]> CyberLeo.Net >> Repos - Github/YOURLS.git/blob - includes/functions.php
Fixed yourls_get_next_decimal() (was still using deprecated table)
[Github/YOURLS.git] / includes / functions.php
1 <?php\r
2 /*\r
3  * YOURLS\r
4  * Function library\r
5  */\r
6 \r
7 if (defined('YOURLS_DEBUG') && YOURLS_DEBUG == true) {\r
8         error_reporting(E_ALL);\r
9 } else {\r
10         error_reporting(E_ERROR | E_WARNING | E_PARSE | E_USER_ERROR | E_USER_WARNING);\r
11 }\r
12 \r
13 // function to convert an integer (1337) to a string (3jk). Input integer processed as a string to beat PHP's int max value\r
14 function yourls_int2string( $id ) {\r
15         $str = yourls_base2base(trim(strval($id)), 10, YOURLS_URL_CONVERT);\r
16         if (YOURLS_URL_CONVERT <= 37)\r
17                 $str = strtolower($str);\r
18         return $str;\r
19 }\r
20 \r
21 // function to convert a string (3jk) to an integer (1337)\r
22 function yourls_string2int( $str ) {\r
23         if (YOURLS_URL_CONVERT <= 37)\r
24                 $str = strtolower($str);\r
25         return yourls_base2base(trim($str), YOURLS_URL_CONVERT, 10);\r
26 }\r
27 \r
28 // Make sure a link keyword (ie "1fv" as in "site.com/1fv") is valid.\r
29 function yourls_sanitize_string($in) {\r
30         if (YOURLS_URL_CONVERT <= 37)\r
31                 $in = strtolower($in);\r
32         return substr(preg_replace('/[^a-zA-Z0-9]/', '', $in), 0, 199);\r
33 }\r
34 \r
35 // A few sanity checks on the URL\r
36 function yourls_sanitize_url($url) {\r
37         // make sure there's only one 'http://' at the beginning (prevents pasting a URL right after the default 'http://')\r
38         $url = str_replace('http://http://', 'http://', $url);\r
39 \r
40         // make sure there's a protocol, add http:// if not\r
41         if ( !preg_match('!^([a-zA-Z]+://)!', $url ) )\r
42                 $url = 'http://'.$url;\r
43         \r
44         $url = yourls_clean_url($url);\r
45         \r
46         return substr( $url, 0, 199 );\r
47 }\r
48 \r
49 // Function to filter all invalid characters from a URL. Stolen from WP's clean_url()\r
50 function yourls_clean_url( $url ) {\r
51         $url = preg_replace('|[^a-z0-9-~+_.?#=!&;,/:%@$\|*\'()\\x80-\\xff]|i', '', $url);\r
52         $strip = array('%0d', '%0a', '%0D', '%0A');\r
53         $url = yourls_deep_replace($strip, $url);\r
54         $url = str_replace(';//', '://', $url);\r
55         \r
56         return $url;\r
57 }\r
58 \r
59 // Perform a replacement while a string is found, eg $subject = '%0%0%0DDD', $search ='%0D' -> $result =''\r
60 // Stolen from WP's _deep_replace\r
61 function yourls_deep_replace($search, $subject){\r
62         $found = true;\r
63         while($found) {\r
64                 $found = false;\r
65                 foreach( (array) $search as $val ) {\r
66                         while(strpos($subject, $val) !== false) {\r
67                                 $found = true;\r
68                                 $subject = str_replace($val, '', $subject);\r
69                         }\r
70                 }\r
71         }\r
72         \r
73         return $subject;\r
74 }\r
75 \r
76 \r
77 // Make sure an integer is a valid integer (PHP's intval() limits to too small numbers)\r
78 // TODO FIXME FFS: unused ?\r
79 function yourls_sanitize_int($in) {\r
80         return ( substr(preg_replace('/[^0-9]/', '', strval($in) ), 0, 20) );\r
81 }\r
82 \r
83 // Make sure a integer is safe\r
84 // Note: this is not checking for integers, since integers on 32bits system are way too limited\r
85 // TODO: find a way to validate as integer\r
86 function yourls_intval($in) {\r
87         return mysql_real_escape_string($in);\r
88 }\r
89 \r
90 // Escape a string\r
91 function yourls_escape( $in ) {\r
92         return mysql_real_escape_string($in);\r
93 }\r
94 \r
95 // Check to see if a given keyword is reserved (ie reserved URL or an existing page)\r
96 // Returns bool\r
97 function yourls_keyword_is_reserved( $keyword ) {\r
98         global $yourls_reserved_URL;\r
99         \r
100         if ( in_array( $keyword, $yourls_reserved_URL)\r
101                 or file_exists(dirname(dirname(__FILE__))."/pages/$keyword.php")\r
102                 or is_dir(dirname(dirname(__FILE__))."/$keyword")\r
103         )\r
104                 return true;\r
105         \r
106         return false;\r
107 }\r
108 \r
109 // Function: Get IP Address. Returns a DB safe string.\r
110 function yourls_get_IP() {\r
111         if(!empty($_SERVER['HTTP_CLIENT_IP'])) {\r
112                 $ip_address = $_SERVER['HTTP_CLIENT_IP'];\r
113         } else if(!empty($_SERVER['HTTP_X_FORWARDED_FOR'])) {\r
114                 $ip_address = $_SERVER['HTTP_X_FORWARDED_FOR'];\r
115         } else if(!empty($_SERVER['REMOTE_ADDR'])) {\r
116                 $ip_address = $_SERVER['REMOTE_ADDR'];\r
117         } else {\r
118                 $ip_address = '';\r
119         }\r
120         if(strpos($ip_address, ',') !== false) {\r
121                 $ip_address = explode(',', $ip_address);\r
122                 $ip_address = $ip_address[0];\r
123         }\r
124         \r
125         $ip_address = preg_replace( '/[^0-9a-fA-F:., ]/', '', $ip_address );\r
126 \r
127         return $ip_address;\r
128 }\r
129 \r
130 // Add the "Edit" row\r
131 function yourls_table_edit_row( $keyword ) {\r
132         global $ydb;\r
133         \r
134         $table = YOURLS_DB_TABLE_URL;\r
135         $keyword = yourls_sanitize_string( $keyword );\r
136         $id = yourls_string2int( $keyword ); // used as HTML #id\r
137         $url = $ydb->get_row("SELECT `url` FROM `$table` WHERE `keyword` = '$keyword';");\r
138         $safe_url = stripslashes( $url->url );\r
139         $www = YOURLS_SITE;\r
140         \r
141         if( $url ) {\r
142                 $return = <<<RETURN\r
143 <tr id="edit-$id" class="edit-row"><td colspan="5"><strong>Original URL</strong>:<input type="text" id="edit-url-$id" name="edit-url-$id" value="$safe_url" class="text" size="100" /> <strong>Short URL</strong>: $www/<input type="text" id="edit-keyword-$id" name="edit-keyword-$id" value="$keyword" class="text" size="10" /></td><td colspan="1"><input type="button" id="edit-submit-$id" name="edit-submit-$id" value="Save" title="Save new values" class="button" onclick="edit_save('$id');" />&nbsp;<input type="button" id="edit-close-$id" name="edit-close-$id" value="X" title="Cancel editing" class="button" onclick="hide_edit('$id');" /><input type="hidden" id="old_keyword_$id" value="$keyword"/></td></tr>\r
