<?
include ("constants.php");
class MySQLDB
{
var $connection; //The MySQL database connection
var $num_active_users; //Number of active users viewing site
var $num_active_guests; //Number of active guests viewing site
var $num_members; //Number of signed-up users
/* Note: call getNumMembers() to access $num_members! */
/* Class constructor */
function MySQLDB()
{
/* Make connection to database */
$this->connection = mysql_connect(DB_SERVER, DB_USER, DB_PASS) or die(mysql_error());
mysql_select_db(DB_NAME, $this->connection) or die(mysql_error());
/**
* Only query database to find out number of members
* when getNumMembers() is called for the first time,
* until then, default value set.
*/
$this->num_members = -1;
if (TRACK_VISITORS)
{
/* Calculate number of users at site */
$this->calcNumActiveUsers();
/* Calculate number of guests at site */
$this->calcNumActiveGuests();
}
}
/**
* confirmUserPass - Checks whether or not the given
* username is in the database, if so it checks if the
* given password is the same password in the database
* for that user. If the user doesn't exist or if the
* passwords don't match up, it returns an error code
* (1 or 2). On success it returns 0.
*/
function confirmUserPass($username, $password)
{
/* Add slashes if necessary (for query) */
if (!get_magic_quotes_gpc())
{
$username = addslashes($username);
}
/* Verify that user is in database */
$q = "SELECT password FROM " . TBL_USERS . " WHERE username = '$username'";
$result = mysql_query($q, $this->connection);
if (!$result || (mysql_numrows($result) < 1))
{
return 1; //Indicates username failure
}
/* Retrieve password from result, strip slashes */
$dbarray = mysql_fetch_array($result);
$dbarray['password'] = stripslashes($dbarray['password']);
$password = stripslashes($password);
/* Validate that password is correct */
if ($password == $dbarray['password'])
{
return 0; //Success! Username and password confirmed
}
else
{
return 2; //Indicates password failure
}
}
/**
* confirmUserID - Checks whether or not the given
* username is in the database, if so it checks if the
* given userid is the same userid in the database
* for that user. If the user doesn't exist or if the
* userids don't match up, it returns an error code
* (1 or 2). On success it returns 0.
*/
function confirmUserID($username, $userid)
{
/* Add slashes if necessary (for query) */
if (!get_magic_quotes_gpc())
{
$username = addslashes($username);
}
/* Verify that user is in database */
$q = "SELECT userid FROM " . TBL_USERS . " WHERE username = '$username'";
$result = mysql_query($q, $this->connection);
if (!$result || (mysql_numrows($result) < 1))
{
return 1; //Indicates username failure
}
/* Retrieve userid from result, strip slashes */
$dbarray = mysql_fetch_array($result);
$dbarray['userid'] = stripslashes($dbarray['userid']);
$userid = stripslashes($userid);
/* Validate that userid is correct */
if ($userid == $dbarray['userid'])
{
return 0; //Success! Username and userid confirmed
}
else
{
return 2; //Indicates userid invalid
}
}
/**
* usernameTaken - Returns true if the username has
* been taken by another user, false otherwise.
*/
function usernameTaken($username)
{
if (!get_magic_quotes_gpc())
{
$username = addslashes($username);
}
$q = "SELECT username FROM " . TBL_USERS . " WHERE username = '$username'";
$result = mysql_query($q, $this->connection);
return (mysql_numrows($result) > 0);
}
/**
* usernameBanned - Returns true if the username has
* been banned by the administrator.
*/
function usernameBanned($username)
{
if (!get_magic_quotes_gpc())
{
$username = addslashes($username);
}
$q = "SELECT username FROM " . TBL_BANNED_USERS . " WHERE username = '$username'";
$result = mysql_query($q, $this->connection);
return (mysql_numrows($result) > 0);
}
/**
* addNewUser - Inserts the given (username, password, email)
* info into the database. Appropriate user level is set.
* Returns true on success, false otherwise.
