<?php
require_once "../../maincore.php";
require_once THEMES."templates/admin_header.php";

if (file_exists(INFUSIONS."komanda/locale/".$settings['locale'].".php"))
   {
   include INFUSIONS."komanda/locale/".$settings['locale'].".php";
   }
   else
   {
   include INFUSIONS."komanda/locale/Lithuanian.php";
   }


function showmessage($message){
opentable("Informacija");
echo "<center><b>".$message."</b></center>";
closetable();
}

$error = "";

if (!checkrights("KOM") || !defined("iAUTH") || !isset($_GET['aid']) || $_GET['aid'] != iAUTH) { redirect("../index.php"); }
   
   $editlist = ""; $sel = "";
   $result2 = dbquery("SELECT * FROM ".$db_prefix."komanda_cats ORDER BY cat_name");
   if (dbrows($result2) != 0) {
      while ($data2 = dbarray($result2)) {
         $editlist .= "<option value='".$data2['cat_id']."'$sel>".$data2['cat_name']."</option>\n";
      }
   }
   $userlist = ""; $useriai = "";
   $result3 = dbquery("SELECT * FROM ".$db_prefix."users ORDER BY user_name");
   if (dbrows($result3) != 0) {
      while ($data3 = dbarray($result3)) {
         $userlist .= "<option value='".$data3['user_id']."'$useriai>".$data3['user_name']."</option>\n";
      }
   }

if(isset($_POST['do']) && $_POST['do'] == "doadd"){

if(!$_POST['slapyvardis']){
showmessage($locale['a21']);
$error = 1;
}else if(!$_POST['amzius']){
showmessage($locale['a22']);   
$error = 1;
}else if(!$_POST['miestas']){
showmessage($locale['a23']);   
$error = 1;
} else if(!$_POST['pareigos']){
showmessage($locale['a24']);   
$error = 1;
}

if ($error == "") {
   $sndyra = mktime(date("H"),date("i"),date("s"),date("m"),date("d"),date("Y"));
   $newavatar = $_FILES['nuotrauka'];
   if (!empty($newavatar['name']) && is_uploaded_file($newavatar['tmp_name'])) {
      $avatarext = strrchr($newavatar['name'],".");
      $avatarname = substr($newavatar['name'], 0, strrpos($newavatar['name'], "."));
      if (preg_match("/^[-0-9A-Z_\[\]]+$/i", $avatarname) && preg_match("/(\.gif|\.GIF|\.jpg|\.JPG|\.png|\.PNG)$/", $avatarext) && $newavatar['size'] <= 1024*10000) {
         $avatarname = $avatarname."[".$userdata['user_id'].$sndyra."]".$avatarext;
         $set_avatar = $avatarname;
         move_uploaded_file($newavatar['tmp_name'], IMAGES."komanda/".$avatarname);
         chmod(IMAGES."komanda/".$avatarname,0644);
         if ($size = @getimagesize(IMAGES."komanda/".$avatarname)) {
            if ($size['0'] > 120 || $size['1'] > 120) {
               unlink(IMAGES."komanda/".$avatarname);
               $set_avatar = "";
            }
         } else {
            unlink(IMAGES."komanda/".$avatarname);
            $set_avatar = "";
         }
      }
   }

if($set_avatar == ""){
showmessage($locale['a25']);
}else{
$slapyvardis = $_POST['slapyvardis'];
$amzius = $_POST['amzius'];
$miestas = $_POST['miestas'];
$pareigos = $_POST['pareigos'];
$kontaktai = $_POST['kontaktai'];
$laida = $_POST['laida'];
$cat_id = $_POST['catid'];
$user_id = $_POST['userid'];
$vedejas = $_POST['vedejas'];
$nuotrauka = $set_avatar;
$result = dbquery("INSERT INTO ".$db_prefix."komanda (slapyvardis, amzius, miestas, pareigos, kontaktai, laida, cat_id, user_id, nuotrauka, vedejas) VALUES ('".$slapyvardis."', '".$amzius."', '".$miestas."', '".$pareigos."', '".$kontaktai."', '".$laida."', '".$cat_id."', '".$user_id."', '".$nuotrauka."', '".$vedejas."')");
showmessage($locale['a31']);
}
}
}

