flag404 = true; } function engine() { $this->__construct(); } function __construct() { // Заглушка $this->engine = &$this; $starttime = explode(' ', microtime()); $this->starttime = $starttime[1] + $starttime[0]; // Если включен magic_quotes_gpc, сносим лишние слэши if (get_magic_quotes_gpc()) { $this->r_stripslashes($_GET); $this->r_stripslashes($_POST); $this->r_stripslashes($_COOKIE); $this->r_stripslashes($_REQUEST); } @session_start(); $this->docroot = rtrim($_SERVER["DOCUMENT_ROOT"],'/'); $this->sysroot = $this->docroot."/nmcms"; $this->serverroot = "http://".$_SERVER["HTTP_HOST"]; $this->initDB(); $this->readEngineConfig(); $this->cachedir = $this->docroot.'/'.$this->config['Main']['cache_dir']; $this->imgcachedir = $this->docroot.'/'.$this->config['Main']['cache_img_dir']; $this->smartydir = $this->docroot.'/'.$this->config['Smarty']['compile_dir']; // Проверяем существование и доступность папок кэша $this->createFolderIfNotExists($this->cachedir); $this->createFolderIfNotExists($this->imgcachedir); $this->createFolderIfNotExists($this->smartydir); // Читаем пользователя $this->initUser(); // Разбираем $_SERVER["REQUEST_URI"] $this->parseRequest($_SERVER["REQUEST_URI"]); return true; } function getIdByAlias($alias) { $this->SQL->execSQL('SELECT id FROM articles WHERE alias="'.$alias.'"'); return $this->SQL->numRows ? $this->SQL->recordset[0]['id'] : false; } function login() { @$login = trim(mysql_escape_string($_POST["login"])); @$password = $_POST["pwd"]; if (!isset($login) || !isset($password)) return false; $pwdh = md5($this->config['Main']['md5_prefix'].$password); $this->SQL->execSQL("SELECT * FROM users WHERE enabled AND login='$login' AND pwdmd5='$pwdh'"); if (!$this->SQL->numRows) { $this->userError = 'Пользователь с таким логином и паролем не найден'; return false; } $userdata = $this->SQL->recordset[0]; $userkey = $this->makerand(32); $this->SQL->execSQL('UPDATE users SET userkey="'.$userkey.'" WHERE userid="'.$this->SQL->recordset[0]["userid"].'"'); setcookie('userkey',$userkey,time()+60*60*24*30,'/'); $_COOKIE['userkey'] = $userkey; $this->initUser(); } function logout() { setcookie('userkey','',time()-1,'/'); unset($_COOKIE['userkey']); $this->currentUser = null; $this->authorized = false; } function readEngineConfig() { $this->config = array(); $this->SQL->execSQL("SELECT * FROM config"); foreach ($this->SQL->recordset as $line) { if (!isset($this->config[$line['module_name']])) $this->config[$line['module_name']] = array(); $this->config[$line['module_name']][$line["entry"]] = $line['cur_value']; } } function initDB() { $dbconfig_paths = array( $this->docroot.'/dbconfig.inc.php', $this->docroot.'/dbconfig.inc', $this->docroot.'/../nmcms_files/dbconfig.inc.php', $this->docroot.'/../nmcms_files/dbconfig.inc', $this->docroot.'/nmcms_files/dbconfig.inc.php', $this->docroot.'/nmcms_files/dbconfig.inc', $this->docroot.'/nmcms/dbconfig.inc.php', $this->docroot.'/nmcms/dbconfig.inc' ); $dbconfig_found = false; foreach ($dbconfig_paths as $config_path) if (is_readable($config_path)) { include_once($config_path); $dbconfig_found = true; break; } if (!$dbconfig_found) $this->fatalError('Database config not found'); if (!isset($mysql)) $this->fatalError('Invalid format of database config file'); include_once($this->sysroot.'/classes/db.class.php'); $this->SQL = new DB($mysql); } function parseRequest($URI) { $request = preg_match('/^(.*)\?/U',$URI,$m); if ($m) $URI = $m[1]; $URI = explode('/',$URI); $this->request = array(); foreach ($URI as $index=>$value) { if ($index == 0 && $value == "") continue; if ($index == count($URI)-1 && $value == "") continue; if ($index == count($URI)-1 && strpos($value,"index.php") === 0) continue; if ($index == count($URI)-1 && strpos($value,"?") === 0) continue; $this->request[] = $value; } return true; } function initUser() { if (isset($_COOKIE['userkey'])) { $userkey = mysql_escape_string($_COOKIE['userkey']); $this->SQL->execSQL('SELECT * FROM users WHERE enabled AND userkey="'.$userkey.'"'); if ($this->SQL->numRows) { $this->currentUser = $this->SQL->recordset[0]; $this->currentUser['userdata'] = unserialize($this->currentUser['userdata']); // Принадлежность к группам $this->SQL->execSQL('SELECT user_groups.gid group_id, user_groups.group_name FROM users_to_groups_rel LEFT JOIN user_groups ON users_to_groups_rel.group_id=user_groups.gid WHERE users_to_groups_rel.user_id="'.$this->currentUser['userid'].'"'); $this->currentUser['groups'] = $this->SQL->recordset; } } } function runComp($compName) { $this->SQL->execSQL('SELECT * FROM comp_keys WHERE replace_key="'.$compName.'"'); if (!$this->SQL->numRows) return 'COMPONENT "'.$compName.'" NOT FOUND'; $class = $this->SQL->recordset[0]['comp_name']; $this->SQL->execSQL('SELECT param_name, param_value FROM comp_settings WHERE comp_key="'.$compName.'"'); $params = $this->SQL->recordset; include_once($this->sysroot.'/components/'.$class.'.php'); $component = new $class($this,$compName); if ($params) foreach ($params as $param) $component->setParam($param['param_name'],$param['param_value']); $component->run(); $res = $component->HTML; if ($component->WINDOW_TITLE) $this->meta['window_title'] = $component->WINDOW_TITLE; if ($component->KEYWORDS) $this->meta['meta_keywords'] = $component->KEYWORDS; if ($component->DESCRIPTION) $this->meta['meta_description'] = $component->DESCRIPTION; if ($component->PAGE_HEADER) $this->meta['title'] = $component->PAGE_HEADER; if ($component->userError) $this->meta['userError'] = $component->userError; if ($component->userMessage) $this->meta['userMessage'] = $component->userMessage; unset($component); return $res; } function autoDump() { if ($this->config["Dumps"]["frequency"] && (time()-$this->config[""]["db_last_backup"] > $this->config["Dumps"]["frequency"])) { $this->createDump(); $this->SQL->execSQL("UPDATE config SET cur_value=".time()." WHERE entry='db_last_backup'"); } } function run() { @setlocale(LC_ALL, 'ru_RU.CP1251'); header("Content-type: text/html; charset=windows-1251"); ob_start('ob_gzhandler'); $this->autoDump(); @$action = $_REQUEST["action"]; if (!isset($action)) $action = ""; switch ($action) { case "login": $this->login(); break; case "logout": $this->logout(); break; case "forget_password": $this->forgetPassword(); break; } $res = $this->runComp('content'); if ($this->flag404) { $this->request = array('404'); $res = $this->runComp('content'); } echo $res; ob_end_flush(); // Автодамп $finishtime = explode(' ', microtime()); $finishtime = $finishtime[1] + $finishtime[0]; $scripttime = $finishtime-$this->starttime; } } ?>