144 RETURN;\r
145         } else {\r
146                 $return = '<tr><td colspan="6">Error, URL not found</td></tr>';\r
147         }\r
148         \r
149         return $return;\r
150 }\r
151 \r
152 // Add a link row\r
153 function yourls_table_add_row( $keyword, $url, $ip, $clicks, $timestamp ) {\r
154         $keyword = yourls_sanitize_string( $keyword );\r
155         $id = yourls_string2int( $keyword ); // used as HTML #id\r
156         $date = date( 'M d, Y H:i', $timestamp+( YOURLS_HOURS_OFFSET * 3600) );\r
157         $clicks = number_format($clicks);\r
158         $www = YOURLS_SITE;\r
159         $shorturl = YOURLS_SITE.'/'.$keyword;\r
160         \r
161         return <<<ROW\r
162 <tr id="id-$id"><td id="keyword-$id"><a href="$shorturl">$shorturl</a></td><td id="url-$id"><a href="$url" title="$url">$url</a></td><td id="timestamp-$id">$date</td><td>$ip</td><td>$clicks</td><td class="actions"><input type="button" id="edit-button-$id" name="edit-button" value="Edit" class="button" onclick="edit('$id');" />&nbsp;<input type="button" id="delete-button-$id" name="delete-button" value="Del" class="button" onclick="remove('$id');" /><input type="hidden" id="keyword_$id" value="$keyword"/></td></tr>\r
163 ROW;\r
164 }\r
165 \r
166 // Get next id a new link will have if no custom keyword provided\r
167 function yourls_get_next_decimal() {\r
168         return (int)yourls_get_option( 'next_id' );\r
169 }\r
170 \r
171 // Update id for next link with no custom keyword\r
172 function yourls_update_next_decimal( $int = '' ) {\r
173         $int = ( $int == '' ) ? yourls_get_next_decimal() + 1 : (int)$int ;\r
174         return yourls_update_option( 'newt_id', $int );\r
175 }\r
176 \r
177 // Delete a link in the DB\r
178 function yourls_delete_link_by_keyword( $keyword ) {\r
179         global $ydb;\r
180 \r
181         $table = YOURLS_DB_TABLE_URL;\r
182         $keyword = yourls_sanitize_string( $keyword );\r
183         return $ydb->query("DELETE FROM `$table` WHERE `keyword` = '$keyword';");\r
184 }\r
185 \r
186 // SQL query to insert a new link in the DB. Needs sanitized data. Returns boolean for success or failure of the inserting\r
187 function yourls_insert_link_in_db($url, $keyword) {\r
188         global $ydb;\r
189 \r
190         $table = YOURLS_DB_TABLE_URL;\r
191         $timestamp = date('Y-m-d H:i:s');\r
192         $ip = yourls_get_IP();\r
193         $insert = $ydb->query("INSERT INTO `$table` VALUES('$keyword', '$url', '$timestamp', '$ip', 0);");\r
194         \r
195         return (bool)$insert;\r
196 }\r
197 \r
198 // Add a new link in the DB, either with custom keyword, or find one\r
199 function yourls_add_new_link( $url, $keyword = '' ) {\r
200         global $ydb;\r
201 \r
202         if ( !$url || $url == 'http://' || $url == 'https://' ) {\r
203                 $return['status'] = 'fail';\r
204                 $return['code'] = 'error:nourl';\r
205                 $return['message'] = 'Missing URL input';\r
206                 return $return;\r
207         }\r
208 \r
209         $table = YOURLS_DB_TABLE_URL;\r
210         $url = mysql_real_escape_string( yourls_sanitize_url($url) );\r
211         $strip_url = stripslashes($url);\r
212         $url_exists = $ydb->get_row("SELECT keyword,url FROM `$table` WHERE `url` = '".$strip_url."';");\r
213         $ip = yourls_get_IP();\r
214         $return = array();\r
215 \r
216         // New URL : store it\r
217         if( !$url_exists ) {\r
218 \r
219                 // Custom keyword provided\r
220                 if ( $keyword ) {\r
221                         $keyword = mysql_real_escape_string(yourls_sanitize_string($keyword));\r
222                         if ( !yourls_keyword_is_free($keyword) ) {\r
223                                 // This shorturl either reserved or taken already\r
224                                 $return['status'] = 'fail';\r
225                                 $return['code'] = 'error:keyword';\r
226                                 $return['message'] = 'Short URL '.$keyword.' already exists in database or is reserved';\r
227                         } else {\r
228                                 // all clear, store !\r
229                                 yourls_insert_link_in_db($url, $keyword);\r
230                                 $return['url'] = array('keyword' => $keyword, 'url' => $strip_url, 'date' => date('Y-m-d H:i:s'), 'ip' => $ip );\r
231                                 $return['status'] = 'success';\r
232                                 $return['message'] = $strip_url.' added to database';\r
233                                 $return['html'] = yourls_table_add_row( $keyword, $url, $ip, 0, time() );\r
234                                 $return['shorturl'] = YOURLS_SITE .'/'. $keyword;\r
235                         }\r
236 \r
237                 // Create random keyword        \r
238                 } else {\r
239                         $timestamp = date('Y-m-d H:i:s');\r
240                         $id = yourls_get_next_decimal();\r
241                         $ok = false;\r
242                         do {\r
243                                 $keyword = yourls_int2string( $id );\r
244                                 $free = yourls_keyword_is_free($keyword);\r
245                                 $add_url = @yourls_insert_link_in_db($url, $keyword);\r
246                                 $ok = ($free && $add_url);\r
247                                 if ( $ok === false && $add_url === 1 ) {\r
248                                         // we stored something, but shouldn't have (ie reserved id)\r
249                                         $delete = yourls_delete_link_by_keyword( $keyword );\r
250                                         $return['extra_info'] .= '(deleted '.$keyword.')';\r
251                                 } else {\r
252                                         // everything ok, populate needed vars\r
253                                         $return['url'] = array('keyword' => $keyword, 'url' => $strip_url, 'date' => $timestamp, 'ip' => $ip );\r
254                                         $return['status'] = 'success';\r
255                                         $return['message'] = $strip_url.' added to database';\r
