public function getItem() { $params = $this->getState('params'); $documentId = (int) $this->getState('document.id'); if (!$documentId) { JError::raiseError(404, JText::_('COM_JUDOWNLOAD_DOCUMENT_NOT_FOUND')); return false; } $user = JFactory::getUser(); $db = JFactory::getDbo(); $query = $db->getQuery(true); $query->select('d.*, c.id AS cat_id'); $query->from('#__judownload_documents AS d'); $query->join('', '#__judownload_documents_xref AS dxref ON d.id = dxref.doc_id AND dxref.main=1'); $query->join('', '#__judownload_categories AS c ON c.id = dxref.cat_id'); $query->select('(SELECT COUNT(*) FROM #__judownload_files AS f WHERE f.doc_id = d.id AND f.published = 1) AS total_files'); $query->select('(SELECT COUNT(*) FROM #__judownload_comments AS cm WHERE cm.doc_id = d.id AND cm.approved = 1 AND cm.published = 1) AS total_comments'); $query->select('(SELECT COUNT(*) FROM #__judownload_subscriptions AS sub WHERE sub.item_id = d.id AND sub.type = "document" AND sub.published = 1) AS total_subscriptions'); $query->select('(SELECT COUNT(*) FROM #__judownload_reports AS r WHERE r.item_id = d.id AND r.type = "document") AS total_reports'); $query->select('(SELECT GROUP_CONCAT(catids.id ORDER BY dx_catids.main DESC, dx_catids.ordering ASC SEPARATOR ",") FROM (#__judownload_categories AS catids JOIN #__judownload_documents_xref AS dx_catids ON catids.id = dx_catids.cat_id) WHERE d.id = dx_catids.doc_id GROUP BY d.id) AS cat_ids'); $query->select('(SELECT GROUP_CONCAT(cattitles.title ORDER BY dx_cattitles.main DESC, dx_cattitles.ordering ASC SEPARATOR "|||") FROM (#__judownload_categories AS cattitles JOIN #__judownload_documents_xref AS dx_cattitles ON cattitles.id = dx_cattitles.cat_id) WHERE d.id = dx_cattitles.doc_id GROUP BY d.id) AS cat_titles'); $accessLevel = implode(',', $user->getAuthorisedViewLevels()); $db = JFactory::getDbo(); $date = JFactory::getDate(); $nullDate = $db->quote($db->getNullDate()); $nowDate = $db->quote($date->toSql()); $fieldQuery = $db->getQuery(true); $fieldQuery->select('field.id'); $fieldQuery->from('#__judownload_fields AS field'); $fieldQuery->where('field.group_id != 1'); $fieldQuery->where('field.details_view = 1'); $fieldQuery->where('field.published = 1'); $fieldQuery->where('field.publish_up <= ' . $nowDate); $fieldQuery->where('(field.publish_down = ' . $nullDate . ' OR field.publish_down > ' . $nowDate . ')'); $fieldQuery->where('(field.access IN (' . $accessLevel . ') OR field.who_can_download_can_access = 1)'); $category = JUDownloadFrontHelperCategory::getMainCategory($documentId); if (is_object($category)) { $fieldQuery->where('field.group_id = ' . $category->fieldgroup_id); } $fieldQuery->join('', '#__judownload_fields_groups AS field_group ON field.group_id = field_group.id'); $fieldQuery->where('field_group.published = 1'); $fieldQuery->where('field_group.access IN (' . $accessLevel . ')'); $fieldQuery->group('field.id'); $db->setQuery($fieldQuery); $fields = $db->loadObjectList(); foreach ($fields AS $field) { $query->select('IFNULL (fields_values_' . $field->id . '.value, "") AS field_values_' . $field->id); $query->join('LEFT', '#__judownload_fields_values AS fields_values_' . $field->id . ' ON fields_values_' . $field->id . '.doc_id = d.id AND fields_values_' . $field->id . '.field_id = ' . $field->id); } $query->where('d.id = ' . $documentId); $db->setQuery($query); $documentObject = $db->loadObject(); if (!is_object($documentObject)) { JError::raiseError(404, JText::_('COM_JUDOWNLOAD_DOCUMENT_NOT_FOUND')); return false; } $documentObject->params = JUDownloadFrontHelperDocument::getDocumentDisplayParams($documentObject->id); if (!$user->get('guest')) { $canEditDocument = JUDownloadFrontHelperPermission::canEditDocument($documentObject->id); $canDeleteDocument = JUDownloadFrontHelperPermission::canDeleteDocument($documentObject->id); $canEditStateDocument = JUDownloadFrontHelperPermission::canEditStateDocument($documentObject); $documentObject->params->set('access-edit', $canEditDocument); $documentObject->params->set('access-edit-state', $canEditStateDocument); $documentObject->params->set('access-delete', $canDeleteDocument); } $canReportDocument = JUDownloadFrontHelperPermission::canReportDocument($documentObject->id); $canContactDocument = JUDownloadFrontHelperPermission::canContactDocument($documentObject->id); $canRateDocument = JUDownloadFrontHelperPermission::canRateDocument($documentObject->id); $canDownloadDocument = JUDownloadFrontHelperPermission::canDownloadDocument($documentObject->id, false); $canCommentDocument = JUDownloadFrontHelperPermission::canComment($documentObject->id); $documentObject->params->set('access-report', $canReportDocument); $documentObject->params->set('access-contact', $canContactDocument); $documentObject->params->set('access-rate', $canRateDocument); $documentObject->params->set('access-download', $canDownloadDocument); $documentObject->params->set('access-comment', $canCommentDocument); $hasPassword = JUDownloadFrontHelperDocument::documentHasPassword($documentObject); $documentObject->params->set('has-password', $hasPassword); if ($hasPassword) { $validPassword = JUDownloadFrontHelperPassword::checkPassword($documentObject); } else { $validPassword = true; } $documentObject->params->set('valid-password', $validPassword); if ($canDownloadDocument && !$validPassword) { $documentObject->allow_enter_password = JUDownloadFrontHelperPassword::allowEnterPassword($documentObject->id); } $token = JSession::getFormToken(); $return = base64_encode(urlencode(JUri::getInstance())); $documentObject->download_link = JRoute::_('index.php?option=com_judownload&task=download.download&doc_id=' . $documentObject->id . '&' . $token . '=1'); $documentObject->download_link .= '&return=' . $return; if ($params->get('show_rule_messages', 'modal') != 'hide') { $downloadRuleErrorMessages = JUDownloadFrontHelperDocument::getDownloadRuleErrorMessages($documentObject->id); if ($downloadRuleErrorMessages !== true) { $documentObject->error_msg = $downloadRuleErrorMessages; } } $documentObject->template_params = new JRegistry($documentObject->template_params); if ($params->get('show_new_label', 1) && JUDownloadFrontHelper::isWithinXDays($documentObject->publish_up, $params->get('num_day_to_show_as_new', 10))) { $documentObject->label_new = true; } else { $documentObject->label_new = false; } if ($params->get('show_updated_label', 1) && JUDownloadFrontHelper::isWithinXDays($documentObject->updated, $params->get('num_day_to_show_as_updated', 10))) { $documentObject->label_updated = true; } else { $documentObject->label_updated = false; } if ($params->get('show_hot_label', 1) && JUDownloadFrontHelperDocument::checkHotDocument($documentObject->publish_up, $params->get('num_download_per_day_to_be_hot', 10), $documentObject->downloads)) { $documentObject->label_hot = true; } else { $documentObject->label_hot = false; } if ($params->get('show_featured_label', 1) && $documentObject->featured) { $documentObject->label_featured = true; } else { $documentObject->label_featured = false; } $documentObject->next_item = $this->getNextPrevItem($documentObject, 'next'); $documentObject->prev_item = $this->getNextPrevItem($documentObject, 'prev'); $documentObject->is_subscriber = $this->isSubscriber($user->id, $documentObject->id, 'document'); return $documentObject; }
public function addComment() { JSession::checkToken() or die(JText::_('JINVALID_TOKEN')); $user = JFactory::getUser(); $model = $this->getModel(); $rootComment = JUDownloadFrontHelperComment::getRootComment(); $data = $_POST; $documentId = $data['doc_id']; $params = JUDownloadHelper::getParams(null, $documentId); $parentId = $data['parent_id']; $model->setSessionCommentForm($documentId); if (strlen($data['title']) < 6) { $this->setError(JText::_('COM_JUDOWNLOAD_COMMENT_INVALID_TITLE')); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } if (strlen($data['guest_name']) < 1) { $this->setError(JText::_('COM_JUDOWNLOAD_COMMENT_INVALID_NAME')); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } if (isset($data['guest_email'])) { if (!preg_match('/^[\w\.-]+@[\w\.-]+\.[\w\.-]{2,6}$/', $data['guest_email'])) { $this->setError(JText::_('COM_JUDOWNLOAD_COMMENT_INVALID_EMAIL')); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } } if (isset($data['website'])) { if (!preg_match('/^(https?:\/\/)?([\w\.-]+)\.([\w\.-]{2,6})([\/\w \.-]*)*\/?$/i', $data['website'])) { $this->setError(JText::_('COM_JUDOWNLOAD_COMMENT_INVALID_WEBSITE')); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } } if (isset($data['comment_language'])) { $langArray = JHtml::_('contentlanguage.existing'); $langKey = array_keys($langArray); array_unshift($langKey, '*'); if (!in_array($data['comment_language'], $langKey)) { $this->setError(JText::_('COM_JUDOWNLOAD_COMMENT_INVALID_LANGUAGE')); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } } $minCharacter = $params->get('min_comment_characters', 20); $maxCharacter = $params->get('max_comment_characters', 1000); $comment = $data['comment']; $comment = JUDownloadFrontHelperComment::parseCommentText($comment, $documentId); $comment = strip_tags($comment); $commentCharacter = strlen($comment); if ($commentCharacter < $minCharacter || $commentCharacter > $maxCharacter) { $this->setError(JText::_('COM_JUDOWNLOAD_COMMENT_INVALID_COMMENT')); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } $showCaptcha = JUDownloadFrontHelperPermission::showCaptchaWhenComment($documentId); if ($showCaptcha) { $validCaptcha = JUDownloadFrontHelperCaptcha::checkCaptcha(); if (!