<?php

include_once('../global.php');

class NewsPage extends Page
{
  var $FullTitle = 'Aktualní informace';
  var $ShortTitle = 'Aktuality';
  var $UploadedFilesFolder = 'uploads/';

  function Show()
  {
    $Output = '';
    $Category = 1;
    $CategoryName = '';
    if(array_key_exists('category', $_GET)) $Category = $_GET['category'] * 1;
    if(array_key_exists('category', $_POST)) $Category = $_POST['category'] * 1;
    $DbResult = $this->Database->select('NewsCategory', '*', 'Id='.$Category.' ORDER BY Sequence');
    if($DbResult->num_rows > 0) 
    {
      $Row = $DbResult->fetch_array();
      $CategoryName = $Row['Caption'];
    }

    if(!array_key_exists('action',$_GET)) $_GET['action'] = '';
    switch($_GET['action'])
    {
      case 'view':
        if(!$this->System->Modules['User']->CheckPermission('News', 'Display', 'Item')) $Output .= 'Nemáte oprávnění';
        else 
        {
          $News = new News($this->Database);
          if(array_key_exists('id', $_GET)) $Id = $_GET['id'] * 1;
          $DbResult = $this->Database->query('SELECT `News`.*, `User`.`Name` FROM `News` LEFT JOIN `User` ON `User`.`Id`=`News`.`User` WHERE  `News`.`Id`='.$Id);
          if($DbResult->num_rows > 0)
          {
            $Row = $DbResult->fetch_array();
            if($Row['Name'] == '') $Author = $Row['Author'];
              else $Author = $Row['Name'];
            $Output .= '<div class="Panel"><div class="Title">'.$Row['Title'].' ('.HumanDate($Row['Date']).', '.$Author.')';
            if($this->System->Modules['User']->User['Id'] == $Row['User'])
            { 
              $Output .= '<div class="Action">';
              $Output .= '&nbsp;<a href="index.php?action=del&amp;category='.$Category.'&amp;id='.$Row['Id'].'">Smazat</a>';
              $Output .= '&nbsp;<a href="index.php?action=edit&amp;category='.$Category.'&amp;id='.$Row['Id'].'">Editovat</a>';
              $Output .= '</div>';
            }
            $Output .= '</div><div class="Content">'.$News->ModifyContent($Row['Content']).'<br />';
            if($Row['Link'] != '') $Output .= '<br/><a href="'.$Row['Link'].'">Odkaz</a>';
            if($Row['Enclosure'] != '')
            { 
              $Output .= '<br />Přílohy: ';
              $Enclosures = explode(';', $Row['Enclosure']);
        foreach($Enclosures as $Enclosure)
              {
          if(file_exists($this->UploadedFilesFolder.$Enclosure)) $Output .= ' <a href="'.$this->UploadedFilesFolder.$Enclosure.'">'.$Enclosure.'</a>';
              }
            }
            $Output .= '</div></div>';
          } else $Output .= 'Položka nenalezena.';
        }
        break;
      case 'add':
        $Output .= '<strong>Vložení nové aktuality:</strong><br />';
        if($Category == 2) $Output .= 'U inzerátů uvádějte co nejvíce informací ať případný zájemce ví co kupuje. Uvádějte kontaktní údaje jako Jméno, email, tel. číslo, ICQ. Dále navrženou cenu, detajlní popis předmětu nejlépe s odkazem na stránky výrobce. Pokud váš inzerát již není platný, připište do něj např. "Prodáno" pomocí editace.';
        $Output .= '<form enctype="multipart/form-data" action="?action=add2" method="post">'.
    'Kategorie: <select name="category">';
        $DbResult = $this->Database->select('NewsCategory', '*');
        while($DbRow = $DbResult->fetch_array()) 
        {
          if($this->System->Modules['User']->CheckPermission('News', 'Insert', 'Group', $DbRow['Id']))
          {
            if($DbRow['Id'] == $Category) $Selected = ' selected="1"'; else $Selected = '';
            $Output .= '<option value="'.$DbRow['Id'].'"'.$Selected.'>'.$DbRow['Caption'].'</option>';
          }
        }
        $Output .= '</select><br />'.
    'Nadpis:<br /><input type="text" size="54" name="title"><br />
    Obsah:<br /><textarea name="content" rows="20" cols="40"></textarea><br />
    Odkaz:<br /><input type="text" size="54" name="link"><br />
    Přílohy (Max. velikost souboru 1 MB):<br /><input type="hidden" name="MAX_FILE_SIZE" value="1000000">
    <input name="enclosure1" size="38" type="file"><br />
    <input name="enclosure2" size="38" type="file"><br />
    <input name="enclosure3" size="38" type="file"><br />
    <input type="submit" value="Vložit">
    </form>';
        break;
      case 'add2':
        $RemoteAddr = GetRemoteAddress();  
        if($this->System->Modules['User']->CheckPermission('News', 'Insert', 'Group', $Category))
        {
          //print_r($_FILES);
          // Process uploaded file
          $EnclosureFileNames = array('enclosure1', 'enclosure2', 'enclosure3');
          $Enclosures = '';
          foreach($EnclosureFileNames as $EnclosureName)
          if(array_key_exists($EnclosureName, $_FILES) and ($_FILES[$EnclosureName]['name'] != ''))
          {
            $UploadedFilePath = $this->UploadedFilesFolder.basename($_FILES[$EnclosureName]['name']); 
            if(move_uploaded_file($_FILES[$EnclosureName]['tmp_name'], $UploadedFilePath)) 
            {
              $Output .= 'Soubor '.basename($_FILES[$EnclosureName]['name']).' byl uložen na serveru.<br />';
          $Enclosures = $Enclosures.';'.basename($_FILES[$EnclosureName]['name']);
            } else
            {
              $Output .= 'Soubor '.basename($_FILES[$EnclosureName]['name']).' se nepodařilo nahrát na server.<br />';
            }
          }
          $Enclosures = substr($Enclosures, 1);

