<?
if (!isset($user) && !isset($_GET['id_user'])){header("Location: /foto/?".SID);exit;}
if (isset($user))$ank['id']=$user['id'];
if (isset($_GET['id_user']))$ank['id']=$_GET['id_user'];
$ank=get_user($ank['id']);
if (!$ank){header("Location: /foto/?".SID);exit;}
$gallery['id']=intval($_GET['id_gallery']);
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `gallery` WHERE `id` = '$gallery[id]' AND `id_user` = '$ank[id]' LIMIT 1"),0)==0){header("Location: /foto/$ank[id]/?".SID);exit;}
$gallery=mysql_fetch_assoc(mysql_query("SELECT * FROM `gallery` WHERE `id` = '$gallery[id]' AND `id_user` = '$ank[id]' LIMIT 1"));
$foto['id']=intval($_GET['id_foto']);
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `gallery_foto` WHERE `id` = '$foto[id]' LIMIT 1"),0)==0){header("Location: /foto/$ank[id]/$gallery[id]/?".SID);exit;}
$foto=mysql_fetch_assoc(mysql_query("SELECT * FROM `gallery_foto` WHERE `id` = '$foto[id]' LIMIT 1"));
mysql_query("UPDATE `gallery_foto` SET `id_user` = '$ank[id]' WHERE `id` = '$foto[id]'");
$set['title']=$ank['nick'].' - '.$gallery['name'].' - '.$foto['name']; // заголовок страницы
include_once '../sys/inc/thead.php';
title();
if (user_access('foto_foto_edit') && $ank['level']>$user['level'] || isset($user) && $ank['id']==$user['id'])
include 'inc/gallery_show_foto_act.php';
//-----------------------добавляем в закладки------------//
if (isset($_GET['fav']) && $_GET['fav']==1){
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `mark_foto` WHERE `id_user` = '".$user['id']."' AND `id_foto` = '".$foto['id']."' LIMIT 1"),0)==0){
mysql_query("INSERT INTO `mark_foto` (`id_foto`, `id_user`, `time`) VALUES ('$foto[id]', '$user[id]', '$time')");
msg('' . $foto['name'] . ' добавлено в закладки');
}
}
//-------------------------------------------------------//
//-----------------------удаляем из закладок------------//
if (isset($_GET['fav']) && $_GET['fav']==0){
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `mark_foto` WHERE `id_user` = '".$user['id']."' AND `id_foto` = '".$foto['id']."' LIMIT 1"),0)==1){
mysql_query("DELETE FROM `mark_foto` WHERE `id_user` = '$user[id]' AND `id_foto` = '$foto[id]' ");
msg('' . $foto['name'] . ' удалено из закладок');
}
}
//-------------------------------------------------------//
//------------очищаем счетчик этого обсуждения-------------//
if (isset($user))
{
mysql_query("UPDATE `discussions` SET `count` = '0' WHERE `id_user` = '$user[id]' AND `type` = 'foto' AND `id_sim` = '$foto[id]' LIMIT 1");
}
//---------------------------------------------------------//
if (isset($_POST['msg']) && isset($user))
{
$msg=$_POST['msg'];
if (isset($_POST['translit']) && $_POST['translit']==1)$msg=translit($msg);
$mat=antimat($msg);
if ($mat)$err[]='В тексте сообщения обнаружен мат: '.$mat;
if (strlen2($msg)>1024){$err='Сообщение слишком длинное';}
elseif (strlen2($msg)<2){$err='Короткое сообщение';}
elseif (mysql_result(mysql_query("SELECT COUNT(*) FROM `gallery_komm` WHERE `id_foto` = '$foto[id]' AND `id_user` = '$user[id]' AND `msg` = '".mysql_escape_string($msg)."' LIMIT 1"),0)!=0){$err='Ваше сообщение повторяет предыдущее';}
elseif(!isset($err)){
if (isset($user) && $respons==TRUE){
$msgenta = "Привет, [b]$user[nick][/b] ответил вам в комментариях к фото [url=/foto/$ank[id]/$gallery[id]/komm/$foto[id]/]$foto[name][/url]";