256                                         $return['html'] = yourls_table_add_row( $keyword, $url, $ip, 0, time() );\r
257                                         $return['shorturl'] = YOURLS_SITE .'/'. $keyword;\r
258                                 }\r
259                                 $id++;\r
260                         } while (!$ok);\r
261                         @yourls_update_next_decimal($id);\r
262                 }\r
263         } else {\r
264                 // URL was already stored\r
265                 $return['status'] = 'fail';\r
266                 $return['code'] = 'error:url';\r
267                 $return['message'] = $strip_url.' already exists in database';\r
268                 $return['shorturl'] = YOURLS_SITE .'/'. $url_exists->keyword;\r
269         }\r
270 \r
271         return $return;\r
272 }\r
273 \r
274 \r
275 // Edit a link\r
276 function yourls_edit_link($url, $keyword, $newkeyword='') {\r
277         global $ydb;\r
278 \r
279         $table = YOURLS_DB_TABLE_URL;\r
280         $url = mysql_real_escape_string(yourls_sanitize_url($url));\r
281         $keyword = yourls_sanitize_string( $keyword );\r
282         $newkeyword = yourls_sanitize_string( $newkeyword );\r
283         $strip_url = stripslashes($url);\r
284         $old_url = $ydb->get_var("SELECT `url` FROM `$table` WHERE `keyword` = '$keyword';");\r
285         \r
286         // Check if new URL is not here already\r
287         if ($old_url != $url) {\r
288                 $new_url_already_there = intval($ydb->get_var("SELECT COUNT(keyword) FROM `$table` WHERE `url` = '$strip_url';"));\r
289         } else {\r
290                 $new_url_already_there = false;\r
291         }\r
292         \r
293         // Check if the new keyword is not here already\r
294         if ( $newkeyword != $keyword ) {\r
295                 $keyword_is_ok = yourls_keyword_is_free( $newkeyword );\r
296         } else {\r
297                 $keyword_is_ok = true;\r
298         }\r
299         \r
300         // All clear, update\r
301         if ( !$new_url_already_there && $keyword_is_ok ) {\r
302                 $timestamp4screen = date( 'Y M d H:i', time()+( yourls_HOURS_OFFSET * 3600) );\r
303                 $timestamp4db = date('Y-m-d H:i:s', time()+( yourls_HOURS_OFFSET * 3600) );\r
304                 $update_url = $ydb->query("UPDATE `$table` SET `url` = '$url', `timestamp` = '$timestamp4db', `keyword` = '$newkeyword' WHERE `keyword` = '$keyword';");\r
305                 if( $update_url ) {\r
306                         $return['url'] = array( 'keyword' => $newkeyword, 'shorturl' => YOURLS_SITE.'/'.$newkeyword, 'url' => $strip_url, 'date' => $timestamp4screen);\r
307                         $return['status'] = 'success';\r
308                         $return['message'] = 'Link updated in database';\r
309                 } else {\r
310                         $return['status'] = 'fail';\r
311                         $return['message'] = 'Error updating '.$strip_url.' (Short URL: '.$keyword.') to database';\r
312                 }\r
313         \r
314         // Nope\r
315         } else {\r
316                 $return['status'] = 'fail';\r
317                 $return['message'] = 'URL or keyword already exists in database';\r
318         }\r
319         \r
320         return $return;\r
321 }\r
322 \r
323 \r
324 // Check if keyword id is free (ie not already taken, and not reserved)\r
325 function yourls_keyword_is_free( $keyword ) {\r
326         global $ydb;\r
327 \r
328         $table = YOURLS_DB_TABLE_URL;\r
329         if ( yourls_keyword_is_reserved($keyword) )\r
330                 return false;\r
331                 \r
332         $already_exists = $ydb->get_var("SELECT COUNT(`keyword`) FROM `$table` WHERE `keyword` = '$keyword';");\r
333         if ( $already_exists )\r
334                 return false;\r
335 \r
336         return true;\r
337 }\r
338 \r
339 \r
340 // Display a page\r
341 function yourls_page( $page ) {\r
342         $include = dirname(dirname(__FILE__))."/pages/$page.php";\r
343         if (!file_exists($include)) {\r
344                 die("Page '$page' not found");\r
345         }\r
346         include($include);\r
347         die();  \r
348 }\r
349 \r
350 // Connect to DB\r
351 function yourls_db_connect() {\r
352         global $ydb;\r
353 \r
354         if (!defined('YOURLS_DB_USER')\r
355                 or !defined('YOURLS_DB_PASS')\r
356                 or !defined('YOURLS_DB_NAME')\r
357                 or !defined('YOURLS_DB_HOST')\r
358                 or !class_exists('ezSQL_mysql')\r
359         ) die ('DB config/class missing');\r
360         \r
361         $ydb =  new ezSQL_mysql(YOURLS_DB_USER, YOURLS_DB_PASS, YOURLS_DB_NAME, YOURLS_DB_HOST);\r
362         if ( $ydb->last_error )\r
363                 die( $ydb->last_error );\r
364         \r
365         if ( defined('YOURLS_DEBUG') && YOURLS_DEBUG === true )\r
366                 $ydb->show_errors = true;\r
367         \r
368         // return $ydb;\r
369 }\r
370 \r
371 // Return JSON output. Compatible with PHP prior to 5.2\r
372 function yourls_json_encode($array) {\r
373         if (function_exists('json_encode')) {\r
374                 return json_encode($array);\r
375         } else {\r
376                 require_once(dirname(__FILE__).'/functions-json.php');\r
377                 return yourls_array_to_json($array);\r
378         }\r
379 }\r
380 \r
381 // Return XML output.\r
382 function yourls_xml_encode($array) {\r
383         require_once(dirname(__FILE__).'/functions-xml.php');\r
384         $converter= new yourls_array2xml;\r
385         return $converter->array2xml($array);\r
386 }\r
387 \r
388 // Return long URL associated with keyword. Optional $notfound = string default message if nothing found\r
389 function yourls_get_longurl( $keyword, $notfound = false ) {\r
390         global $ydb;\r
391         $keyword = yourls_sanitize_string( $keyword );\r
392         $table = YOURLS_DB_TABLE_URL;\r
393         $url = stripslashes($ydb->get_var("SELECT `url` FROM `$table` WHERE `keyword` = '$keyword'"));\r
394         \r
395         if( $url )\r
396                 return $url;\r
397                 \r
398         return $notfound;       \r
399 }\r
400 \r
401 // Update click count on a short URL\r
402 function yourls_update_clicks( $keyword ) {\r
403         global $ydb;\r
