<?php

define('IN_METAL', 1);
$root_path = "./../";
include($root_path . 'common.php');
$banner_page = BANNER_PAGE_NEWS; // Идентификация страницы для баннерокрутилки
$userdata = session_pagestart($user_ip, PAGE_NEWS);

$main_title = "Справочник по металлу и металлопродукции";
$page_title = '<a href="/inform" style="text-decoration:none;">Справочник по металлу и металлопродукции</a>';
$templates_dir = $root_path . $templates_dir;

$template->set_filenames(array('body' => $templates_dir . "inform.tpl"));



/****************/
function showForm($fio, $city, $phone, $email, $site, $maintext, $err) {
		echo('
			<br /><br />

		<table border=1 width=80% align="center" style="border-collapse: collapse" bordercolor="#111111" bordercolorlight="#C0C0C0" bordercolordark="#FFFFFF"><tr><td align="center">			
			<font size=2><b><u>Добавить свой ответ:</u></b></font><br />
			<font size=1>(предложение, вопрос, отзыв...)</font>
			<br /><br />
		');


		if (!empty($err) && ($err != "")) {
			echo("<br /><font color='#CC0207'><b>".$err."</b></font><br />");
		}


		if (!strpos($site, "http://")) {
			$site = "http://";
		}

		echo('
		
		<table class=price width="100%" cellspacing="5" cellpadding="2">
			<form action="" method=post>
				<input type="hidden" name="action" value="action" />
				<tr>
					<td align=left valign=middle width=40%><b>Автор (компания, имя) *</b></td>
					<td align=left valign=middle width=60%><input type=text name="fio" maxlength=100 size=25 value="'.$fio.'"></td>
				</tr>

				<tr>
					<td align=left valign=middle width=40%><b>Город</b></td>
					<td align=left valign=middle width=60%><input type=text name="city" maxlength=100 size=25 value="'.$city.'"></td>
				</tr>

				<tr>
					<td align=left valign=middle width=40%><b>Телефон</b></td>
					<td align=left valign=middle width=60%><input type=text name="phone" maxlength=100 size=25 value="'.$phone.'"></td>
				</tr>

				<tr>
					<td align=left valign=middle width=40%><b>E-mail</b></td>
					<td align=left valign=middle width=60%><input type=text name="email" maxlength=100 size=25 value="'.$email.'"></td>
				</tr>

				<tr>
					<td align=left valign=middle width=40%><b>Сайт</b></td>
					<td align=left valign=middle width=60%><input type=text name="site" maxlength=100 size=25 value="'.$site.'"></td>
				</tr>

				<tr>
					<td align=left valign=middle width=40%><b>Текст *</b></td>
					<td align=left valign=middle width=60%><textarea name="maintext" cols=35 rows=10" onKeyUp="doCnt1()">'.$maintext.'</textarea></td>
				</tr>
				<tr>
					<td align=center valign=middle colspan=2><input type=submit value="Отправить"></td>
				</tr>
			</form>
			</table>
		</td></tr></table><br /><br /><br />');
		return 0;
}
/***************/




include("../my/functions.php");
$id = str_antihack_number($_GET["id"]);
$catid = $id;

if (empty($id))	{

	include($root_path . 'includes/page_header.php');
	$template->pparse('body');
	
	$query = "SELECT * FROM metalboard_inform_cat";
	$result = mysql_query($query);
	echo("<table width='100%' border=1 cellpadding=5 cellspacing=2 align='center' bordercolorlight='#C0C0C0' bordercolordark='#FFFFFF'>");
	echo("<tr>");
		echo("<td align='center'><b>Название подрубрики</b></td>");
		echo("<td align='center'><b>Описание</b></th>");
		echo("<td align='center'><b>Количество просмотров/предложений</b></td>");
	echo("</tr>");
	while ($row = mysql_fetch_array($result)) {
		echo("<tr>");
			echo('<td><a href="inform'.$row["id"].'">'.$row["name"].'</a></td>');
			echo("<td>".$row["keywords"]."</td>");
			$catid = $row["id"];
			$query2 = "SELECT COUNT(*) FROM metalboard_inform_comments WHERE catid={$catid}";
			$result2 = mysql_query($query2);
			$row2 = mysql_fetch_row($result2);
			if ($row2["0"] == 0) {
				echo("<td align='center'>".$row["showcount"]."/".$row2["0"]."</td>");
			} else {
				$query3 = "SELECT cdate FROM metalboard_inform_comments WHERE catid={$catid} ORDER BY cdate DESC";
				$result3 = mysql_query($query3);
				$row3 = mysql_fetch_row($result3);
				$cdate = $row3["0"];
				$cdate = substr($cdate, 0, strpos($cdate, " "));
				echo("<td align='center'>".$row["showcount"]."/".$row2["0"]."<br /><font color='#6B6B6B'>Последний ответ: ".$cdate."</font></td>");
			}
		echo("</tr>");
	}
	echo("</table>");


} else {


	$query = "SELECT showcount FROM metalboard_inform_cat WHERE id={$id}";
	$result = mysql_query($query);
	$row = mysql_fetch_row($result);
	$sc = $row[0];
	$query = "UPDATE metalboard_inform_cat SET showcount=({$sc}+1) WHERE id={$id}";
	$result = mysql_query($query);



/* Описание темы */
	$query = "SELECT * FROM metalboard_inform_cat WHERE id={$id}";
	$result = mysql_query($query);
	$row = mysql_fetch_array($result);
	$keywords = $row["keywords"];
	$name = $row["name"];
	$maintext = $row["maintext"];
	
