Allow more liberal reuse of tokens to avoid cross-frame conflicts
[squirrelmail.git] / src / addressbook.php
index ee38cf7f8b87d57077c67ce8fea3b8acf661b251..96522252f22d924d48c895311546fd091bf6a3a7 100644 (file)
 /**
  * addressbook.php
  *
- * Copyright (c) 1999-2001 The Squirrelmail Development Team
- * Licensed under the GNU GPL. For full terms see the file COPYING.
- *
  * Manage personal address book.
  *
- * $Id$
+ * @copyright 1999-2012 The SquirrelMail Project Team
+ * @license http://opensource.org/licenses/gpl-license.php GNU Public License
+ * @version $Id$
+ * @package squirrelmail
+ * @subpackage addressbook
  */
 
-/*****************************************************************/
-/*** THIS FILE NEEDS TO HAVE ITS FORMATTING FIXED!!!           ***/
-/*** PLEASE DO SO AND REMOVE THIS COMMENT SECTION.             ***/
-/***    + Base level indent should begin at left margin, as    ***/
-/***      the require_once below looks.                        ***/
-/***    + All identation should consist of four space blocks   ***/
-/***    + Tab characters are evil.                             ***/
-/***    + all comments should use "slash-star ... star-slash"  ***/
-/***      style -- no pound characters, no slash-slash style   ***/
-/***    + FLOW CONTROL STATEMENTS (if, while, etc) SHOULD      ***/
-/***      ALWAYS USE { AND } CHARACTERS!!!                     ***/
-/***    + Please use ' instead of ", when possible. Note "     ***/
-/***      should always be used in _( ) function calls.        ***/
-/*** Thank you for your help making the SM code more readable. ***/
-/*****************************************************************/
-
-require_once('../src/validate.php');
-require_once('../functions/array.php');
-require_once('../functions/display_messages.php');
-require_once('../functions/addressbook.php');
-
-/* Sort array by the key "name" */
-function alistcmp($a,$b) {
-    if($a['backend'] > $b['backend']) {
-        return 1;
-    } else {
-        if($a['backend'] < $b['backend']) {
-            return -1;
-        }
-    }
-    return (strtolower($a['name']) > strtolower($b['name'])) ? 1 : -1;
-}
-
-/* Make an input field */
-function adressbook_inp_field($label, $field, $name, $size, $values, $add) {
-    global $color;
-    echo '<TR><TD BGCOLOR="' . $color[4] . '" ALIGN=RIGHT>' .
-         $label . ':</TD>' .
-         '<TD BGCOLOR="' . $color[4] . '" ALIGN=left>' .
-         '<INPUT NAME="' . $name . '[' . $field . ']" SIZE="' . $size . '" VALUE="';
-    if (isset($values[$field])) {
-        echo htmlspecialchars($values[$field]);
-    }
-    echo '">' . $add . '</TD></TR>' . "\n";
-}
-
-/* Output form to add and modify address data */
-function address_form($name, $submittext, $values = array()) {
-    global $color;
+/** This is the addressbook page */
+define('PAGE_NAME', 'addressbook');
 