if(isset($_POST['do']) && $_POST['do'] == "del"){
$img = dbarray(dbquery("SELECT * FROM ".$db_prefix."komanda WHERE id = '".$_POST['id']."'"));
$qery = dbquery("DELETE FROM ".$db_prefix."komanda WHERE id = ".$_POST['id']."");
unlink(IMAGES."komanda/".$img['nuotrauka']);
showmessage($locale['a32']);   
}

if(isset($_POST['do']) && $_POST['do'] == "edit"){
$komandosas = dbarray(dbquery("SELECT * FROM ".$db_prefix."komanda WHERE id = '".$_POST['id']."'"));
$sel = ($komandosas['cat_id'] == $data2['cat_id'] ? " selected" : ""); 
$useriai = ($komandosas['user_id'] == $data3['user_id'] ? " selected" : ""); 
if(!$komandosas){
showmessage($locale['a26']);
}else{
opentable($locale['a13']);
echo '
<form method="POST" action="admin.php'.$aidlink.'" enctype="multipart/form-data">
<input type="hidden" name="do" value="doedit">
<input type="hidden" name="id" value="'.$komandosas['id'].'">
<table border="0" cellpadding="1" cellspacing="1" align="center">
  <tr>
    <td>'.$locale['a01'].'</td>
    <td><input type="text" class="textbox" name="slapyvardis" value="'.$komandosas['slapyvardis'].'"></td>
  </tr>
  <tr>
    <td>'.$locale['a02'].'</td>
    <td><input type="text" class="textbox" name="amzius" value="'.$komandosas['amzius'].'"></td>
  </tr>
    <tr>
    <td>'.$locale['a03'].'</td>
    <td><input type="text" class="textbox" name="miestas" value="'.$komandosas['miestas'].'"></td>
  </tr>
    <tr>
    <td>'.$locale['a04'].'</td>
    <td><input type="text" class="textbox" name="pareigos" value="'.$komandosas['pareigos'].'"></td>
  </tr>
    <tr>
    <td>'.$locale['a05'].'</td>
    <td><input type="text" class="textbox" name="kontaktai" value="'.$komandosas['kontaktai'].'"></td>
  </tr>
  <tr>
    <td>'.$locale['a06'].'</td>
    <td><input type="text" class="textbox" name="laida" value="'.$komandosas['laida'].'"></td>
  </tr>
  <tr>
    <td>'.$locale['a17'].'</td>
    <td><input type="text" class="textbox" name="vedejas" value="'.$komandosas['vedejas'].'"></td>
  </tr>
  <tr>
    <td>'.$locale['a11'].'</td>
    <td><select name="userid" class="textbox">'.$userlist.'</select></td>
  </tr>
  <tr>
    <td>'.$locale['a12'].'</td>
    <td><select name="catid" class="textbox">'.$editlist.'</select></td>
  </tr>    
  <tr>
    <td>'.$locale['a11'].'</td>
    <td><input type="file" name="nuotrauka" class="textbox" size="20"></td>
  </tr>
  <tr>
    <td colspan="2" align="center"><input class="button" type="submit" value="'.$locale['a15'].'" name="B1"></td>
  </tr>
</table>
</form>';
closetable();
}
}

if(isset($_POST['do']) && $_POST['do'] == "doedit"){
$komandosas = dbarray(dbquery("SELECT * FROM ".$db_prefix."komanda WHERE id = '".$_POST['id']."'"));