404         $keyword = yourls_sanitize_string( $keyword );\r
405         $table = YOURLS_DB_TABLE_URL;\r
406         return $ydb->query("UPDATE `$table` SET `clicks` = clicks + 1 WHERE `keyword` = '$keyword'");\r
407 }\r
408 \r
409 \r
410 \r
411 // Return array for API stat requests\r
412 function yourls_api_stats( $filter, $limit ) {\r
413         global $ydb;\r
414 \r
415         switch( $filter ) {\r
416                 case 'bottom':\r
417                         $sort_by = 'clicks';\r
418                         $sort_order = 'asc';\r
419                         break;\r
420                 case 'last':\r
421                         $sort_by = 'timestamp';\r
422                         $sort_order = 'desc';\r
423                         break;\r
424                 case 'rand':\r
425                 case 'random':\r
426                         $sort_by = 'RAND()';\r
427                         $sort_order = '';\r
428                         break;\r
429                 case 'top':\r
430                 default:\r
431                         $sort_by = 'clicks';\r
432                         $sort_order = 'desc';\r
433                         break;\r
434         }\r
435         \r
436         $limit = intval( $limit );\r
437         $table_url = YOURLS_DB_TABLE_URL;\r
438         $results = $ydb->get_results("SELECT * FROM $table_url WHERE 1=1 ORDER BY $sort_by $sort_order LIMIT 0, $limit;");\r
439 \r
440         $return = array();\r
441         $i = 1;\r
442 \r
443         foreach ($results as $res) {\r
444                 $return['links']['link_'.$i++] = array(\r
445                         'shorturl' => YOURLS_SITE .'/'. $res->keyword,\r
446                         'url' => $res->url,\r
447                         'timestamp' => $res->timestamp,\r
448                         'ip' => $res->ip,\r
449                         'clicks' => $res->clicks\r
450                 );\r
451         }\r
452 \r
453         $return['stats'] = yourls_get_db_stats();\r
454 \r
455         return $return;\r
456 }\r
457 \r
458 \r
459 // Get total number of URLs and sum of clicks. Input: optional "AND WHERE" clause. Returns array\r
460 function yourls_get_db_stats( $where = '' ) {\r
461         global $ydb;\r
462         $table_url = YOURLS_DB_TABLE_URL;\r
463 \r
464         $totals = $ydb->get_row("SELECT COUNT(keyword) as count, SUM(clicks) as sum FROM $table_url WHERE 1=1 $where");\r
465         return array( 'total_links' => $totals->count, 'total_clicks' => $totals->sum );\r
466 }\r
467 \r
468 // Return API result. Dies after this\r
469 function yourls_api_output( $mode, $return ) {\r
470         switch ( $mode ) {\r
471                 case 'json':\r
472                         header('Content-type: application/json');\r
473                         echo yourls_json_encode($return);\r
474                         break;\r
475                 \r
476                 case 'xml':\r
477                         header('Content-type: application/xml');\r
478                         echo yourls_xml_encode($return);\r
479                         break;\r
480                         \r
481                 case 'simple':\r
482                 default:\r
483                         echo $return['shorturl'];\r
484                         break;\r
485         }\r
486         die();\r
487 }\r
488 \r
489 // Display HTML head and <body> tag\r
490 function yourls_html_head( $context = 'index' ) {\r
491         // Load components as needed\r
492         switch ( $context ) {\r
493                 case 'bookmark':\r
494                         $share = true;\r
495                         $insert = true;\r
496                         $tablesorter = true;\r
497                         break;\r
498                         \r
499                 case 'index':\r
500                         $share = false;\r
501                         $insert = true;\r
502                         $tablesorter = true;\r
503                         break;\r
504                 \r
505                 case 'install':\r
506                 case 'login':\r
507                 case 'new':\r
508                 case 'tools':\r
509                 case 'upgrade':\r
510                         $share = false;\r
511                         $insert = false;\r
512                         $tablesorter = false;\r
513                         break;\r
514         }\r
515         \r
516         ?>\r
517 <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">\r
518 <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">\r
519 <head>\r
520         <title>YOURLS &raquo; Your Own URL Shortener | <?php echo YOURLS_SITE; ?></title>\r
521         <link rel="icon" type="image/gif" href="<?php echo YOURLS_SITE; ?>/images/favicon.gif" />\r
522         <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />\r
523         <meta name="copyright" content="Copyright &copy; 2008-<?php echo date('Y'); ?> YOURS" />\r
524         <meta name="author" content="Ozh Richard, Lester Chan" />\r
525         <meta name="description" content="Insert URL &laquo; YOURLS &raquo; Your Own URL Shortener' | <?php echo YOURLS_SITE; ?>" />\r
526         <script src="<?php echo YOURLS_SITE; ?>/js/jquery-1.3.2.min.js" type="text/javascript"></script>\r
527         <link rel="stylesheet" href="<?php echo YOURLS_SITE; ?>/css/style.css" type="text/css" media="screen" />\r
528         <?php if ($tablesorter) { ?>\r
529                 <link rel="stylesheet" href="<?php echo YOURLS_SITE; ?>/css/tablesorter.css" type="text/css" media="screen" />\r
530                 <script src="<?php echo YOURLS_SITE; ?>/js/jquery.tablesorter.min.js" type="text/javascript"></script>\r
531         <?php } ?>\r
532         <?php if ($insert) { ?>\r
533                 <script src="<?php echo YOURLS_SITE; ?>/js/insert.js" type="text/javascript"></script>\r
534         <?php } ?>\r
535         <?php if ($share) { ?>\r
536                 <script src="<?php echo YOURLS_SITE; ?>/js/share.js" type="text/javascript"></script>\r
537         <?php } ?>\r
538 </head>\r
539 <body class="<?php echo $context; ?>">\r
540         <?php\r
541 }\r
542 \r
543 // Display HTML footer (including closing body & html tags)\r
544 function yourls_html_footer() {\r
545         global $ydb;\r
546 \r
547         $num_queries = ( $ydb && $ydb->num_queries  ? ' &ndash; '.$ydb->num_queries.' queries' : '' );\r