-    echo '<TABLE BORDER=0 CELLPADDING=1 COLS=2 WIDTH="90%" ALIGN=center>' ."\n";
-
-    adressbook_inp_field(_("Nickname"),     'nickname', $name, 15, $values,
-        '<SMALL>' . _("Must be unique") . '</SMALL>');
-    adressbook_inp_field(_("E-mail address"),  'email', $name, 45, $values, '');
-    adressbook_inp_field(_("First name"),  'firstname', $name, 45, $values, '');
-    adressbook_inp_field(_("Last name"),    'lastname', $name, 45, $values, '');
-    adressbook_inp_field(_("Additional info"), 'label', $name, 45, $values, '');
-
-    echo '<TR><TD COLSPAN=2 BGCOLOR="' . $color[4] . '" ALIGN=center>' . "\n" .
-         '<INPUT TYPE=submit NAME="' . $name . '[SUBMIT]" VALUE="' .
-         $submittext . '"></TD></TR>' .
-         "\n</TABLE>\n";
-}
-
-
-// Open addressbook, with error messages on but without LDAP (the
-// second "true"). Don't need LDAP here anyway
-$abook = addressbook_init(true, true);
+/**
+ * Include the SquirrelMail initialization file.
+ */
+include('../include/init.php');
+
+/** SquirrelMail required files. */
+/* address book functions */
+require_once(SM_PATH . 'functions/addressbook.php');
+include_once(SM_PATH . 'templates/util_addressbook.php');
+
+/* form functions */
+require_once(SM_PATH . 'functions/forms.php');
+
+/** lets get the global vars we may need */
+
+/* From the address form */
+sqgetGlobalVar('smtoken',       $submitted_token, SQ_POST, '');
+sqgetGlobalVar('addaddr',       $addaddr,       SQ_POST);
+sqgetGlobalVar('editaddr',      $editaddr,      SQ_POST);
+sqgetGlobalVar('deladdr',       $deladdr,       SQ_POST);
+sqgetGlobalVar('compose_to',    $compose_to,    SQ_POST);
+sqgetGlobalVar('sel',           $sel,           SQ_POST);
+sqgetGlobalVar('oldnick',       $oldnick,       SQ_POST);
+sqgetGlobalVar('backend',       $backend,       SQ_POST);
+sqgetGlobalVar('doedit',        $doedit,        SQ_POST);
+$page_size = $abook_show_num;
+if (!sqGetGlobalVar('page_number', $page_number, SQ_FORM))
+    if (!sqGetGlobalVar('current_page_number', $page_number, SQ_FORM))
+        $page_number = 1;
+if (!sqGetGlobalVar('show_all', $show_all, SQ_FORM))
+    $show_all = 0;
+
+/* Get sorting order */
+$abook_sort_order = get_abook_sort();
+
+// Create page header before addressbook_init in order to
+// display error messages correctly, unless we might be
+// redirecting the browser to the compose page.
+//
+if ((empty($compose_to)) || sizeof($sel) < 1)
+    displayPageHeader($color);
+
+/* Open addressbook with error messages on.
+ remote backends (LDAP) are enabled because they can be used. (list_addr function)
+*/
+$abook = addressbook_init(true, false);
+
+// FIXME: do we really have to stop use of address book when localbackend is not present?
 if($abook->localbackend == 0) {
-    plain_error_message(
-        _("No personal address book is defined. Contact administrator."),
-        $color);
+    plain_error_message(_("No personal address book is defined. Contact administrator."));
     exit();
 }
 
-displayPageHeader($color, 'None');
+$current_backend = $abook->localbackend;
+if (sqgetGlobalVar('new_bnum', $new_backend, SQ_FORM)
+ && array_key_exists($new_backend, $abook->backends)) {
+    $current_backend = (int) $new_backend;
+}
 
+$abook_selection = '&nbsp;';
+$list_backends = array();
+if (count($abook->backends) > 1) {
+    foreach($abook->get_backend_list() as $oBackend) {
+        if ($oBackend->listing) {
+            $list_backends[$oBackend->bnum]=$oBackend->sname;
+        }
+    }
+    if (count($list_backends)>1) {
+        $abook_selection = addSelect('new_bnum',$list_backends,$current_backend,true)
+            .addSubmit(_("Change"),'change_abook');
+    }
+}
 
 $defdata   = array();
 $formerror = '';
 $abortform = false;
 $showaddrlist = true;
 $defselected  = array();
+$form_url = 'addressbook.php';
 
+/* Handle user's actions */
+if(sqgetGlobalVar('REQUEST_METHOD', $req_method, SQ_SERVER) && $req_method == 'POST') {
 
-// Handle user's actions
-if($REQUEST_METHOD == 'POST') {
+    // first, validate security token
+    sm_validate_security_token($submitted_token, -1, TRUE);
 
-    // ***********************************************
-    // Add new address
-    // ***********************************************
-    if(!empty($addaddr['nickname'])) {
-
-        $r = $abook->add($addaddr, $abook->localbackend);
+    /**************************************************
+     * Add new address                                *
+     **************************************************/
+    if (isset($addaddr)) {
+        if (isset($backend)) {
+            $r = $abook->add($addaddr, $backend);
+        } else {
+            $r = $abook->add($addaddr, $abook->localbackend);
+        }
 
-        // Handle error messages
-        if(!$r) {
-            // Remove backend name from error string
+        /* Handle error messages */
+        if (!$r) {
+            /* Remove backend name from error string */
             $errstr = $abook->error;
-            $errstr = ereg_replace('^\[.*\] *', '', $errstr);
+            $errstr = preg_replace('/^\[.*\] */', '', $errstr);
 