*/
function addNewUser($username, $password, $email)
{
$time = time();
/* If admin sign up, give admin user level */
if (strcasecmp($username, ADMIN_NAME) == 0)
{
$ulevel = ADMIN_LEVEL;
}
else
{
$ulevel = USER_LEVEL;
}
$q = "INSERT INTO " . TBL_USERS . " VALUES ('$username', '$password', '0', $ulevel, '$email', $time)";
return mysql_query($q, $this->connection);
}
/**
* updateUserField - Updates a field, specified by the field
* parameter, in the user's row of the database.
*/
function updateUserField($username, $field, $value)
{
$q = "UPDATE " . TBL_USERS . " SET " . $field . " = '$value' WHERE username = '$username'";
return mysql_query($q, $this->connection);
}
/**
* getUserInfo - Returns the result array from a mysql
* query asking for all information stored regarding
* the given username. If query fails, NULL is returned.
*/
function getUserInfo($username)
{
$q = "SELECT * FROM " . TBL_USERS . " WHERE username = '$username'";
$result = mysql_query($q, $this->connection);
/* Error occurred, return given name by default */
if (!$result || (mysql_numrows($result) < 1))
{
return null;
}
/* Return result array */
$dbarray = mysql_fetch_array($result);
return $dbarray;
}
/**
* getNumMembers - Returns the number of signed-up users
* of the website, banned members not included. The first
* time the function is called on page load, the database
* is queried, on subsequent calls, the stored result
* is returned. This is to improve efficiency, effectively
* not querying the database when no call is made.
*/
function getNumMembers()
{
if ($this->num_members < 0)
{
$q = "SELECT * FROM " . TBL_USERS;
$result = mysql_query($q, $this->connection);
$this->num_members = mysql_numrows($result);
}
return $this->num_members;
}
/**
* calcNumActiveUsers - Finds out how many active users
* are viewing site and sets class variable accordingly.
*/
function calcNumActiveUsers()
{
/* Calculate number of users at site */
$q = "SELECT * FROM " . TBL_ACTIVE_USERS;
$result = mysql_query($q, $this->connection);
$this->num_active_users = mysql_numrows($result);
}
/**
* calcNumActiveGuests - Finds out how many active guests
* are viewing site and sets class variable accordingly.
*/
function calcNumActiveGuests()
{
/* Calculate number of guests at site */
$q = "SELECT * FROM " . TBL_ACTIVE_GUESTS;
$result = mysql_query($q, $this->connection);
$this->num_active_guests = mysql_numrows($result);
}
/**
* addActiveUser - Updates username's last active timestamp
* in the database, and also adds him to the table of
* active users, or updates timestamp if already there.
*/
function addActiveUser($username, $time)
{
$q = "UPDATE " . TBL_USERS . " SET timestamp = '$time' WHERE username = '$username'";
mysql_query($q, $this->connection);
if (!TRACK_VISITORS) return;
$q = "REPLACE INTO " . TBL_ACTIVE_USERS . " VALUES ('$username', '$time')";
mysql_query($q, $this->connection);
$this->calcNumActiveUsers();
}
/* addActiveGuest - Adds guest to active guests table */
function addActiveGuest($ip, $time)
{
if (!TRACK_VISITORS) return;
$q = "REPLACE INTO " . TBL_ACTIVE_GUESTS . " VALUES ('$ip', '$time')";
mysql_query($q, $this->connection);
$this->calcNumActiveGuests();
}
/* These functions are self explanatory, no need for comments */
/* removeActiveUser */
function removeActiveUser($username)
{
if (!TRACK_VISITORS) return;
$q = "DELETE FROM " . TBL_ACTIVE_USERS . " WHERE username = '$username'";
mysql_query($q, $this->connection);
$this->calcNumActiveUsers();
}
/* removeActiveGuest */
function removeActiveGuest($ip)
{
if (!TRACK_VISITORS) return;
$q = "DELETE FROM " . TBL_ACTIVE_GUESTS . " WHERE ip = '$ip'";
mysql_query($q, $this->connection);
$this->calcNumActiveGuests();
}
/* removeInactiveUsers */
function removeInactiveUsers()
{
if (!TRACK_VISITORS) return;
$timeout = time() - USER_TIMEOUT * 60;
$q = "DELETE FROM " . TBL_ACTIVE_USERS . " WHERE timestamp < $timeout";
mysql_query($q, $this->connection);
$this->calcNumActiveUsers();
}
/* removeInactiveGuests */
function removeInactiveGuests()
{
if (!TRACK_VISITORS) return;
$timeout = time() - GUEST_TIMEOUT * 60;
$q = "DELETE FROM " . TBL_ACTIVE_GUESTS . " WHERE timestamp < $timeout";
mysql_query($q, $this->connection);
$this->calcNumActiveGuests();
}
/**
* query - Performs the given query on the database and
* returns the result, which may be false, true or a
* resource identifier.