548         ?>\r
549         <div id="footer"><p>Powered by <a href="http://yourls.org/" title="YOURLS">YOURLS</a> v<?php echo YOURLS_VERSION; echo $num_queries; ?></p></div>\r
550         </body>\r
551         </html>\r
552         <?php\r
553 }\r
554 \r
555 // Display "Add new URL" box\r
556 function yourls_html_addnew( $url = '', $keyword = '' ) {\r
557         $url = $url ? $url : 'http://';\r
558         ?>\r
559         <div id="new_url">\r
560                 <div>\r
561                         <form id="new_url_form" action="" method="get">\r
562                                 <div><strong>Enter the URL</strong>:<input type="text" id="add-url" name="url" value="<?php echo $url; ?>" class="text" size="90" />\r
563                                 Optional: <strong>Custom short URL</strong>:<input type="text" id="add-keyword" name="keyword" value="<?php echo $keyword; ?>" maxlength="12" class="text" size="8" />\r
564                                 <input type="button" id="add-button" name="add-button" value="Shorten The URL" class="button" onclick="add();" /></div>\r
565                         </form>\r
566                         <div id="feedback" style="display:none"></div>\r
567                 </div>\r
568         </div>\r
569         <?php\r
570 }\r
571 \r
572 // Display main table's footer\r
573 function yourls_html_tfooter( $params = array() ) {\r
574         extract( $params ); // extract $search_text, $page, $search_in_sql ...\r
575 \r
576         ?>\r
577         <tfoot>\r
578                 <tr>\r
579                         <th colspan="4" style="text-align: left;">\r
580                                 <form action="" method="get">\r
581                                         <div>\r
582                                                 <div style="float:right;">\r
583                                                         <input type="submit" id="submit-sort" value="Filter" class="button primary" />\r
584                                                         &nbsp;\r
585                                                         <input type="button" id="submit-clear-filter" value="Clear Filter" class="button" onclick="window.parent.location.href = 'index.php'" />\r
586                                                 </div>\r
587 \r
588                                                 Search&nbsp;for&nbsp;\r
589                                                 <input type="text" name="s_search" class="text" size="20" value="<?php echo $search_text; ?>" />\r
590                                                 &nbsp;in&nbsp;\r
591                                                 <select name="s_in" size="1">\r
592                                                         <!-- <option value="id"<?php if($search_in_sql == 'id') { echo ' selected="selected"'; } ?>>ID</option> -->\r
593                                                         <option value="url"<?php if($search_in_sql == 'url') { echo ' selected="selected"'; } ?>>URL</option>\r
594                                                         <option value="ip"<?php if($search_in_sql == 'ip') { echo ' selected="selected"'; } ?>>IP</option>\r
595                                                 </select>\r
596                                                 &ndash;&nbsp;Order&nbsp;by&nbsp;\r
597                                                 <select name="s_by" size="1">\r
598                                                         <option value="id"<?php if($sort_by_sql == 'id') { echo ' selected="selected"'; } ?>>ID</option>\r
599                                                         <option value="url"<?php if($sort_by_sql == 'url') { echo ' selected="selected"'; } ?>>URL</option>\r
600                                                         <option value="timestamp"<?php if($sort_by_sql == 'timestamp') { echo ' selected="selected"'; } ?>>Date</option>\r
601                                                         <option value="ip"<?php if($sort_by_sql == 'ip') { echo ' selected="selected"'; } ?>>IP</option>\r
602                                                         <option value="clicks"<?php if($sort_by_sql == 'clicks') { echo ' selected="selected"'; } ?>>Clicks</option>\r
603                                                 </select>\r
604                                                 <select name="s_order" size="1">\r
605                                                         <option value="asc"<?php if($sort_order_sql == 'asc') { echo ' selected="selected"'; } ?>>Ascending</option>\r
606                                                         <option value="desc"<?php if($sort_order_sql == 'desc') { echo ' selected="selected"'; } ?>>Descending</option>\r
607                                                 </select>\r
608                                                 &ndash;&nbsp;Show&nbsp;\r
609                                                 <input type="text" name="perpage" class="text" size="2" value="<?php echo $perpage; ?>" />&nbsp;rows<br/>\r
610                                                 \r
611                                                 Show links with\r
612                                                 <select name="link_filter" size="1">\r
613                                                         <option value="more"<?php if($link_filter === 'more') { echo ' selected="selected"'; } ?>>more</option>\r
614                                                         <option value="less"<?php if($link_filter === 'less') { echo ' selected="selected"'; } ?>>less</option>\r
615                                                 </select>\r
616                                                 than\r
617                                                 <input type="text" name="link_limit" class="text" size="4" value="<?php echo $link_limit; ?>" />clicks\r
618 \r
619                                                 \r
620                                         </div>\r
621                                 </form>\r
622                         </th>\r
623                         <th colspan="3" style="text-align: right;">\r
624                                 Pages (<?php echo $total_pages; ?>):\r
625                                 <?php\r
626                                         if ($page >= 4) {\r
