Fixes to properly escape awkward characters in e-mail addresses etc.
[squirrelmail.git] / src / addressbook.php
CommitLineData
abdfb4d0 1<?php
895905c0 2
35586184 3/**
4 * addressbook.php
5 *
15e6162e 6 * Copyright (c) 1999-2002 The SquirrelMail Project Team
35586184 7 * Licensed under the GNU GPL. For full terms see the file COPYING.
8 *
9 * Manage personal address book.
10 *
11 * $Id$
12 */
13
35586184 14require_once('../src/validate.php');
15require_once('../functions/array.php');
16require_once('../functions/display_messages.php');
17require_once('../functions/addressbook.php');
5177fb2b 18require_once('../functions/strings.php');
ac987a56 19require_once('../functions/html.php');
ffd8224c 20
daba719e 21/* Make an input field */
22function adressbook_inp_field($label, $field, $name, $size, $values, $add) {
23 global $color;
ac987a56 24 $td_str = '<INPUT NAME="' . $name . '[' . $field . ']" SIZE="' . $size . '" VALUE="';
daba719e 25 if (isset($values[$field])) {
ac987a56 26 $td_str .= htmlspecialchars($values[$field]);
ffd8224c 27 }
ac987a56 28 $td_str .= '">' . $add . '';
29 return html_tag( 'tr' ,
30 html_tag( 'td', $label . ':', 'right', $color[4]) .
31 html_tag( 'td', $td_str, 'left', $color[4])
32 )
33 . "\n";
daba719e 34}
ffd8224c 35
daba719e 36/* Output form to add and modify address data */
37function address_form($name, $submittext, $values = array()) {
38 global $color;
ac987a56 39 echo html_tag( 'table',
40 adressbook_inp_field(_("Nickname"), 'nickname', $name, 15, $values,
41 '<SMALL>' . _("Must be unique") . '</SMALL>') .
42 adressbook_inp_field(_("E-mail address"), 'email', $name, 45, $values, '') .
43 adressbook_inp_field(_("First name"), 'firstname', $name, 45, $values, '') .
44 adressbook_inp_field(_("Last name"), 'lastname', $name, 45, $values, '') .
45 adressbook_inp_field(_("Additional info"), 'label', $name, 45, $values, '') .
46 html_tag( 'tr',
47 html_tag( 'td',
48 '<INPUT TYPE=submit NAME="' . $name . '[SUBMIT]" VALUE="' .
49 $submittext . '">',
50 'center', $color[4], 'colspan="2"')
51 )
52 , 'center', '', 'border="0" cellpadding="1" cols="2" width="90%"') ."\n";
daba719e 53}
ffd8224c 54
ffd8224c 55
f6c945b9 56/* Open addressbook, with error messages on but without LDAP (the *
57 * second "true"). Don't need LDAP here anyway */
daba719e 58$abook = addressbook_init(true, true);
59if($abook->localbackend == 0) {
60 plain_error_message(
61 _("No personal address book is defined. Contact administrator."),
62 $color);
63 exit();
64}
ffd8224c 65
daba719e 66displayPageHeader($color, 'None');
ffd8224c 67
daba719e 68
69$defdata = array();
70$formerror = '';
71$abortform = false;
72$showaddrlist = true;
73$defselected = array();
74
75
f6c945b9 76/* Handle user's actions */
daba719e 77if($REQUEST_METHOD == 'POST') {
78
f6c945b9 79 /**************************************************
80 * Add new address *
81 **************************************************/
82 if (!empty($addaddr['nickname'])) {
ffd8224c 83
84 $r = $abook->add($addaddr, $abook->localbackend);
85
f6c945b9 86 /* Handle error messages */
87 if (!$r) {
88 /* Remove backend name from error string */
ffd8224c 89 $errstr = $abook->error;
90 $errstr = ereg_replace('^\[.*\] *', '', $errstr);
91
92 $formerror = $errstr;
93 $showaddrlist = false;
94 $defdata = $addaddr;
95 }
96
daba719e 97 } else {
ffd8224c 98