mysql_query("INSERT INTO `lenta_komm` (`id_user`, `id_kont`, `msg`, `time`) values('160', '$ank_otv[id]', '$msgenta', '$time')");
}
######################Обсуждения
$q = mysql_query("SELECT * FROM `frends` WHERE `user` = '".$gallery['id_user']."' AND `i` = '1'");
while ($f = mysql_fetch_array($q))
{
$a=get_user($f['frend']);
//---------друзьям автора--------------//
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `discussions` WHERE `id_user` = '$a[id]' AND `type` = 'foto' AND `id_sim` = '$foto[id]' LIMIT 1"),0)==0)
{
if ($a['id'] != $user['id'])
mysql_query("INSERT INTO `discussions` (`id_user`, `avtor`, `type`, `time`, `id_sim`, `count`) values('$a[id]', '$gallery[id_user]', 'foto', '$time', '$foto[id]', '1')");
}
else
{
$disc = mysql_fetch_array(mysql_query("SELECT * FROM `discussions` WHERE `id_user` = '$gallery[id_user]' AND `type` = 'foto' AND `id_sim` = '$foto[id]' LIMIT 1"));
if ($gallery['id_user'] != $user['id'])
mysql_query("UPDATE `discussions` SET `count` = '".($disc['count']+1)."', `time` = '$time' WHERE `id_user` = '$a[id]' AND `type` = 'foto' AND `id_sim` = '$foto[id]' LIMIT 1");
}
//-------------------------------------//
}
//-------------отправляем автору------------//
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `discussions` WHERE `id_user` = '$gallery[id_user]' AND `type` = 'foto' AND `id_sim` = '$foto[id]' LIMIT 1"),0)==0)
{
if ($gallery['id_user'] != $user['id'])
mysql_query("INSERT INTO `discussions` (`id_user`, `avtor`, `type`, `time`, `id_sim`, `count`) values('$gallery[id_user]', '$gallery[id_user]', 'foto', '$time', '$foto[id]', '1')");
}
else
{
$disc2 = mysql_fetch_array(mysql_query("SELECT * FROM `discussions` WHERE `id_user` = '$gallery[id_user]' AND `type` = 'foto' AND `id_sim` = '$foto[id]' LIMIT 1"));
if ($gallery['id_user'] != $user['id'])
mysql_query("UPDATE `discussions` SET `count` = '".($disc2['count']+1)."', `time` = '$time' WHERE `id_user` = '$gallery[id_user]' AND `type` = 'foto' AND `id_sim` = '$foto[id]' LIMIT 1");
}
#######################Конец
mysql_query("INSERT INTO `gallery_komm` (`id_foto`, `id_user`, `time`, `msg`) values('$foto[id]', '$user[id]', '$time', '".my_esc($msg)."')");
mysql_query("UPDATE `user` SET `balls` = '".($user['balls']+1)."' WHERE `id` = '$user[id]' LIMIT 1");
msg('Сообщение успешно добавлено');
}
}
if (isset($user) && $user['id']!=$ank['id'] && $user['rating']>=0 && mysql_result(mysql_query("SELECT COUNT(*) FROM `gallery_rating` WHERE `id_user` = '$user[id]' AND `id_foto` = '$foto[id]'"), 0)==0)
{
if (isset($_GET['rating']) && $_GET['rating']=='1'){
mysql_query("INSERT INTO `gallery_rating` (`id_user`, `id_foto`, `like`, `time`, `avtor`) values('$user[id]', '$foto[id]', '1', '$time', $foto[id_user])",$db);
mysql_query("UPDATE `gallery_foto` SET `rating` = '".($foto['rating']+1)."' WHERE `id` = '$foto[id]' LIMIT 1",$db);
}
elseif(isset($_GET['rating']) && $_GET['rating']=='2')
{
mysql_query("INSERT INTO `gallery_rating` (`id_user`, `id_foto`, `like`, `time`, `avtor`) values('$user[id]', '$foto[id]', '2', '$time', $foto[id_user])",$db);
mysql_query("UPDATE `gallery_foto` SET `rating` = '".($foto['rating']+2)."' WHERE `id` = '$foto[id]' LIMIT 1",$db);
}
elseif(isset($_GET['rating']) && $_GET['rating']=='3')
{
mysql_query("INSERT INTO `gallery_rating` (`id_user`, `id_foto`, `like`, `time`, `avtor`) values('$user[id]', '$foto[id]', '3', '$time', $foto[id_user])",$db);