627                                                 echo '<b><a href="'.$base_page.'?s_by='.$sort_by_sql.'&amp;s_order='.$sort_order_sql.$search_url.'&amp;perpage='.$perpage.'&amp;page=1'.'" title="Go to First Page">&laquo; First</a></b> ... ';\r
628                                         }\r
629                                         if($page > 1) {\r
630                                                 echo ' <b><a href="'.$base_page.'?s_by='.$sort_by_sql.'&amp;s_order='.$sort_order_sql.$search_url.'&amp;perpage='.$perpage.'&amp;page='.($page-1).'" title="&laquo; Go to Page '.($page-1).'">&laquo;</a></b> ';\r
631                                         }\r
632                                         for($i = $page - 2 ; $i  <= $page +2; $i++) {\r
633                                                 if ($i >= 1 && $i <= $total_pages) {\r
634                                                         if($i == $page) {\r
635                                                                 echo "<strong>[$i]</strong> ";\r
636                                                         } else {\r
637                                                                 echo '<a href="'.$base_page.'?s_by='.$sort_by_sql.'&amp;s_order='.$sort_order_sql.$search_url.'&amp;perpage='.$perpage.'&amp;page='.($i).'" title="Page '.$i.'">'.$i.'</a> ';\r
638                                                         }\r
639                                                 }\r
640                                         }\r
641                                         if($page < $total_pages) {\r
642                                                 echo ' <b><a href="'.$base_page.'?s_by='.$sort_by_sql.'&amp;s_order='.$sort_order_sql.$search_url.'&amp;perpage='.$perpage.'&amp;page='.($page+1).'" title="Go to Page '.($page+1).' &raquo;">&raquo;</a></b> ';\r
643                                         }\r
644                                         if (($page+2) < $total_pages) {\r
645                                                 echo ' ... <b><a href="'.$base_page.'?s_by='.$sort_by_sql.'&amp;s_order='.$sort_order_sql.$search_url.'&amp;perpage='.$perpage.'&amp;page='.($total_pages).'" title="Go to Last Page">Last &raquo;</a></b>';\r
646                                         }\r
647                                 ?>\r
648                         </th>\r
649                 </tr>\r
650         </tfoot>\r
651         <?php\r
652 }\r
653 \r
654 // Display the Quick Share box of the tools.php page\r
655 function yourls_share_box( $longurl, $shorturl, $title='', $text='' ) {\r
656         $text = ( $text ? '"'.$text.'" ' : '' );\r
657         $title = ( $title ? "$title " : '' );\r
658         $share = htmlentities( $title.$text.$shorturl );\r
659         $_share = rawurlencode( $share );\r
660         $_url = rawurlencode( $shorturl );\r
661         $count = 140 - strlen( $share );\r
662         ?>\r
663         \r
664         <div id="shareboxes">\r
665 \r
666                 <div id="copybox" class="share">\r
667                 <h2>Your short link</h2>\r
668                         <p><input id="copylink" class="text" size="40" value="<?php echo $shorturl; ?>" /></p>\r
669                         <p><small>Original link: <a href="<?php echo $longurl; ?>"><?php echo $longurl; ?></a></small></p>\r
670                 </div>\r
671 \r
672                 <div id="sharebox" class="share">\r
673                         <h2>Quick Share</h2>\r
674                         <div id="tweet">\r
675                                 <span id="charcount"><?php echo $count; ?></span>\r
676                                 <textarea id="tweet_body"><?php echo $share; ?></textarea>\r
677                         </div>\r
678                         <p id="share_links">Share with \r
679                                 <a id="share_tw" href="http://twitter.com/home?status=<?php echo $_share; ?>" title="Tweet this!" onclick="share('tw');return false">Twitter</a>\r
680                                 <a id="share_fb" href="http://www.facebook.com/share.php?u=<?php echo $_url; ?>" title="Share on Facebook" onclick="share('fb');return false;">Facebook</a>\r
681                                 <a id="share_ff" href="http://friendfeed.com/share/bookmarklet/frame#title=<?php echo $_share; ?>" title="Share on Friendfeed" onclick="javascript:share('ff');return false;">FriendFeed</a>\r
682                         </p>\r
683                         </div>\r
684                 </div>\r
685         \r
686         </div>\r
687         \r
688         <?php\r
689 }\r
690 \r
691 // Get number of SQL queries performed\r
692 function yourls_get_num_queries() {\r
693         global $ydb;\r
694 \r
695         return $ydb->num_queries;\r
696 }\r
697 \r
698 // Compat http_build_query for PHP4\r
699 if (!function_exists('http_build_query')) {\r
700         function http_build_query($data, $prefix=null, $sep=null) {\r
701                 return yourls_http_build_query($data, $prefix, $sep);\r
702         }\r
703 }\r
704 \r
705 // from php.net (modified by Mark Jaquith to behave like the native PHP5 function)\r
706 function yourls_http_build_query($data, $prefix=null, $sep=null, $key='', $urlencode=true) {\r
707         $ret = array();\r
708 \r
709         foreach ( (array) $data as $k => $v ) {\r
710                 if ( $urlencode)\r
711                         $k = urlencode($k);\r
712                 if ( is_int($k) && $prefix != null )\r
713                         $k = $prefix.$k;\r
714                 if ( !empty($key) )\r
715                         $k = $key . '%5B' . $k . '%5D';\r
716                 if ( $v === NULL )\r
717                         continue;\r
718                 elseif ( $v === FALSE )\r
719                         $v = '0';\r
720 \r
721                 if ( is_array($v) || is_object($v) )\r
722                         array_push($ret,yourls_http_build_query($v, '', $sep, $k, $urlencode));\r
723                 elseif ( $urlencode )\r
724                         array_push($ret, $k.'='.urlencode($v));\r
725                 else\r
726                         array_push($ret, $k.'='.$v);\r
727         }\r
728 \r
729         if ( NULL === $sep )\r
730                 $sep = ini_get('arg_separator.output');\r
731 \r
732         return implode($sep, $ret);\r
733 }\r
734 \r
735 // Returns a sanitized a user agent string. Given what I found on http://www.user-agents.org/ it should be OK.\r
736 function yourls_get_user_agent() {\r