             $formerror = $errstr;
             $showaddrlist = false;
             $defdata = $addaddr;
         }
-
     } else {
 
-        /***********************************************
-        // Delete address(es)
-        // ***********************************************
-        if((!empty($deladdr)) && sizeof($sel) > 0) {
+        /************************************************
+         * Delete address(es)                           *
+         ************************************************/
+        if ((!empty($deladdr)) && sizeof($sel) > 0) {
             $orig_sel = $sel;
             sort($sel);
 
-            // The selected addresses are identidied by "backend:nickname".
-            // Sort the list and process one backend at the time
+            /* The selected addresses are identified by "backend_nickname". *
+             * Sort the list and process one backend at the time            */
             $prevback  = -1;
             $subsel    = array();
             $delfailed = false;
 
-            for($i = 0 ; (($i < sizeof($sel)) && !$delfailed) ; $i++) {
-                list($sbackend, $snick) = explode(':', $sel[$i]);
+            for ($i = 0 ; (($i < sizeof($sel)) && !$delfailed) ; $i++) {
+                list($sbackend, $snick) = explode('_', $sel[$i], 2);
 
-                // When we get to a new backend, process addresses in
-                // previous one.
-                if($prevback != $sbackend && $prevback != -1) {
+                /* When we get to a new backend, process addresses in *
+                 * previous one.                                      */
+                if ($prevback != $sbackend && $prevback != -1) {
 
                     $r = $abook->remove($subsel, $prevback);
-                    if(!$r) {
+                    if (!$r) {
                         $formerror = $abook->error;
                         $i = sizeof($sel);
                         $delfailed = true;
@@ -150,32 +153,75 @@ if($REQUEST_METHOD == 'POST') {
                     $subsel   = array();
                 }
 
-                // Queue for processing
+                /* Queue for processing */
                 array_push($subsel, $snick);
                 $prevback = $sbackend;
             }
 
-            if(!$delfailed) {
+            if (!$delfailed) {
                 $r = $abook->remove($subsel, $prevback);
-                if(!$r) { // Handle errors
+                if (!$r) { /* Handle errors */
                     $formerror = $abook->error;
                     $delfailed = true;
                 }
             }
 
-            if($delfailed) {
+            if ($delfailed) {
                 $showaddrlist = true;
                 $defselected  = $orig_sel;
             }
 
-        } else {
+        /************************************************
+         * Compose to selected address(es)              *
+         ************************************************/
+        } else if ((!empty($compose_to)) && sizeof($sel) > 0) {
+            $orig_sel = $sel;
+            sort($sel);
+
+            // The selected addresses are identified by "backend_nickname"
+            $lookup_failed = false;
+            $send_to = '';
 
-            // ***********************************************
-            // Update/modify address
-            // ***********************************************
-            if(!empty($editaddr)) {
+            for ($i = 0 ; (($i < sizeof($sel)) && !$lookup_failed) ; $i++) {
+                list($sbackend, $snick) = explode('_', $sel[$i], 2);
 