$validCaptcha) { if ($parentId == $rootComment->id) { $form = '#judl-comment-form'; } else { $form = '#comment-reply-wrapper-' . $parentId; } $this->setError(JText::_('COM_JUDOWNLOAD_INVALID_CAPTCHA')); $this->setMessage($this->getError(), 'error'); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId . $form, false)); return false; } } if ($user->get('guest')) { if (!$model->checkNameOfGuest($documentId)) { $this->setError(JText::_('COM_JUDOWNLOAD_YOU_ARE_NOT_AUTHORIZED_TO_COMMENT_ON_THIS_DOCUMENT')); $this->setMessage($model->getError(), 'error'); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } if (!$model->checkEmailOfGuest()) { $this->setMessage($model->getError(), 'error'); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } } if ($parentId == $rootComment->id) { $canComment = JUDownloadFrontHelperPermission::canComment($documentId, $data['guest_email']); if (!$canComment) { $this->setError(JText::_('COM_JUDOWNLOAD_YOU_ARE_NOT_AUTHORIZED_TO_COMMENT_ON_THIS_DOCUMENT')); $this->setMessage($this->getError(), 'error'); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } } elseif ($parentId > 0 && $parentId != $rootComment->id) { $canReplyComment = JUDownloadFrontHelperPermission::canReplyComment($documentId, $parentId); if (!$canReplyComment) { $this->setError(JText::_('COM_JUDOWNLOAD_YOU_ARE_NOT_AUTHORIZED_TO_REPLY_THIS_COMMENT')); $this->setMessage($this->getError(), 'error'); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } } else { $this->setError(JText::_('COM_JUDOWNLOAD_INVALID_DATA')); $this->setMessage($this->getError(), 'error'); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } $dataValid = array(); if ($parentId == $rootComment->id) { $canRateDocument = JUDownloadFrontHelperPermission::canRateDocument($documentId); if ($canRateDocument) { $dataValid = $this->validateCriteria($data, $parentId); if (!$dataValid) { $this->setError(JText::_('COM_JUDOWNLOAD_INVALID_RATING_VALUE')); $this->setMessage($this->getError(), 'error'); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } } } $requiredPostNames = array('title', 'guest_name', 'guest_email', 'comment', 'parent_id', 'doc_id'); if ($params->get('website_field_in_comment_form', 0) == 2) { array_push($requiredPostNames, 'website'); } if ($parentId == $rootComment->id && $params->get('filter_comment_language', 0)) { array_push($requiredPostNames, 'comment_language'); } foreach ($requiredPostNames AS $requiredPostName) { if (trim($data[$requiredPostName]) == '') { $this->setError(JText::_('COM_JUDOWNLOAD_INVALID_INPUT_DATA')); $this->setMessage($this->getError(), 'error'); $this->setRedirect(JRoute::_('index.php?option=' . $this->option . '&view=' . $this->view_item . '&id=' . $documentId, false)); return false; } } $acceptedPostNames = array('title', 'guest_name', 'guest_email', 'language', 'website', 'comment', 'parent_id', 'doc_id', 'subscribe'); if ($params->get('website_field_in_comment_form', 0) == 2 || $params->get('website_field_in_comment_form', 0) == 1) { array_push($acceptedPostNames, 'website'); } if ($params->get('filter_comment_language', 0)) { array_push($acceptedPostNames, 'comment_language'); } foreach ($acceptedPostNames AS $acceptedPostName) { if (isset($data[$acceptedPostName])) { $dataValid[$acceptedPostName] = $data[$acceptedPostName]; } } $newCommentId = $model->saveComment($dataValid); if (!$newCommentId) { $this->setError($model->getError()); $this->setMessage($this->getError(), 'error'); $redirectUrl = JRoute::_(JUDownloadHelperRoute::getDocumentRoute($documentId), false); $this->setRedirect($redirectUrl); return false; } $session = JFactory::getSession(); $timeNow = JFactory::getDate()->toSql(); $timeNowStamp = strtotime($timeNow); $sessionCommentOnDocumentTime = 'judl-commented-' . $documentId; $sessionCommentTime = 'judl-commented'; $session->set($sessionCommentOnDocumentTime, $timeNowStamp); $session->set($sessionCommentTime, $timeNowStamp); $session->clear('judownload_commentform_' . $documentId); $this->setMessage(JText::_('COM_JUDOWNLOAD_ADD_COMMENT_SUCCESSFULLY')); $redirectUrl = JRoute::_(JUDownloadHelperRoute::getDocumentRoute($documentId) . '#comment-item-' . $newCommentId, false); $this->setRedirect($redirectUrl); return true; }