737         if ( !isset( $_SERVER['HTTP_USER_AGENT'] ) )\r
738                 return '-';\r
739         \r
740         $ua = strip_tags( html_entity_decode( $_SERVER['HTTP_USER_AGENT'] ));\r
741         $ua = preg_replace('![^0-9a-zA-Z\':., /{}\(\)\[\]\+@&\!\?;_\-=~\*\#]!', '', $ua );\r
742                 \r
743         return substr( $ua, 0, 254 );\r
744 }\r
745 \r
746 // Redirect to another page\r
747 function yourls_redirect( $location, $code = 301 ) {\r
748         // Anti fool check: cannot redirect to the URL we currently are on\r
749         if( preg_replace('!^[^:]+://!', '', $location) != $_SERVER["SERVER_NAME"].$_SERVER['REQUEST_URI'] ) {\r
750                 $protocol = $_SERVER["SERVER_PROTOCOL"];\r
751                 if ( 'HTTP/1.1' != $protocol && 'HTTP/1.0' != $protocol )\r
752                         $protocol = 'HTTP/1.0';\r
753 \r
754                 $code = intval( $code );\r
755                 $desc = yourls_get_HTTP_status($code);\r
756 \r
757                 if ( php_sapi_name() != 'cgi-fcgi' )\r
758                                 header ("$protocol $code $desc"); // This causes problems on IIS and some FastCGI setups\r
759                 header("Location: $location");\r
760                 die();\r
761         }\r
762 }\r
763 \r
764 // Redirect to another page using Javascript\r
765 function yourls_redirect_javascript( $location ) {\r
766         echo <<<REDIR\r
767         <script type="text/javascript">\r
768         //window.location="$location";\r
769         </script>\r
770         <small>(if you are not redirected after 10 seconds, please <a href="$location">click here</a>)</small>\r
771 REDIR;\r
772 }\r
773 \r
774 // Return a HTTP status code\r
775 function yourls_get_HTTP_status( $code ) {\r
776         $code = intval( $code );\r
777         $headers_desc = array(\r
778                 100 => 'Continue',\r
779                 101 => 'Switching Protocols',\r
780                 102 => 'Processing',\r
781 \r
782                 200 => 'OK',\r
783                 201 => 'Created',\r
784                 202 => 'Accepted',\r
785                 203 => 'Non-Authoritative Information',\r
786                 204 => 'No Content',\r
787                 205 => 'Reset Content',\r
788                 206 => 'Partial Content',\r
789                 207 => 'Multi-Status',\r
790                 226 => 'IM Used',\r
791 \r
792                 300 => 'Multiple Choices',\r
793                 301 => 'Moved Permanently',\r
794                 302 => 'Found',\r
795                 303 => 'See Other',\r
796                 304 => 'Not Modified',\r
797                 305 => 'Use Proxy',\r
798                 306 => 'Reserved',\r
799                 307 => 'Temporary Redirect',\r
800 \r
801                 400 => 'Bad Request',\r
802                 401 => 'Unauthorized',\r
803                 402 => 'Payment Required',\r
804                 403 => 'Forbidden',\r
805                 404 => 'Not Found',\r
806                 405 => 'Method Not Allowed',\r
807                 406 => 'Not Acceptable',\r
808                 407 => 'Proxy Authentication Required',\r
809                 408 => 'Request Timeout',\r
810                 409 => 'Conflict',\r
811                 410 => 'Gone',\r
812                 411 => 'Length Required',\r
813                 412 => 'Precondition Failed',\r
814                 413 => 'Request Entity Too Large',\r
815                 414 => 'Request-URI Too Long',\r
816                 415 => 'Unsupported Media Type',\r
817                 416 => 'Requested Range Not Satisfiable',\r
818                 417 => 'Expectation Failed',\r
819                 422 => 'Unprocessable Entity',\r
820                 423 => 'Locked',\r
821                 424 => 'Failed Dependency',\r
822                 426 => 'Upgrade Required',\r
823 \r
824                 500 => 'Internal Server Error',\r
825                 501 => 'Not Implemented',\r
826                 502 => 'Bad Gateway',\r
827                 503 => 'Service Unavailable',\r
828                 504 => 'Gateway Timeout',\r
829                 505 => 'HTTP Version Not Supported',\r
830                 506 => 'Variant Also Negotiates',\r
831                 507 => 'Insufficient Storage',\r
832                 510 => 'Not Extended'\r
833         );\r
834 \r
835         if ( isset( $headers_desc[$code] ) )\r
836                 return $headers_desc[$code];\r
837         else\r
838                 return '';\r
839 }\r
840 \r
841 \r
842 // Log a redirect (for stats)\r
843 function yourls_log_redirect( $keyword ) {\r
844         global $ydb;\r
845         $table = YOURLS_DB_TABLE_LOG;\r
846         \r
847         $keyword = yourls_sanitize_string( $keyword );\r
848         $referrer = ( isset( $_SERVER['HTTP_REFERER'] ) ? yourls_sanitize_url( $_SERVER['HTTP_REFERER'] ) : 'direct' );\r
849         $ua = yourls_get_user_agent();\r
850         $ip = yourls_get_IP();\r
851         $location = yourls_get_location( $ip );\r
852         \r
853         return $ydb->query( "INSERT INTO `$table` VALUES ('', NOW(), '$keyword', '$referrer', '$ua', '$ip', '$location')" );\r
854 }\r
855 \r
856 // Converts an IP to a 2 letter country code, using GeoIP database if available in includes/geo/\r
857 function yourls_get_location( $ip = '', $default = '' ) {\r
858         if ( !file_exists( dirname(__FILE__).'/geo/GeoIP.dat') || !file_exists( dirname(__FILE__).'/geo/geoip.inc') )\r
859                 return $default;\r
860 \r
861         if ( $ip = '' )\r
862                 $ip = yourls_get_IP();\r
863                 \r
864         require_once( dirname(__FILE__).'/geo/geoip.inc') ;\r
865         $gi = geoip_open( dirname(__FILE__).'/geo/GeoIP.dat', GEOIP_STANDARD);\r
866         $location = geoip_country_code_by_addr($gi, $ip);\r
867         geoip_close($gi);\r
868 \r
869         return $location;\r
870 }\r
871 \r
872 // Check if an upgrade is needed\r
873 function yourls_upgrade_is_needed() {\r
874         // check YOURLS_VERSION && YOURLS_DB_VERSION exist && match values stored in YOURLS_DB_TABLE_OPTIONS\r
875         list( $currentver, $currentsql ) = yourls_get_current_version_from_sql();\r
876 \r
877         // Using floatval() to get 1.4 from 1.4-alpha\r
878         if( ( $currentver < floatval( YOURLS_VERSION ) ) || ( $currentsql < floatval( YOURLS_DB_VERSION ) ) )   \r
879                 return true;\r