f6c945b9 99 /************************************************
100 * Delete address(es) *
101 ************************************************/
102 if ((!empty($deladdr)) && sizeof($sel) > 0) {
daba719e 103 $orig_sel = $sel;
104 sort($sel);
105
f6c945b9 106 /* The selected addresses are identidied by "backend:nickname". *
107 * Sort the list and process one backend at the time */
daba719e 108 $prevback = -1;
109 $subsel = array();
110 $delfailed = false;
111
f6c945b9 112 for ($i = 0 ; (($i < sizeof($sel)) && !$delfailed) ; $i++) {
daba719e 113 list($sbackend, $snick) = explode(':', $sel[$i]);
114
f6c945b9 115 /* When we get to a new backend, process addresses in *
116 * previous one. */
117 if ($prevback != $sbackend && $prevback != -1) {
daba719e 118
119 $r = $abook->remove($subsel, $prevback);
f6c945b9 120 if (!$r) {
daba719e 121 $formerror = $abook->error;
122 $i = sizeof($sel);
123 $delfailed = true;
124 break;
125 }
126 $subsel = array();
127 }
128
f6c945b9 129 /* Queue for processing */
daba719e 130 array_push($subsel, $snick);
131 $prevback = $sbackend;
ffd8224c 132 }
ffd8224c 133
f6c945b9 134 if (!$delfailed) {
daba719e 135 $r = $abook->remove($subsel, $prevback);
f6c945b9 136 if (!$r) { /* Handle errors */
daba719e 137 $formerror = $abook->error;
138 $delfailed = true;
139 }
ffd8224c 140 }
ffd8224c 141
f6c945b9 142 if ($delfailed) {
daba719e 143 $showaddrlist = true;
144 $defselected = $orig_sel;
ffd8224c 145 }
ffd8224c 146
daba719e 147 } else {
148
f6c945b9 149 /***********************************************
150 * Update/modify address *
151 ***********************************************/
152 if (!empty($editaddr)) {
daba719e 153
f6c945b9 154 /* Stage one: Copy data into form */
daba719e 155 if (isset($sel) && sizeof($sel) > 0) {
156 if(sizeof($sel) > 1) {
157 $formerror = _("You can only edit one address at the time");
158 $showaddrlist = true;
159 $defselected = $sel;
160 } else {
161 $abortform = true;
162 list($ebackend, $enick) = explode(':', $sel[0]);
163 $olddata = $abook->lookup($enick, $ebackend);
164
f6c945b9 165 /* Display the "new address" form */
166 echo '<FORM ACTION="' . $PHP_SELF . '" METHOD="POST">' .
167 "\n" .
ac987a56 168 html_tag( 'table',
169 html_tag( 'tr',
170 html_tag( 'td',
171 "\n". '<strong>' . _("Update address") . '</strong>' ."\n",
172 'center', $color[0] )
173 ),
174 'center', '', 'width="100%" cols="1"' ) .
daba719e 175 address_form("editaddr", _("Update address"), $olddata);
f6c945b9 176 echo '<INPUT TYPE=hidden NAME=oldnick VALUE="' .
177 htmlspecialchars($olddata["nickname"]) . "\">\n" .
178 '<INPUT TYPE=hidden NAME=backend VALUE="' .
179 htmlspecialchars($olddata["backend"]) . "\">\n" .
180 '<INPUT TYPE=hidden NAME=doedit VALUE=1>' . "\n" .
181 '</FORM>';
daba719e 182 }
183 } else {
184
f6c945b9 185 /* Stage two: Write new data */
186 if ($doedit = 1) {
daba719e 187 $newdata = $editaddr;
188 $r = $abook->modify($oldnick, $newdata, $backend);
189
f6c945b9 190 /* Handle error messages */
191 if (!$r) {
192 /* Display error */
ac987a56 193 echo html_tag( 'table',
194 html_tag( 'tr',
195 html_tag( 'td',
196 "\n". '<br><strong><font color="' . $color[2] .
197 '">' . _("ERROR") . ': ' . $abook->error . '</font></strong>' ."\n",
198 'center' )
199 ),
200 'center', '', 'width="100%" cols="1"' );
f6c945b9 201
202 /* Display the "new address" form again */
203 echo '<FORM ACTION="' . $PHP_SELF .