	$main_title = "Справочный каталог - ".$keywords;


	include($root_path . 'includes/page_header.php');
	$template->pparse('body');
	
	$cat_data = "
	<table width='100%'>
	<tr><td>
		<h3>".$name."</h3><hr />
	</td></tr><tr><td>
		<br />".$maintext."<br />
	</td></tr>
	</table>";
/* Конец Описание темы */


	if (!empty($_POST["action"])) {

		$fio = str_antihack_simple($_POST["fio"]);
		$city = str_antihack_simple($_POST["city"]);
		$phone = str_antihack_simple($_POST["phone"]);
		$email = str_antihack_email($_POST["email"]);
		$site = str_antihack_simple($_POST["site"]);
		$maintext = str_antihack_simple($_POST["maintext"]);
		$maintext = str_replace("\r\n", "<br />", $maintext);

//		echo "<h1>!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!</h1>";

		$err = 0;
		if (strlen($maintext) > 2000) {
			$fio = str_antihack_out($fio);
			$city = str_antihack_out($city);
			$phone = str_antihack_out($phone);
			$email = str_antihack_out($email);
			$site = str_antihack_out($site);
			$maintext = str_antihack_out($maintext);

			$err = 1;
			echo($cat_data);
			showForm($fio, $city, $phone, $email, $site, $maintext, "Текст слишком большой");
		} else {

			if (($err = 1) && (empty($fio) || empty($maintext))) {
				$fio = str_antihack_out($fio);
				$city = str_antihack_out($city);
				$phone = str_antihack_out($phone);
				$email = str_antihack_out($email);
				$site = str_antihack_out($site);
				$maintext = str_antihack_out($maintext);

				echo($cat_data);
				showForm($fio, $city, $phone, $email, $site, $maintext, "Вы должны заполнить обязательные поля");
			} else {
				$query = "INSERT INTO metalboard_inform_comments VALUES(
					null,
					{$catid},
					'{$fio}',
					'{$city}',
					'{$phone}',
					'{$email}',
					'{$site}',
					'{$maintext}',
					1,
					NOW()
				)";
				$result = mysql_query($query);
				if ($result) {
					echo("<center><h3>Спасибо. Ваше сообщение отправлено</h3><br /><a href='/inform/inform".$id."'>Перейти на страницу \"".$keywords."\"</a></center>");
				} else {
					echo("<center><h3>Ошибка добавления, пожалуйста, обратитесь к администратору</h3></center>".mysql_error());
				}
			}

		}


	} else {


		echo($cat_data);

		$showCount = 15;

		$page = str_antihack_number($_GET["page"]);
		if (empty($page)) {
			$page = 0;
		}

		$query = "
			SELECT * FROM metalboard_inform_comments
			WHERE access=1 AND catid={$catid}
			ORDER BY cdate DESC
			LIMIT {$page},{$showCount}
		";
	    $result = mysql_query($query);

		echo("<hr /><br /><center><b><u>Предложения по теме</u></b></center><br /><br />");

		echo("<table width=\"88%\" cellpadding=0 cellspacing=0 align='center'>");
		while ($row = mysql_fetch_array($result)) {
		  echo("<tr height='25'>");
			echo("<td bgcolor='#EAEAEA'>");
			$fio = str_antihack_out($row["fio"]);
			$maintext = str_antihack_out($row["maintext"]);
			$city = str_antihack_out($row["city"]);
			$phone = str_antihack_out($row["phone"]);
			$site = str_antihack_out($row["site"]);
			$email = str_antihack_out($row["email"]);
			$cdate = $row["cdate"];
			$cdate = substr($cdate, 0, strpos($cdate, " "));
			echo("<b>Сообщение от: </b>".$fio);
			if (!empty($city) && ($city != "")) {
				echo(" (".$city.") ");
			}
			if (!empty($phone) && ($phone != "")) {
				echo(" | тел.".$phone." ");
			}
			if (!empty($site) && ($site != "") && ($site != "http://")) {
				strpos($site, "http://")>-1 ? $site = $site : $site = "http://".$site;
				echo(" | <a href='../my/redirect.php?url=".$site."'>".$site."</a> ");
			}
			if (!empty($email) && ($email != "")) {
				echo(" | <a href='mailto:".$email."'>".$email."</a> ");
			}
			echo("<font color='949494'> [".$cdate."]</font><br />");
			echo("</td></tr>");
			echo("<tr><td bgcolor='#F9F9FF'>");
			echo("<p>".$maintext."</p><hr />");
			echo("</td>");
		  echo("</tr>");
		  echo("<tr>");
			echo("<td>");
			echo("</td>");
		  echo("</tr>");
		}

		  echo("<tr>");
			echo("<td>");
				$query = "SELECT * FROM metalboard_inform_comments WHERE access=1 AND catid={$catid}";
				$result = mysql_query($query);
				$count = mysql_num_rows($result);

				$count = (int) ceil($count / $showCount);

				$page = 0;
//				echo("<br /><b>Страницы:</b>&nbsp;&nbsp;");
				for ($i=1; $i<=$count; $i++) {
				  echo("<a href=\"http://www.meta-portal.ru/inform/inform".$id."/".$page."\">".$i."</a>&nbsp;&nbsp;");
				  $page = $i * $showCount;
				}
			echo("<br /></td>");
		  echo("</tr>");


		  echo("<tr>");
			echo("<td>");
				showForm('', '', '', '', '', '', '');
			echo("</td>");
		  echo("</tr>");


		echo("</table>");


	}


}





include($root_path . 'includes/page_footer.php');

?>
