<?php require('framework/session.php'); ?>
<?php require('framework/ready.php'); ?>
<?php require('style/layout/header.php'); ?>
<div id="content_wrapper">
<div class="content">
<?php
echo '<div class="content_left">
<div id="breadcrumb">
<ul class="crumbs">
<li class="first"><a href="index.php" style="z-index:9;"><span></span>' . $lang['index'] . '</a></li>
<li><a href="messages.php" style="z-index:8;">' . $lang['messages'] . '</a></li>
<li><a href="new_message.php" style="z-index:7;">' . $lang['new_message'] . '</a></li>
</ul>
</div>
</div>
<div class="content_right">';
include('modules/search.inc.php');
echo '</div>
<div class="clear_long"></div>';
$ret = 1;
echo '<div class="main_menu">';
$ret = include 'framework/templates/'.$main_content['menu'];
echo '<div id="line"></div>';
$ret = include 'framework/templates/'.$main_content['infos'];
echo '</div>';
echo '<div class="main_content">';
echo '<h1 class="p_space">' . $lang['new_message'] . '</h1>';
$form = TRUE; $title = ''; $reciver = ''; $content = '';
if(isset($_POST['title'], $_POST['reciver'], $_POST['content'])) {
$title = $_POST['title'];
$reciver = $_POST['reciver'];
$content = $_POST['content'];
if($_POST['title']!='' AND $_POST['reciver']!='' AND $_POST['content']!='') {
$title = mysql_real_escape_string($title);
$recip = mysql_real_escape_string($reciver);
$content = mysql_real_escape_string($content);
$sql = mysql_fetch_assoc(mysql_query("SELECT count(id) AS reciver, id AS recipid, (select count(*) FROM messages) AS npm FROM members WHERE name='" . $reciver . "'"));
if($sql['reciver'] == 1) {
if($sql['recipid']!=(int)$_SESSION['id']) {
$id = $sql['npm']+1;
if(mysql_query("INSERT INTO messages (msg, assign, title, user1, user2, content, date, user1read, user2read)VALUES('" . $id . "', '1', '" . $title . "', '" . (int)$_SESSION['id'] . "', '" . $sql['recipid'] . "', '" . $content . "', NOW(), 'yes', 'no')") OR die(mysql_error())) {
echo '<p class="success">' . $lang['message_sent_successfully'] . '</p>
<p><a href="messages.php">' . $lang['messages'] . '</a> - <a href="outbox.php">' . $lang['outbox'] . '</a></p>';
$form = FALSE;
}else{
$error = '<p class="false">' . $lang['an_error_occurred'] . '</p>';
}
}else{
$error = '<p class="false">' . $lang['not_sent_yourself'] . '</p>';
}
}else{
$error = '<p class="false">' . $lang['user_not_exists'] . '</p>';
}
}else{
$error = '<p class="false">' . $lang['not_filled_in_all_fields'] . '</p>';
}
}elseif(is_numeric($_GET['reciver'])) {
$reciver = intval($_GET['reciver']);
}
if($form) {
if(isset($error)) {
echo $error;
}
if(isset($_GET['name'])) {
$name = mysql_real_escape_string($_GET['name']);
}
echo '<form action="new_message.php" method="post" name="pm">
<p><input type="text" id="title" name="title" class="textfields" required size="40"> ' . $lang['subject'] . '</p>
<p><input type="text" id="reciver" name="reciver" class="textfields" ';
if(isset($name)) { echo 'value="' . $name . '"'; }
echo ' required size="40"> ' . $lang['receiver'] . ' <small>(' . $lang['re_name'] . ')</small></p>
<textarea cols="45" rows="8" name="content" id="content" class="textareas">' . htmlentities($content, ENT_QUOTES) . '</textarea>
<p><input type="submit" name="submit" value="' . $lang['send'] . '" alt="' . $lang['send'] . '" class="buttons"></p>
</form>';
}
?>
<?php require('style/layout/footer.php'); ?>