204 '" METHOD="POST">' . "\n" .
ac987a56 205 html_tag( 'table',
206 html_tag( 'tr',
207 html_tag( 'td',
208 "\n". '<br><strong>' . _("Update address") . '</strong>' ."\n",
209 'center', $color[0] )
210 ),
211 'center', '', 'width="100%" cols="1"' ) .
daba719e 212 address_form("editaddr", _("Update address"), $newdata);
f6c945b9 213 echo '<INPUT TYPE=hidden NAME=oldnick VALUE="' .
214 htmlspecialchars($oldnick) . "\">\n" .
215 '<INPUT TYPE=hidden NAME=backend VALUE="' .
216 htmlspecialchars($backend) . "\">\n" .
217 '<INPUT TYPE=hidden NAME=doedit VALUE=1>' .
218 "\n" . '</FORM>';
daba719e 219 $abortform = true;
220 }
221 } else {
222
f6c945b9 223 /* Should not get here... */
daba719e 224 plain_error_message(_("Unknown error"), $color);
225 $abortform = true;
226 }
227 }
228 } /* !empty($editaddr) - Update/modify address */
229 } /* (!empty($deladdr)) && sizeof($sel) > 0 - Delete address(es) */
230 } /* !empty($addaddr['nickname']) - Add new address */
231
232 // Some times we end output before forms are printed
233 if($abortform) {
f6c945b9 234 echo "</BODY></HTML>\n";
daba719e 235 exit();
ffd8224c 236 }
daba719e 237}
ffd8224c 238
239
f6c945b9 240/* =================================================================== *
241 * The following is only executed on a GET request, or on a POST when *
242 * a user is added, or when "delete" or "modify" was successful. *
243 * =================================================================== */
ffd8224c 244
f6c945b9 245/* Display error messages */
246if (!empty($formerror)) {
ac987a56 247 echo html_tag( 'table',
248 html_tag( 'tr',
249 html_tag( 'td',
250 "\n". '<br><strong><font color="' . $color[2] .
251 '">' . _("ERROR") . ': ' . $formerror . '</font></strong>' ."\n",
252 'center' )
253 ),
254 'center', '', 'width="100%" cols="1"' );
daba719e 255}
ffd8224c 256
257
f6c945b9 258/* Display the address management part */
259if ($showaddrlist) {
260 /* Get and sort address list */
daba719e 261 $alist = $abook->list_addr();
262 if(!is_array($alist)) {
ffd8224c 263 plain_error_message($abook->error, $color);
264 exit;
daba719e 265 }
ffd8224c 266
daba719e 267 usort($alist,'alistcmp');
268 $prevbackend = -1;
269 $headerprinted = false;
ffd8224c 270
ac987a56 271 echo html_tag( 'p', '<a href="#AddAddress">' . _("Add address") . '</a>', 'center' ) . "\n";
ffd8224c 272
f6c945b9 273 /* List addresses */
91821fc0 274 if (count($alist) > 0) {
275 echo '<FORM ACTION="' . $PHP_SELF . '" METHOD="POST">' . "\n";
276 while(list($undef,$row) = each($alist)) {
277
278 /* New table header for each backend */
279 if($prevbackend != $row['backend']) {
92cd1e8e 280 if($prevbackend < 0) {
ac987a56 281 echo html_tag( 'table',
282 html_tag( 'tr',
283 html_tag( 'td',
284 '<INPUT TYPE=submit NAME=editaddr VALUE="' .
285 _("Edit selected") . "\">\n" .
286 '<INPUT TYPE=submit NAME=deladdr VALUE="' .
287 _("Delete selected") . "\">\n",
288 'center', '', 'colspan="5"' )
289 ) .
290 html_tag( 'tr',
291 html_tag( 'td', '&nbsp;<br>', 'center', '', 'colspan="5"' )
292 ) ,
293 'center' );
91821fc0 294 }
295
ac987a56 296 echo html_tag( 'table',
297 html_tag( 'tr',
298 html_tag( 'td', "\n" . '<strong>' . $row['source'] . '</strong>' . "\n", 'center', $color[0] )
299 ) ,
300 'center', '', 'width="95%" cols="1"' ) ."\n"
301 . html_tag( 'table', '', 'center', '', 'cols="5" border="0" cellpadding="1" cellspacing="0" width="90%"' ) .
302 html_tag( 'tr', "\n" .