mysql_query("UPDATE `gallery_foto` SET `rating` = '".($foto['rating']+3)."' WHERE `id` = '$foto[id]' LIMIT 1",$db);
}
elseif(isset($_GET['rating']) && $_GET['rating']=='4')
{
mysql_query("INSERT INTO `gallery_rating` (`id_user`, `id_foto`, `like`, `time`, `avtor`) values('$user[id]', '$foto[id]', '4', '$time', $foto[id_user])",$db);
mysql_query("UPDATE `gallery_foto` SET `rating` = '".($foto['rating']+4)."' WHERE `id` = '$foto[id]' LIMIT 1",$db);
}
elseif(isset($_GET['rating']) && $_GET['rating']=='5')
{
mysql_query("INSERT INTO `gallery_rating` (`id_user`, `id_foto`, `like`, `time`, `avtor`) values('$user[id]', '$foto[id]', '5', '$time', $foto[id_user])",$db);
mysql_query("UPDATE `gallery_foto` SET `rating` = '".($foto['rating']+5)."' WHERE `id` = '$foto[id]' LIMIT 1",$db);
}
elseif(isset($_GET['rating']) && $_GET['rating']=='5i')
{
$c=mysql_result(mysql_query("SELECT COUNT(*) FROM `ocenky` WHERE `id_user` = '$user[id]' AND `time` > '$time'"), 0);
if ($c==1){
mysql_query("INSERT INTO `gallery_rating` (`id_user`, `id_foto`, `like`, `time`, `avtor`) values('$user[id]', '$foto[id]', '6', '$time', $foto[id_user])",$db);
mysql_query("UPDATE `gallery_foto` SET `rating` = '".($foto['rating']+10)."' WHERE `id` = '$foto[id]' LIMIT 1",$db);
}
else
{
header("Location: /user/money/plus5.php");
}
}
}
$foto=mysql_fetch_assoc(mysql_query("SELECT * FROM `gallery_foto` WHERE `id` = $foto[id] LIMIT 1"));
$rat=mysql_result(mysql_query("SELECT COUNT(*) FROM `gallery_rating` WHERE `id_foto` = $foto[id] AND `like` = '6'"), 0);
//-------------------пароль и сессия------------//
if ($user['id']!=$ank['id']){
if (isset($_POST['pass']))$_SESSION['pass']=$_POST['pass'];
else
$_SESSION['pass']=NULL;
if (isset($_SESSION['pass']) && $_SESSION['pass']==$gallery['pass']){
mysql_query("UPDATE `user` SET `session_pass` = '$_SESSION[pass]' WHERE `id` = '$user[id]'");
header("Location: ?".SID);
}
if (isset($_SESSION['pass']) && $_SESSION['pass']!=$gallery['pass']){
mysql_query("UPDATE `user` SET `session_pass` = '0' WHERE `id` = '$user[id]'");
$err = 'Неверный пароль';
}
if (!$_SESSION['pass'])$_SESSION['pass']=$user['session_pass'];
}
//----------------------------------------------//
if (isset($_GET['err']))$err='Ошибка доступа';
err();
aut();
//----------------------листинг-------------------//
$listr = mysql_fetch_assoc(mysql_query("SELECT * FROM `gallery_foto` WHERE `id_user` = '$ank[id]' AND `id_gallery` = '$gallery[id]' AND `id` < '$foto[id]' ORDER BY `id` DESC LIMIT 1"));
$list = mysql_fetch_assoc(mysql_query("SELECT * FROM `gallery_foto` WHERE `id_user` = '$ank[id]' AND `id_gallery` = '$gallery[id]' AND `id` > '$foto[id]' ORDER BY `id` ASC LIMIT 1"));
if ($listr['id'] || $list['id'])echo "<div class=\"foot\">\n";
if ($list['id'])echo "<a href='/foto/$ank[id]/$gallery[id]/$list[id]/'>«Пред.</a>";
if ($listr['id'] && $list['id'])echo " • ";
if ($listr['id'])echo "<a href='/foto/$ank[id]/$gallery[id]/$listr[id]/'>След.»</a>";
if ($listr['id'] || $list['id'])echo "</div>\n";
//----------------------alex-borisi---------------//
$frend=mysql_result(mysql_query("SELECT COUNT(*) FROM `frends` WHERE (`user` = '$user[id]' AND `frend` = '$ank[id]') OR (`user` = '$ank[id]' AND `frend` = '$user[id]') LIMIT 1"),0);
if ($gallery['privat']==1 && $user['id']!=$ank['id'] && $frend!=2){
msg('Фотоальбом доступен только для друзей');