          $_POST['content'] = str_replace("\n",'<br />',$_POST['content']);
          $this->Database->insert('News',array('Category' => $Category, 'Title' => $_POST['title'], 'Content' => $_POST['content'], 'Date' => 'NOW()', 'IP' => $RemoteAddr, 'Enclosure' => $Enclosures, 'Author' => $this->System->Modules['User']->User['Name'], 'User' => $this->System->Modules['User']->User['Id'], 'Link' => $_POST['link']));
          $Output .= 'Aktualita přidána!<br />Pokud budete chtít vaši aktualitu smazat, klikněte na odkaz Smazat v seznamu všech aktualit v kategorii.<br /><br />';
          $Output .= '<a href="index.php?category='.$_POST['category'].'">Zpět na seznam aktualit</a>';
          $this->System->Modules['Log']->NewRecord('News', 'Aktualita přidána', $this->Database->insert_id);
        } else $Output .= 'Do této kategorie nemůžete vkládat aktuality!';
        break;
      case 'edit':
        $DbResult = $this->Database->query('SELECT * FROM News WHERE Id='.$_GET['id']);
        $Row = $DbResult->fetch_array();
        if($this->System->Modules['User']->User['Id'] == $Row['User'])
        {
          $Row['Content'] = str_replace('<br />', '', $Row['Content']);
          $Output .= '<strong>Editace aktuality v kategorii '.$CategoryName.':</strong><br />';
          $Output .= '<form action="index.php?action=update" method="post">'.
          '<input type="hidden" value="'.$_GET['id'].'" name="id">'.
          'Nadpis:<br /><input type="text" size="54" name="title" value="'.$Row['Title'].'"><br />'.
          'Obsah:<br /><textarea name="content" rows="20" cols="40">'.$Row['Content'].'</textarea><br />'.
          'Odkaz:<br /><input type="text" size="54" name="link"><br />'.
          '<input type="hidden" name="category" value="'.$Category.'"><br />'.
          '<input type="submit" value="Uložit">'.
          '</form>';
        } else $Output .= 'Nepovolená operace!';
        break;
      case 'update':
        $RemoteAddr = GetRemoteAddress();  
        $_POST['id'] = $_POST['id'] * 1;
        $DbResult = $this->Database->select('News', '*', 'Id='.$_POST['id']);
        if($DbResult->num_rows > 0)
        {
          $Row = $DbResult->fetch_array();
          if($this->System->Modules['User']->User['Id'] == $Row['User'])
          {
            $_POST['content'] = str_replace("\n", '<br />', $_POST['content']);
            $this->Database->update('News', 'Id='.$_POST['id'], array('Title' => $_POST['title'], 'Content' => $_POST['content']));
            $Output .= 'Aktualita uložena!<br />';
      $Output .= '<a href="index.php?category='.$Category.'">Zpět na seznam aktualit</a>';
          } else $Output .= 'Nelze měnit cizí aktualitu!<br />';
        } else $Output .= 'ID nenalezeno!';
        break;
      case 'del':
        $DbResult = $this->Database->query('SELECT * FROM News WHERE Id='.$_GET['id']);
        $Row = $DbResult->fetch_array();
        if($this->System->Modules['User']->User['Id'] == $Row['User'])
        {
          if($Row['Enclosure'] != '')
          { 
            $Output .= '<br />Přílohy: ';
            $Enclosures = explode(';', $Row['Enclosure']);
            foreach($Enclosures as $Enclosure)
            {
              if(file_exists($this->UploadedFilesFolder.$Enclosure)) unlink($this->UploadedFilesFolder.$Enclosure);
            }
          }
          $this->Database->query('DELETE FROM News WHERE Id='.$_GET['id']);
          $Output .= 'Aktualita smazána!<br /><a href="index.php?category='.$Category.'">Zpět na seznam aktualit</a>';
        } else $Output .= 'Nemáte oprávnění.';
        break;
      default:
        if($this->System->Modules['User']->CheckPermission('News', 'Display', 'Group', $Category))
        {
          $News = new News($this->Database);
          $PerPage = 20;
          $DbResult = $this->Database->select('News', 'COUNT(*)', ' Category='.$Category);
          $RowTotal = $DbResult->fetch_array();
          $PageMax = $RowTotal[0];
          if(array_key_exists('page', $_GET)) $Page = $_GET['page']; 
            else $Page = 0; //round($PageMax/$PerPage);
          $Output .= '<strong>Seznam aktualit kategorie '.$CategoryName.':</strong><div style="font-size: small;">';
          $Output .= PagesList('?category='.$Category.'&amp;page=', $Page, $PageMax, $PerPage);