*/
function query($query)
{
return mysql_query($query, $this->connection);
}
}
;
/* Create database connection */
$database = new MySQLDB;
/* get the downloads, make them pretty, count them, and assign them */
$qsum = "SELECT SUM(downloads) FROM downloads";
$total_d = mysql_query($qsum);
$total_downloads = mysql_result($total_d, 0);
if ($total_downloads == "0")
{
$total_count = 0;
}
else
{
$total_count = number_format($total_downloads);
}
/* get the settings */
$settings = mysql_fetch_array(mysql_query("SELECT * FROM `settings` "));
/* get the ads */
$ads = mysql_fetch_array(mysql_query("SELECT * FROM `ads` "));
/* clean the search */
$search = $_GET[search];
$search = stripslashes($search);
$search = str_replace("'", "", $search);
$search = str_replace("/", "", $search);
$search = str_replace("-", " ", $search);
$srch = preg_replace('/ /', '+', $search);
/* ajax suggest db connect */
function db_connect($server = DB_SERVER, $username = DB_USER, $password = DB_PASS, $database = DB_NAME, $link = 'db_link')
{
global $$link;
$$link = mysql_connect($server, $username, $password);
if ($$link) mysql_select_db($database);
return $$link;
}
//Function to handle database errors.
function db_error($query, $errno, $error)
{
die('<font color="#000000"><b>' . $errno . ' - ' . $error . '<br><br>' . $query . '<br><br><small><font color="#ff0000">[STOP]</font></small><br><br></b></font>');
}
//Function to query the database.
function db_query($query, $link = 'db_link')
{
global $$link;
$result = mysql_query($query, $$link) or db_error($query, mysql_errno(), mysql_error());
return $result;
}
//Get a row from the database query
function db_fetch_array($db_query)
{
return mysql_fetch_array($db_query, MYSQL_ASSOC);
}
//The the number of rows returned from the query.
function db_num_rows($db_query)
{
return mysql_num_rows($db_query);
}
//Get the last auto_increment ID.
function db_insert_id()
{
return mysql_insert_id();
}
//Add HTML character incoding to strings
function db_output($string)
{
return htmlspecialchars($string);
}
//Add slashes to incoming data
function db_input($string, $link = 'db_link')
{
global $$link;
if (function_exists('mysql_real_escape_string'))
{
return mysql_real_escape_string($string, $$link);
} elseif (function_exists('mysql_escape_string'))
{
return mysql_escape_string($string);
}
return addslashes($string);
}
//Date
$date = date("m-d-Y");
$yesterday = date("m-d-Y", time() - 86400);
//Search Stats
if ($date == $date)
{
$quer = mysql_query("SELECT `id` FROM `tags` WHERE date='$yesterday'");
$tag_count = mysql_num_rows($quer);
$stat_count = mysql_num_rows(mysql_query("SELECT `id` from `search_stats` WHERE date='$yesterday'"));
if ($stat_count == "0")
{
mysql_query("INSERT INTO `search_stats` VALUES ('','$tag_count','$yesterday')");
}
}
//Encoding URLs
function enc($string)
{
$hex = '';
for ($i = 0; $i < strlen($string); $i++)
{
$hex .= dechex(ord($string[$i]));
}
return $hex;
}
function dec($hex)
{
$string = '';
for ($i = 0; $i < strlen($hex) - 1; $i += 2)
{
$string .= chr(hexdec($hex[$i] . $hex[$i + 1]));
}
return $string;
}
$path = $web_path . "get.php?id=";
$type = $_GET['type'];
if ($type == "lyrics")
{
$search_box_text = "Search Lyrics...";
}
else
{
$search_box_text = "Search Mp3s...";
}
$working = 0;
?>