303 html_tag( 'th', '&nbsp;', 'left', '', 'width="1%"' ) .
304 html_tag( 'th', _("Nickname"), 'left', '', 'width="1%"' ) .
305 html_tag( 'th', _("Name"), 'left', '', 'width="1%"' ) .
306 html_tag( 'th', _("E-mail"), 'left', '', 'width="1%"' ) .
307 html_tag( 'th', _("Info"), 'left', '', 'width="1%"' ) ,
308 '', $color[9] ) . "\n";
91821fc0 309
310 $line = 0;
311 $headerprinted = true;
312 } /* End of header */
313
314 $prevbackend = $row['backend'];
315
316 /* Check if this user is selected */
317 if(in_array($row['backend'] . ':' . $row['nickname'], $defselected)) {
318 $selected = 'CHECKED';
319 } else {
320 $selected = '';
ffd8224c 321 }
91821fc0 322
323 /* Print one row */
ac987a56 324 $tr_bgcolor = '';
325 if ($line % 2) { $tr_bgcolor = $color[0]; }
326 echo html_tag( 'tr', '') .
327 html_tag( 'td',
328 '<SMALL>' .
329 '<INPUT TYPE=checkbox ' . $selected . ' NAME="sel[]" VALUE="' .
330 $row['backend'] . ':' . $row['nickname'] . '"></SMALL>' ,
331 'center', '', 'valign="top" width="1%"' ) .
332 html_tag( 'td', '&nbsp;' . $row['nickname'] . '&nbsp;', 'left', '', 'valign="top" width="1%" nowrap' ) .
333 html_tag( 'td', '&nbsp;' . $row['name'] . '&nbsp;', 'left', '', 'valign="top" width="1%" nowrap' ) .
334 html_tag( 'td', '', 'left', '', 'valign="top" width="1%" nowrap' ) . '&nbsp;';
3d0cada3 335 $email = $abook->full_address($row);
ac987a56 336 if ($compose_new_win == '1') {
3d0cada3 337 echo '<a href="javascript:void(0)" onclick=comp_in_new(false,"compose.php?send_to='.rawurlencode($email).'")>';
ac987a56 338 }
339 else {
3d0cada3 340 echo '<A HREF="compose.php?send_to=' . rawurlencode($email).'">';
ac987a56 341 }
4e160237 342 echo htmlspecialchars($row['email']) . '</A>&nbsp;</td>'."\n".
343 html_tag( 'td', '&nbsp;' . htmlspecialchars($row['label']) . '&nbsp;', 'left', '', 'valign="top" width="1%"' ) .
ac987a56 344 "</tr>\n";
91821fc0 345 $line++;
daba719e 346 }
91821fc0 347
348 /* End of list. Close table. */
349 if ($headerprinted) {
ac987a56 350 echo html_tag( 'tr',
351 html_tag( 'td',
352 '<INPUT TYPE="submit" NAME="editaddr" VALUE="' . _("Edit selected") .
353 "\">\n" .
354 '<INPUT TYPE="submit" NAME="deladdr" VALUE="' . _("Delete selected") .
355 "\">\n",
356 'center', '', 'colspan="5"' )
357 );
91821fc0 358 }
ac987a56 359 echo '</table></FORM>';
daba719e 360 }
f6c945b9 361} /* end of addresslist */
daba719e 362
363
f6c945b9 364/* Display the "new address" form */
365echo '<a name="AddAddress"></a>' . "\n" .
ac987a56 366 '<FORM ACTION="' . $PHP_SELF . '" NAME=f_add METHOD="POST">' . "\n" .
367 html_tag( 'table',
368 html_tag( 'tr',
369 html_tag( 'td', "\n". '<strong>' . sprintf(_("Add to %s"), $abook->localbackendname) . '</strong>' . "\n",
370 'center', $color[0]
371 )
372 )
373 , 'center', '', 'width="100%" cols="1"' ) ."\n";
daba719e 374address_form('addaddr', _("Add address"), $defdata);
375echo '</FORM>';
376
f6c945b9 377/* Add hook for anything that wants on the bottom */
daba719e 378do_hook('addressbook_bottom');
abdfb4d0 379?>
380
35586184 381</BODY></HTML>