880                 \r
881         return false;\r
882 }\r
883 \r
884 // Get current version & db version as stored in the options DB\r
885 function yourls_get_current_version_from_sql() {\r
886         if( !defined('YOURLS_DB_TABLE_OPTIONS') )\r
887                 die('<p>Your <tt>config.php</tt> does not contain all the required constant definitions. Please check <tt>config-sample.php</tt> and update your config accordingly, there are new stuffs!</p>');\r
888         \r
889         global $ydb;\r
890         $table = YOURLS_DB_TABLE_OPTIONS;\r
891         $currentver = @$ydb->get_var("SELECT `option_value` FROM $table WHERE `option_name` = 'version'");\r
892         $currentsql = @$ydb->get_var("SELECT `option_value` FROM $table WHERE `option_name` = 'db_version'");\r
893         if( !$currentver )\r
894                 $currentver = '1.3';\r
895         if( !$currentsql )\r
896                 $currentsql = '100';\r
897                 \r
898         return array( $currentver, $currentsql);\r
899 }\r
900 \r
901 // Read an option from DB (or from cache if available). Return value or $default if not found\r
902 function yourls_get_option( $option_name, $default = false ) {\r
903         if ( !isset( $ydb->option[$option_name] ) ) {\r
904                 global $ydb;\r
905                 $table = YOURLS_DB_TABLE_OPTIONS;\r
906                 $option_name = yourls_escape( $option_name );\r
907                 $row = $ydb->get_row( "SELECT `option_value` FROM `$table` WHERE `option_name` = '$option_name' LIMIT 1" );\r
908                 if ( is_object( $row) ) { // Has to be get_row instead of get_var because of funkiness with 0, false, null values\r
909                         $value = $row->option_value;\r
910                 } else { // option does not exist, so we must cache its non-existence\r
911                         $value = $default;\r
912                 }\r
913                 $ydb->option[$option_name] = yourls_maybe_unserialize( $value );\r
914         }\r
915 \r
916         return $ydb->option[$option_name];\r
917 }\r
918 \r
919 // Update (add if doesn't exist) an option to DB\r
920 function yourls_update_option( $option_name, $newvalue ) {\r
921         global $ydb;\r
922         $table = YOURLS_DB_TABLE_OPTIONS;\r
923 \r
924         $safe_option_name = yourls_escape( $option_name );\r
925 \r
926         $oldvalue = yourls_get_option( $safe_option_name );\r
927 \r
928         // If the new and old values are the same, no need to update.\r
929         if ( $newvalue === $oldvalue )\r
930                 return false;\r
931 \r
932         if ( false === $oldvalue ) {\r
933                 yourls_add_option( $option_name, $newvalue );\r
934                 return true;\r
935         }\r
936 \r
937         $_newvalue = yourls_escape( yourls_maybe_serialize( $newvalue ) );\r
938 \r
939         $ydb->query( "UPDATE `$table` SET `option_value` = '$_newvalue' WHERE `option_name` = '$option_name'");\r
940 \r
941         if ( $ydb->rows_affected == 1 ) {\r
942                 $ydb->option[$option_name] = $newvalue;\r
943                 return true;\r
944         }\r
945         return false;\r
946 }\r
947 \r
948 // Add an option to the DB\r
949 function yourls_add_option( $name, $value = '' ) {\r
950         global $ydb;\r
951         $table = YOURLS_DB_TABLE_OPTIONS;\r
952         $safe_name = yourls_escape( $name );\r
953 \r
954         // Make sure the option doesn't already exist. We can check the 'notoptions' cache before we ask for a db query\r
955         if ( false !== yourls_get_option( $safe_name ) )\r
956                 return;\r
957 \r
958         $_value = yourls_escape( yourls_maybe_serialize( $value ) );\r
959 \r
960         $ydb->query( "INSERT INTO `$table` (`option_name`, `option_value`) VALUES ('$name', '$_value')" );\r
961         $ydb->option[$name] = $value;\r
962         return;\r
963 }\r
964 \r
965 \r
966 // Delete an option from the DB\r
967 function yourls_delete_option( $name ) {\r
968         global $ydb;\r
969         $table = YOURLS_DB_TABLE_OPTIONS;\r
970         $name = yourls_escape( $name );\r
971 \r
972         // Get the ID, if no ID then return\r
973         $option = $ydb->get_row( "SELECT option_id FROM `$table` WHERE `option_name` = '$name'" );\r
974         if ( is_null($option) || !$option->option_id )\r
975                 return false;\r
976         $ydb->query( "DELETE FROM `$table` WHERE `option_name` = '$name'" );\r
977         return true;\r
978 }\r
979 \r
980 \r
981 \r
982 // Serialize data if needed. Stolen from WordPress\r
983 function yourls_maybe_serialize( $data ) {\r
984         if ( is_array( $data ) || is_object( $data ) )\r
985                 return serialize( $data );\r
986 \r
987         if ( yourls_is_serialized( $data ) )\r
988                 return serialize( $data );\r
989 \r
990         return $data;\r
991 }\r
992 \r
993 // Check value to find if it was serialized. Stolen from WordPress\r
994 function yourls_is_serialized( $data ) {\r
995         // if it isn't a string, it isn't serialized\r
996         if ( !is_string( $data ) )\r
997                 return false;\r
998         $data = trim( $data );\r
999         if ( 'N;' == $data )\r
1000                 return true;\r
1001         if ( !preg_match( '/^([adObis]):/', $data, $badions ) )\r
1002                 return false;\r
1003         switch ( $badions[1] ) {\r
1004                 case 'a' :\r
1005                 case 'O' :\r
1006                 case 's' :\r
1007                         if ( preg_match( "/^{$badions[1]}:[0-9]+:.*[;}]\$/s", $data ) )\r
1008                                 return true;\r
1009                         break;\r
1010                 case 'b' :\r
1011                 case 'i' :\r
1012                 case 'd' :\r
1013                         if ( preg_match( "/^{$badions[1]}:[0-9.E-]+;\$/", $data ) )\r
1014                                 return true;\r
1015                         break;\r
1016         }\r
1017         return false;\r
1018 }\r
1019 \r
1020 // Unserialize value only if it was serialized. Stolen from WP\r
1021 function yourls_maybe_unserialize( $original ) {\r
1022         if ( yourls_is_serialized( $original ) ) // don't attempt to unserialize data that wasn't serialized going in\r
1023                 return @unserialize( $original );\r
1024         return $original;\r
1025 }