-                // Stage one: Copy data into form
+                $data = $abook->lookup($snick, $sbackend);
+
+                if (!$data) {
+                    $formerror = $abook->error;
+                    $lookup_failed = true;
+                    break;
+                } else {
+                    $addr = $abook->full_address($data);
+                    if (!empty($addr))
+                        $send_to .= $addr . ', ';
+                }
+            }
+
+
+            if ($lookup_failed || empty($send_to)) {
+                $showaddrlist = true;
+                $defselected  = $sel;
+
+                // we skipped the page header above for this functionality, so add it here
+                displayPageHeader($color);
+            }
+
+
+            // send off to compose screen
+            else {
+                $send_to = trim($send_to, ', ');
+                header('Location: ' . $base_uri . 'src/compose.php?send_to=' . rawurlencode($send_to));
+                exit;
+            }
+
+        } else {
+
+            /***********************************************
+             * Update/modify address                       *
+             ***********************************************/
+            if (!empty($editaddr)) {
+                /* Stage one: Copy data into form */
                 if (isset($sel) && sizeof($sel) > 0) {
                     if(sizeof($sel) > 1) {
                         $formerror = _("You can only edit one address at the time");
@@ -183,196 +229,216 @@ if($REQUEST_METHOD == 'POST') {
                         $defselected = $sel;
                     } else {
                         $abortform = true;
-                        list($ebackend, $enick) = explode(':', $sel[0]);
+                        list($ebackend, $enick) = explode('_', current($sel), 2);
                         $olddata = $abook->lookup($enick, $ebackend);
-
-                        // Display the "new address" form
-                        print "<FORM ACTION=\"$PHP_SELF\" METHOD=\"POST\">\n";
-                        print "<TABLE WIDTH=100% COLS=1 ALIGN=CENTER>\n";
-                        print "<TR><TD BGCOLOR=\"$color[0]\" ALIGN=CENTER>\n<STRONG>";
-                        print _("Update address");
-                        print "<STRONG>\n</TD></TR>\n";
-                        print "</TABLE>\n";
-                        address_form("editaddr", _("Update address"), $olddata);
-                        printf("<INPUT TYPE=hidden NAME=oldnick VALUE=\"%s\">\n",
-                            htmlspecialchars($olddata["nickname"]));
-                        printf("<INPUT TYPE=hidden NAME=backend VALUE=\"%s\">\n",
-                            htmlspecialchars($olddata["backend"]));
-                        print "<INPUT TYPE=hidden NAME=doedit VALUE=1>\n";
-                        print '</FORM>';
-                    }
-                } else {
-
-                    // Stage two: Write new data
-                    if($doedit = 1) {
-                        $newdata = $editaddr;
-                        $r = $abook->modify($oldnick, $newdata, $backend);
-
-                        // Handle error messages
-                        if(!$r) {
-                            // Display error
-                            print "<TABLE WIDTH=100% COLS=1 ALIGN=CENTER>\n";
-                            print "<TR><TD ALIGN=CENTER>\n<br><STRONG>";
-                            print "<FONT COLOR=\"$color[2]\">"._("ERROR").": ".
-                                $abook->error."</FONT>";
-                            print "<STRONG>\n</TD></TR>\n";
-                            print "</TABLE>\n";
-
-                            // Display the "new address" form again
-                            printf("<FORM ACTION=\"%s\" METHOD=\"POST\">\n", $PHP_SELF);
-                            print "<TABLE WIDTH=100% COLS=1 ALIGN=CENTER>\n";
-                            print "<TR><TD BGCOLOR=\"$color[0]\" ALIGN=CENTER>\n<STRONG>";
-                            print _("Update address");
-                            print "<STRONG>\n</TD></TR>\n";
-                            print "</TABLE>\n";
-                            address_form("editaddr", _("Update address"), $newdata);
-                            printf("<INPUT TYPE=hidden NAME=oldnick VALUE=\"%s\">\n",
-                                htmlspecialchars($oldnick));
-                            printf("<INPUT TYPE=hidden NAME=backend VALUE=\"%s\">\n",
-                                htmlspecialchars($backend));
-                            print "<INPUT TYPE=hidden NAME=doedit VALUE=1>\n";
-                            print '</FORM>';
-
-                            $abortform = true;
+                        // Test if $olddata really contains anything and return an error message if it doesn't
+                        if (!$olddata) {
+                            error_box(nl2br(sm_encode_html_special_chars($abook->error)));
+                        } else {
+                            /* Display the "new address" form */
+                            echo abook_create_form($form_url, 'editaddr',
+                                                   _("Update address"),
+                                                   _("Update address"),
+                                                   $current_backend,
+                                                   $olddata);
+                            echo addHidden('oldnick', $olddata['nickname']).
+                                addHidden('backend', $olddata['backend']).
+                                addHidden('doedit', '1').
+                                '</form>';
                         }
-                    } else {
-
-                        // Should not get here...
-                        plain_error_message(_("Unknown error"), $color);
+                    }
+                } elseif ($doedit == 1) {
+                    /* Stage two: Write new data */
+                    $newdata = $editaddr;
+                    $r = $abook->modify($oldnick, $newdata, $backend);
+
+                    /* Handle error messages */
+                    if (!$r) {
+                        /* Display error */
+                        plain_error_message( nl2br(sm_encode_html_special_chars($abook->error)));
+
+                        /* Display the "new address" form again */
+                        echo abook_create_form($form_url, 'editaddr',
+                                               _("Update address"),
+                                               _("Update address"),
+                                               $current_backend,
+                                               $newdata);
+                        echo addHidden('oldnick', $oldnick).
+                            addHidden('backend', $backend).
+                            addHidden('doedit',  '1').
+                            "\n" . '</form>';
                         $abortform = true;
                     }
-                }
-            } /* !empty($editaddr)                  - Update/modify address */
-        } /* (!empty($deladdr)) && sizeof($sel) > 0 - Delete address(es) */
-    } /* !empty($addaddr['nickname'])               - Add new address */
+                } else {
+                    /**
+                     * $editaddr is set, but $sel (address selection in address listing)
+                     * and $doedit (address edit form) are not set.
+                     * Assume that user clicked on "Edit address" without selecting any address.
+                     */
+                    $formerror = _("Please select address that you want to edit");
+                    $showaddrlist = true;
+                } /* end of edit stage detection */
+            } /* !empty($editaddr)                     - Update/modify address */
+        } /* (!empty($deladdr)) && sizeof($sel) > 0    - Delete address(es) 
+          or (!empty($compose_to)) && sizeof($sel) > 0 - Compose to address(es) */
+    } /* !empty($addaddr['nickname'])                  - Add new address */
 