          //echo(GetRemoteAddress().','.$_SERVER['HTTP_X_FORWARDED_FOR'].'<br />');
          $DbResult = $this->Database->query('SELECT `News`.*, `User`.`Name` FROM `News` LEFT JOIN `User` ON `User`.`Id`=`News`.`User` WHERE `Category`='.$Category.' ORDER BY `News`.`Id` DESC LIMIT '.($Page * $PerPage).','.$PerPage);
          while($Row = $DbResult->fetch_array())
          {
            if($Row['Name'] == '') $Author = $Row['Author'];
              else $Author = $Row['Name'];
            $Output .= '<div class="Panel"><div class="Title"><a href="?action=view&amp;id='.$Row['Id'].'">'.$Row['Title'].'</a> ('.HumanDate($Row['Date']).', '.$Author.')';
            if($this->System->Modules['User']->User['Id'] == $Row['User'])
            {
              $Output .= '<div class="Action">';
              $Output .= '&nbsp;<a href="index.php?action=del&amp;category='.$Category.'&amp;id='.$Row['Id'].'">Smazat</a>';
              $Output .= '&nbsp;<a href="index.php?action=edit&amp;category='.$Category.'&amp;id='.$Row['Id'].'">Editovat</a>';
              $Output .= '</div>';
            }
            $Output .= '</div><div class="Content">'.$News->ModifyContent($Row['Content']).'<br />';
            if($Row['Link'] != '') $Output .= '<br/><a href="'.$Row['Link'].'">Odkaz</a>';
            if($Row['Enclosure'] != '')
            {
              $Output .= '<br />Přílohy: ';
              $Enclosures = explode(';', $Row['Enclosure']);
              foreach($Enclosures as $Enclosure)
              {
                if(file_exists($this->UploadedFilesFolder.$Enclosure)) $Output .= ' <a href="'.$this->UploadedFilesFolder.$Enclosure.'">'.$Enclosure.'</a>';
              }
            }
            $Output .= '</div></div>';
          }
          $Output .= PagesList('?category='.$Category.'&amp;page=', $Page, $PageMax, $PerPage);
          $Output .= '</div>';
        } else $Output .= 'Nemáte oprávnění.';
    }
    return($Output);
  }
}

$System->AddModule(new NewsPage());
$System->Modules['NewsPage']->GetOutput();

?>
