.php include/functions.inc manage/users.php users.sql

From: Date: Sun, 25 Nov 2012 14:49:04 +0000
Subject: com web/master: add profile field for user: fetch/user-profile.php include/functions.inc manage/users.php users.sql
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-15000@lists.php.net to get a copy of this message
Commit: ebe049eb4c23324bc6b6ba9b30bef22b50fc9fc1 Author: Peter Cowburn <petercowburn@gmail.com> Thu, 15 Nov 2012 20:08:27 +0000 Parents: 501bfe5d1deff43d856e8dafcafe54da7d67a43b Branches: master Link: http://git.php.net/?p=web/master.git;a=commitdiff;h=ebe049eb4c23324bc6b6ba9b30bef22b50fc9fc1 Log: add profile field for user Changed paths: A fetch/user-profile.php M include/functions.inc M manage/users.php M users.sql Diff: diff --git a/fetch/user-profile.php b/fetch/user-profile.php new file mode 100644 index 0000000..95b2bd6 --- /dev/null +++ b/fetch/user-profile.php @@ -0,0 +1,52 @@ +<?php // vim: et ts=4 sw=4 +function error($text, $status) +{ + switch((int)$status) { + default: + case 500: + header("HTTP/1.0 500 Internal server error"); + break; + + case 404: + header("HTTP/1.0 404 Not Found"); + break; + + case 401: + header("HTTP/1.0 401 Unauthorized"); + break; + } + render(array("error" => $text)); + exit; +} + +function render($result) +{ + $json = json_encode($result); + header('Content-Type: application/json'); + header('Content-Length: ' . strlen($json)); + echo $json; +} + +(!isset($_GET['token']) || md5($_GET['token']) != "d3fbcabfcf3648095037175fdeef322f") && error("token not correct.", 401); + +$USERNAME = filter_input(INPUT_GET, "username", FILTER_SANITIZE_STRING, FILTER_FLAG_STRIP_HIGH); + +$pdo = new PDO("mysql:host=localhost;dbname=phpmasterdb", "nobody", ""); + +$stmt = $pdo->prepare(" + SELECT u.username, COALESCE(up.markdown, '') AS markdown, COALESCE(up.html, '') AS html + FROM users u + LEFT JOIN users_profile up ON u.userid = up.userid + WHERE u.username = ? AND cvsaccess + LIMIT 1 +"); +if (!$stmt->execute(array($USERNAME))) { + error("This error should never happen", 500); +} + +$results = $stmt->fetch(PDO::FETCH_ASSOC); +if (!$results) { + error("No such user", 404); +} + +render($results); diff --git a/include/functions.inc b/include/functions.inc index 34d8b58..b6bb56a 100644 --- a/include/functions.inc +++ b/include/functions.inc @@ -227,3 +227,6 @@ function get_extension_info($mirror_hostname,$ext=null) { } return $exts; } + +// We use markdown for people profiles +include_once dirname(__FILE__) . '/../vendor/michelf/php-markdown-extra/markdown.php'; diff --git a/manage/users.php b/manage/users.php index a18127f..4a20c52 100644 --- a/manage/users.php +++ b/manage/users..php @@ -134,6 +134,7 @@ the ability to work with others. mail($userinfo['email'],"VCS Account Request: $userinfo[username]",$message,"From: PHP Group <group@php.net>", "-fnoreply@php.net"); mail($mailto . ($cc ? ",$cc" : ""),$userinfo['cvsaccess'] ? "VCS Account Deleted: $userinfo[username] deleted by $user" : "VCS Account Rejected: $userinfo[username] rejected by $user","Nuked $userinfo[username]","From: PHP Group <group@php..net>\nIn-Reply-To: <cvs-account-$id-admin@php.net>", "-fnoreply@php.net"); db_query("DELETE FROM users_note WHERE userid=$id"); + db_query("DELETE FROM users_profile WHERE userid=$id"); if (!$noclose) { echo '<script language="javascript">window.close();</script>'; exit; @@ -202,6 +203,16 @@ if ($id && $in) { $query = "INSERT INTO users_note (userid, note, entered) VALUES ($id, '$purpose', NOW())"; db_query($query); } + + if(!empty($in['profile_markdown'])) { + $profile_markdown = $in['profile_markdown']; + $profile_html = Markdown($profile_markdown); + $profile_markdown = mysql_real_escape_string($profile_markdown); + $profile_html = mysql_real_escape_string($profile_html); + $query = "INSERT INTO users_profile (userid, markdown, html) VALUES ($id, '$profile_markdown', '$profile_html') + ON DUPLICATE KEY UPDATE markdown='$profile_markdown', html='$profile_html'"; + db_query($query); + } } warn("record $id updated"); @@ -326,6 +337,24 @@ table.useredit tr { <p>Adding/editing the SSH key takes a few minutes to propagate to the server.<br> Multiple keys are allowed, separated using a newline.</p></td> </tr> +<?php + if ($id) { + $res = db_query("SELECT markdown FROM users_profile WHERE userid=$id"); + $row['profile_markdown'] = ''; + if ($profile_row = mysql_fetch_assoc($res)) { + $row['profile_markdown'] = $profile_row['markdown']; + } +?> +<tr> + <th align="right">People Profile<br>(<a href="http://people.php.net/user.php?username=<?php echo urlencode($row['username']);?>"><?php echo hscr($row['username']);?>'s page</a>)</th> + <td> + <p>Use <a href="http://michelf.ca/projects/php-markdown/dingus/" title="PHP Markdown: Dingus">Markdown</a>. Type as much as you like.</p> + <div><textarea cols="100" rows="20" name="in[profile_markdown]"><?php echo escape(html_entity_decode($row['profile_markdown'], ENT_QUOTES)); ?></textarea></div> + </td> +</tr> +<?php + } +?> <tr> <th align="right">Add Note: </th> <td><textarea cols="50" rows="5" name="in[purpose]"></textarea></td> diff --git a/users.sql b/users.sql index df742c6..3e98734 100644 --- a/users.sql +++ b/users.sql @@ -60,3 +60,10 @@ CREATE TABLE users_note ( FULLTEXT KEY note (note) ) TYPE=MyISAM; +/* the users_profile table contains up to one profile row for each user */ +CREATE TABLE users_profile ( + userid int(11) NOT NULL, + markdown TEXT NOT NULL default '', + html TEXT NOT NULL default '', + PRIMARY KEY (userid) +) ENGINE=MyISAM DEFAULT CHARSET=utf8;

« previous php.webmaster (#15000) next »