echo "<div class=\"foot\">\n";
echo "«<a href='/foto/$ank[id]/'>К фотоальбомам</a><br />\n";
echo "</div>\n";
include_once '../sys/inc/tfoot.php';
exit;
}
if ($gallery['privat']==2 && $user['id']!=$ank['id']){
msg('Пользователь запретил просмотр фотоальбома');
echo "<div class=\"foot\">\n";
echo "«<a href='/foto/$ank[id]/'>К фотоальбомам</a><br />\n";
echo "</div>\n";
include_once '../sys/inc/tfoot.php';
exit;
}
if ($user['id']!=$ank['id']){
if ($gallery['pass']!=0 && $user['session_pass']!=$gallery['pass'] && $user['level']<$ank['level'] || $gallery['pass']!=0 && $_SESSION['pass']!=$gallery['pass'] && $user['level']<$ank['level']){
echo "<form action='?' method=\"post\">";
echo "Пароль:<br />";
echo "<input name='pass' type='text' value='' /><br />";
echo "<input class='submit' type='submit' value='Войти' /> ";
echo "</form>";
include_once '../sys/inc/tfoot.php';
exit;
}
}
$IS = GetImageSize(H.'sys/gallery/128/'.$foto['id'].'.'.$foto['ras'].'');
printf("", $IS[0], $IS[1]);
$w = $IS[0];
$h = $IS[1];
echo "<a href='/foto/$ank[id]/$gallery[id]/komm/$foto[id]/'>Комментарии (".mysql_result(mysql_query("SELECT COUNT(*) FROM `gallery_komm` WHERE `id_foto` = '$foto[id]'"),0).")</a><br />\n";
echo "<table>";
if ($set['web']){
$di='640';
$width='350';
}else{
$width='';
$di='128';
}
echo "<div style='display:inline;'><a href='/foto/foto0/$foto[id].$foto[ras]' title='Скачать оригинал'><img src='/foto/foto$di/$foto[id].$foto[ras]'/></a></div>";
if ($rat>0)echo "<div style='display:inline;margin-left:-25px;vertical-align:top;'><img style='padding-top:10px;' src='/style/icons/6.png'/></div>";
echo "</table>";
echo "Тип: <b>".$foto['ras']."</b>, ".$w."x".$h." <br />";
if ($foto['opis']!=null)
echo esc(trim(br(bbcode(smiles(links(stripcslashes(htmlspecialchars($foto['opis']))))))))."<br />\n";
//--------------------------В закладки-----------------------------//
if (isset($user)){
echo "<div class='main_seriy'>";
echo "<div class='main'>";
echo "<img src='/style/icons/fav.gif' alt='*' /> ";
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `mark_foto` WHERE `id_user` = '".$user['id']."' AND `id_foto` = '".$foto['id']."' LIMIT 1"),0)==0)
echo "<a href='/foto/$ank[id]/$gallery[id]/$foto[id]/?fav=1'>Добавить в закладки</a> \n";
else
echo "<a href='/foto/$ank[id]/$gallery[id]/$foto[id]/?fav=0'>Удалить из закладок</a> \n";
echo "</div>";
echo "</div>";
}
//-------------------------------------------------------------//
if (isset($user) && $user['id']!=$ank['id'] && mysql_result(mysql_query("SELECT COUNT(*) FROM `gallery_rating` WHERE `id_user` = '$user[id]' AND `id_foto` = '$foto[id]'"), 0)==0){
echo "<a href=\"?id=$foto[id]&rating=5i\" title=\"5+\"><img src='/style/icons/6.png' alt=''/></a>";
echo "<a href=\"?id=$foto[id]&rating=5\" title=\"5\"><img src='/style/icons/5.png' alt=''/></a>";
echo "<a href=\"?id=$foto[id]&rating=4\" title=\"4\"><img src='/style/icons/4.png' alt=''/></a>";
echo "<a href=\"?id=$foto[id]&rating=3\" title=\"3\"><img src='/style/icons/3.png' alt=''/></a>";
echo "<a href=\"?id=$foto[id]&rating=2\" title=\"2\"><img src='/style/icons/2.png' alt=''/></a>";
echo "<a href=\"?id=$foto[id]&rating=1\" title=\"1\"><img src='/style/icons/1.png' alt=''/></a>";
}else{
$rate=mysql_fetch_assoc(mysql_query("SELECT * FROM `gallery_rating` WHERE `id_foto` = $foto[id] AND `id_user` = '$user[id]' LIMIT 1"));