     // Some times we end output before forms are printed
     if($abortform) {
-       print "</BODY></HTML>\n";
-       exit();
+//FIXME: use footer.tpl; remove HTML from core
+        echo "</body></html>\n";
+        exit();
     }
 }
 
 
-// ===================================================================
-// The following is only executed on a GET request, or on a POST when
-// a user is added, or when "delete" or "modify" was successful.
-// ===================================================================
+/* =================================================================== *
+ * The following is only executed on a GET request, or on a POST when  *
+ * a user is added, or when "delete" or "modify" was successful.       *
+ * =================================================================== */
 
-// Display error messages
-if(!empty($formerror)) {
-    print "<TABLE WIDTH=100% COLS=1 ALIGN=CENTER>\n";
-    print "<TR><TD ALIGN=CENTER>\n<br><STRONG>";
-    print "<FONT COLOR=\"$color[2]\">"._("ERROR").": $formerror</FONT>";
-    print "<STRONG>\n</TD></TR>\n";
-    print "</TABLE>\n";
+/* Display error messages */
+if (!empty($formerror)) {
+    plain_error_message(nl2br(sm_encode_html_special_chars($formerror)));
 }
 
 
-// Display the address management part
-if($showaddrlist) {
-    // Get and sort address list
-    $alist = $abook->list_addr();
-    if(!is_array($alist)) {
-        plain_error_message($abook->error, $color);
-        exit;
+/* Display the address management part */
+$addresses = array();
+while (list($k, $backend) = each ($abook->backends)) {
+    $a = array();
+    $a['BackendID'] = $backend->bnum;
+    $a['BackendSource'] = $backend->sname;
+    $a['BackendWritable'] = $backend->writeable;
+    $a['Addresses'] = array();
+
+    // don't do address lookup if we are not viewing that backend
+    //
+    if ($backend->bnum == $current_backend) {
+        $alist = $abook->list_addr($backend->bnum);
+
+        /* check return (array with data or boolean false) */
+        if (is_array($alist)) {
+            usort($alist,'alistcmp');
+    
+            $a['Addresses'] = formatAddressList($alist);
+  
+            $addresses[$backend->bnum] = $a;
+        } else {
+            // list_addr() returns boolean
+            plain_error_message(nl2br(sm_encode_html_special_chars($abook->error)));
+        }
+    } else {
+        $addresses[$backend->bnum] = $a;
     }
+}
 
-    usort($alist,'alistcmp');
-    $prevbackend = -1;
-    $headerprinted = false;
-
-    echo "<p align=center><a href=\"#AddAddress\">" .
-         _("Add address") . "</a></p>\n";
-
-    // List addresses
-    printf("<FORM ACTION=\"%s\" METHOD=\"POST\">\n", $PHP_SELF);
-    while(list($undef,$row) = each($alist)) {
-
-    // New table header for each backend
-        if($prevbackend != $row["backend"]) {
-            if($prevbackend >= 0) {
-                print "<TR><TD COLSPAN=5 ALIGN=center>\n";
-                printf("<INPUT TYPE=submit NAME=editaddr VALUE=\"%s\">\n",
-                    _("Edit selected"));
-                printf("<INPUT TYPE=submit NAME=deladdr VALUE=\"%s\">\n",
-                    _("Delete selected"));
-                echo "</tr>\n";
-                print '<TR><TD COLSPAN="5" ALIGN=center>';
-                print "&nbsp;<BR></TD></TR></TABLE>\n";
-            }
 
-            print "<TABLE WIDTH=\"95%\" COLS=1 ALIGN=CENTER>\n";
-            print "<TR><TD BGCOLOR=\"$color[0]\" ALIGN=CENTER>\n<STRONG>";
-            print $row["source"];
-            print "<STRONG>\n</TD></TR>\n";
-            print "</TABLE>\n";
-
-            print '<TABLE COLS="5" BORDER="0" CELLPADDING="1" CELLSPACING="0" WIDTH="90%" ALIGN="center">';
-            printf('<TR BGCOLOR="%s"><TH ALIGN=left WIDTH="%s">&nbsp;'.
-            '<TH ALIGN=left WIDTH="%s">%s<TH ALIGN=left WIDTH="%s">%s'.
-            '<TH ALIGN=left WIDTH="%s">%s<TH ALIGN=left WIDTH="%s">%s'.
-            "</TR>\n", $color[9], "1%",
-            "1%", _("Nickname"),
-            "1%", _("Name"),
-            "1%", _("E-mail"),
-            "%",  _("Info"));
-            $line = 0;
-            $headerprinted = true;
-        } // End of header
-
-        $prevbackend = $row['backend'];
-
-        // Check if this user is selected
-        if(in_array($row['backend'].':'.$row['nickname'], $defselected)) {
-            $selected = 'CHECKED';
-        } else {
-            $selected = '';
+$current_page_args = array(
+                           'abook_sort_order' => $abook_sort_order,
+                           'new_bnum'         => $current_backend,
+                           'page_number'      => $page_number,
+                          );
+
+
+// note that plugins can add to $current_page_args as well as
+// filter the address list
+//
+$temp = array(&$addresses, &$current_backend, &$page_number, &$current_page_args);
+do_hook('abook_list_filter', $temp);
+
+
+// NOTE to address book backend authors and plugin authors: if a backend does
+//      pagination (which might be more efficient), it needs to place a key
+//      in every address listing it returns called "paginated", whose value
+//      should evaluate to boolean TRUE.  However, if a plugin will also be
+//      used on the hook above to filter the addresses (perhaps by group), then
+//      the backend should be made compatible with the filtering plugin and
+//      should do the actual filtering too.  Otherwise, the backend will paginate
+//      before filtering has taken place, the output of which is clearly wrong.
+//      It is proposed that filtering be based on a GET/POST variable called
+//      "abook_groups_X" where X is the current backend number.  The value of
+//      this varaible would be an array of possible filter names, which the
+//      plugin and the backend would both know about.  The plugin would only
+//      filter based on that value if the backend didn't already do it.  The
+//      backend can insert a "grouped" key into all address listings, whose
+//      value evaluates to boolean TRUE, telling the plugin not to do any
+//      filtering itself.  For an example of this implementation, see the
+//      Address Book Grouping and Pagination plugin.
+
+
+// if no pagination was done by a plugin or the abook
+// backend (which is indicated by the presence of a
+// "paginated" key within all of the address entries
+// in the list of addresses for the backend currently
+// being viewed), then we provide default pagination
+//
+$total_addresses = 0;
+if (!$show_all
+ && is_array($addresses[$current_backend]['Addresses'])
+ && empty($addresses[$current_backend]['Addresses'][0]['paginated'])) {
+
+    // at this point, we assume the current list is
+    // the *full* list
+    //
+    $total_addresses = sizeof($addresses[$current_backend]['Addresses']);
+
+    // iterate through all the entries, building list of addresses
+    // to keep based on current page
+    //
+    $new_address_list = array();
+    $total_pages = ceil($total_addresses / $page_size);
+    if ($page_number > $total_pages) $page_number = $total_pages;
+    $page_count = 1;
+    $page_item_count = 0;
+    foreach ($addresses[$current_backend]['Addresses'] as $addr) {
+        $page_item_count++;
+        if ($page_item_count > $page_size) {
+            $page_count++;
+            $page_item_count = 1;
         }
-
-        // Print one row
-        printf("<TR%s>",
-            (($line % 2) ? " bgcolor=\"$color[0]\"" : ""));
-        print  '<TD VALIGN=top ALIGN=center WIDTH="1%"><SMALL>';
-        printf('<INPUT TYPE=checkbox %s NAME="sel[]" VALUE="%s:%s"></SMALL></TD>',
-            $selected, $row["backend"], $row["nickname"]);
-        printf('<TD VALIGN=top NOWRAP WIDTH="%s">&nbsp;%s&nbsp;</TD>'.
-            '<TD VALIGN=top NOWRAP WIDTH="%s">&nbsp;%s&nbsp;</TD>',
-            "1%", $row["nickname"],
-            "1%", $row["name"]);
-        printf('<TD VALIGN=top NOWRAP WIDTH="%s">&nbsp;<A HREF="compose.php?send_to=%s">%s</A>&nbsp;</TD>'."\n",
-            "1%", rawurlencode($row["email"]), $row["email"]);
-        printf('<TD VALIGN=top WIDTH="%s">&nbsp;%s&nbsp;</TD>',
-            "%", $row["label"]);
-        print "</TR>\n";
-        $line++;
+        if ($page_count == $page_number)
+            $new_address_list[] = $addr;
     }
+    $addresses[$current_backend]['Addresses'] = $new_address_list;
 