if (isset($user) && $user['id']!=$ank['id'])
echo "Ваша оценка <img src='/style/icons/$rate[like].png' alt=''/></a>";
}
echo "</div>\n";
if (user_access('foto_foto_edit') && $ank['level']>$user['level'] || isset($user) && $ank['id']==$user['id'])
include 'inc/gallery_show_foto_form.php';
###############################komm
echo "<div class='foot'>";
echo "Комментарии:";
echo "</div>";
$k_post=mysql_result(mysql_query("SELECT COUNT(*) FROM `gallery_komm` WHERE `id_foto` = '$foto[id]'"),0);
$k_page=k_page($k_post,$set['p_str']);
$page=page($k_page);
$start=$set['p_str']*$page-$set['p_str'];
echo "<table class='post'>\n";
if ($k_post==0)
{
echo " <tr>\n";
echo " <td class='p_t'>\n";
echo "Нет комментариев\n";
echo " </td>\n";
echo " </tr>\n";
}
$q=mysql_query("SELECT * FROM `gallery_komm` WHERE `id_foto` = '$foto[id]' ORDER BY `id` DESC LIMIT $start, $set[p_str]");
while ($post = mysql_fetch_assoc($q))
{
$ank2=mysql_fetch_assoc(mysql_query("SELECT * FROM `user` WHERE `id` = '$post[id_user]' LIMIT 1"));
echo " <tr>\n";
if ($set['set_show_icon']==2){
echo " <td class='icon48' rowspan='2'>\n";
avatar($ank2['id']);
echo " </td>\n";
}elseif ($set['set_show_icon']==1){
echo " <td class='icon48' rowspan='1'>\n";
status($ank2['id']);
echo " </td>\n";
}
echo " <td class='p_t'>\n";
echo " ".group($ank2['id'])." <a href='/info.php?id=$ank2[id]'>" . GradientText("$ank2[nick]", "$ank2[ncolor]", "$ank2[ncolor2]") . "</a> <a href='?response=$ank2[id]'>[*]</a>".online($ank2['id'])." (".vremja($post['time']).")\n";
echo " </td>\n";
echo " </tr>\n";
echo " <tr>\n";
if ($set['set_show_icon']==1)echo " <td class='p_m' colspan='2'>\n"; else echo " <td class='p_m'>\n";
echo output_text($post['msg'])."<br />\n";
echo " </td>\n";
echo " </tr>\n";
}
echo "</table>\n";
if ($k_page>1)str('?',$k_page,$page); // Вывод страниц
$frend=mysql_result(mysql_query("SELECT COUNT(*) FROM `frends` WHERE (`user` = '$user[id]' AND `frend` = '$ank[id]') OR (`user` = '$ank[id]' AND `frend` = '$user[id]') LIMIT 1"),0);
if ($gallery['privat_komm']==1 && $user['id']!=$ank['id'] && $frend!=2){
msg('Комментировать могут только друзья');
echo "<div class=\"foot\">\n";
echo "«<a href='/foto/$ank[id]/'>К фотоальбомам</a><br />\n";
echo "</div>\n";
include_once '../sys/inc/tfoot.php';
exit;
}
if ($gallery['privat_komm']==2 && $user['id']!=$ank['id']){
msg('Пользователь запретил комментирование фотоальбома');
echo "<div class=\"foot\">\n";
echo "«<a href='/foto/$ank[id]/'>К фотоальбомам</a><br />\n";
echo "</div>\n";
include_once '../sys/inc/tfoot.php';
exit;
}
if (isset($user))
{
echo "<form method='post' name='message' action='?$passgen".$go_otv."'>\n";
if ($set['web'] && is_file(H.'style/themes/'.$set['set_them'].'/altername_post_form.php'))
include_once H.'style/themes/'.$set['set_them'].'/altername_post_form.php';
else
echo "Сообщение:<br />\n<textarea name=\"msg\">$otvet</textarea><br />\n";
if ($user['set_translit']==1)echo "<label><input type=\"checkbox\" name=\"translit\" value=\"1\" /> Транслит</label><br />\n";
echo "<input value=\"Отправить\" type=\"submit\" />\n";
echo "</form>\n";
}
echo "<div class=\"foot\">\n";
echo "<a href='/foto/$ank[id]/$gallery[id]/'>К фотографиям</a><br />\n";
echo "<a href='/foto/$ank[id]/'>К фотоальбомам</a><br />\n";
echo "</div>\n";
include_once '../sys/inc/tfoot.php';
exit;
?>