-    // End of list. Close table.
-    if($headerprinted) {
-        print "<TR><TD COLSPAN=5 ALIGN=center>\n";
-        printf("<INPUT TYPE=submit NAME=editaddr VALUE=\"%s\">\n",
-            _("Edit selected"));
-        printf("<INPUT TYPE=submit NAME=deladdr VALUE=\"%s\">\n",
-            _("Delete selected"));
-        print "</TR></TABLE></FORM>";
-    }
-} // end of addresslist
+}
 
 
-// Display the "new address" form
-echo "<a name=\"AddAddress\"></a>\n" .
-     "<FORM ACTION=\"$PHP_SELF\" NAME=f_add METHOD=\"POST\">\n".
-     "<TABLE WIDTH=100% COLS=1 ALIGN=CENTER>\n".
-     "<TR><TD BGCOLOR=\"$color[0]\" ALIGN=CENTER>\n<STRONG>";
-printf(_("Add to %s"), $abook->localbackendname);
-echo "<STRONG>\n</TD></TR>\n".
-     "</TABLE>\n";
-address_form('addaddr', _("Add address"), $defdata);
-echo '</FORM>';
+if ($showaddrlist) {
+    
+    $oTemplate->assign('show_all', $show_all);
+    $oTemplate->assign('page_number', $page_number);
+    $oTemplate->assign('page_size', $page_size);
+    $oTemplate->assign('total_addresses', $total_addresses);
+    $oTemplate->assign('abook_compact_paginator', $abook_compact_paginator);
+    $oTemplate->assign('abook_page_selector', $abook_page_selector);
+    $oTemplate->assign('current_page_args', $current_page_args);
+    $oTemplate->assign('abook_page_selector_max', $abook_page_selector_max);
+    $oTemplate->assign('addresses', $addresses);
+    $oTemplate->assign('current_backend', $current_backend);
+    $oTemplate->assign('backends', $list_backends);
+    $oTemplate->assign('abook_has_extra_field', $abook->add_extra_field);
+    $oTemplate->assign('compose_new_win', $compose_new_win);
+    $oTemplate->assign('compose_height', $compose_height);
+    $oTemplate->assign('compose_width', $compose_width);
+    $oTemplate->assign('form_action', $form_url);
+        
+    $oTemplate->display('addressbook_list.tpl');
+    
+}
+
+/* Display the "new address" form */
+//FIXME: Remove HTML from here! (echo abook_create_form() is OK, since it is all template based output
+echo '<a name="AddAddress"></a>' . "\n";
+echo abook_create_form($form_url, 'addaddr',
+                       _("Add to address book"),
+                       _("Add address"),
+                       $current_backend,
+                       $defdata);
+echo "</form>\n";
 
-// Add hook for anything that wants on the bottom
-do_hook('addressbook_bottom');
-?>
+/* Hook for extra address book blocks */
+do_hook('addressbook_bottom', $null);
 
-</BODY></HTML>
+$oTemplate->display('footer.tpl');