if(!$_POST['id'] or !$_POST['slapyvardis']){
showmessage($locale['a26']);
}else if($_FILES["nuotrauka"]["error"] > 0){
$result = dbquery("UPDATE ".$db_prefix."komanda SET slapyvardis='".$slapyvardis."', amzius='".$amzius."', miestas='".$miestas."', pareigos='".$pareigos."', kontaktai='".$kontaktai."', laida='".$laida."', cat_id='".$cat_id."', user_id='".$user_id."', vedejas='".$vedejas."' WHERE id='".$_POST['id']."'");
showmessage($locale['a33']);   
}else{
if ($error == "") {
   $sndyra = mktime(date("H"),date("i"),date("s"),date("m"),date("d"),date("Y"));
   $newavatar = $_FILES['nuotrauka'];
   if (!empty($newavatar['name']) && is_uploaded_file($newavatar['tmp_name'])) {
      $avatarext = strrchr($newavatar['name'],".");
      $avatarname = substr($newavatar['name'], 0, strrpos($newavatar['name'], "."));
      if (preg_match("/^[-0-9A-Z_\[\]]+$/i", $avatarname) && preg_match("/(\.gif|\.GIF|\.jpg|\.JPG|\.png|\.PNG)$/", $avatarext) && $newavatar['size'] <= 1024*$goldsettings['maxbanner120x120size']) {
         $avatarname = $avatarname."[".$userdata['user_id'].$sndyra."]".$avatarext;
         $set_avatar = $avatarname;
         move_uploaded_file($newavatar['tmp_name'], IMAGES."komanda/".$avatarname);
         chmod(IMAGES."komanda/".$avatarname,0644);
         if ($size = @getimagesize(IMAGES."komanda/".$avatarname)) {
            if ($size['0'] > 120 || $size['1'] > 120) {
               unlink(IMAGES."komanda/".$avatarname);
               $set_avatar = "";
            }
         } else {
            unlink(IMAGES."komanda/".$avatarname);
            $set_avatar = "";
         }
      }
   }

}   


if($set_avatar == ""){
showmessage($locale['a25']);
}else{
   $result = dbquery("UPDATE ".$db_prefix."komanda SET slapyvardis='".$slapyvardis."', amzius='".$amzius."', miestas='".$miestas."', pareigos='".$pareigos."', kontaktai='".$kontaktai."', laida='".$laida."', cat_id='".$cat_id."', user_id='".$user_id."', vedejas='".$vedejas."', nuotrauka='".$set_avatar."' WHERE id='".$_POST['id']."'");
   unlink(IMAGES."komanda/".$komandosas['nuotrauka']);   
showmessage($locale['a31']);
}



}


}

opentable($locale['a14']);
echo '
<form method="POST" action="admin.php'.$aidlink.'" enctype="multipart/form-data">
<input type="hidden" name="do" value="doadd">
<table border="0" cellpadding="1" cellspacing="1" align="center">
  <tr>
    <td>'.$locale['a01'].'</td>
    <td><input type="text" class="textbox" name="slapyvardis"></td>
  </tr>
  <tr>
    <td>'.$locale['a02'].'</td>
    <td><input type="text" class="textbox" name="amzius"></td>
  </tr>
    <tr>
    <td>'.$locale['a03'].'</td>
    <td><input type="text" class="textbox" name="miestas"></td>
  </tr>
    <tr>
    <td>'.$locale['a04'].'</td>
    <td><input type="text" class="textbox" name="pareigos"></td>
  </tr>
    <tr>
    <td>'.$locale['a05'].'</td>
    <td><input type="text" class="textbox" name="kontaktai"></td>
  </tr>
  <tr>
    <td>'.$locale['a06'].'</td>
    <td><input type="text" class="textbox" name"laida"></td>
  </tr>
  <tr>
    <td>'.$locale['a17'].'</td>
    <td><input type="text" class="textbox" name"vedejas"></td>
  </tr>
  <tr>
    <td>'.$locale['a07'].'</td>
    <td><select name="userid" class="textbox">'.$userlist.'</select></td>
  </tr>
  <tr>
    <td>'.$locale['a12'].'</td>
    <td><select name="catid" class="textbox">'.$editlist.'</select></td>
  </tr>    
  <tr>
    <td>'.$locale['a11'].'</td>
    <td><input type="file" name="nuotrauka" class="textbox" size="20"></td>
  </tr>
  <tr>
    <td colspan="2">
    <p align="center">
  <input type="submit" class="button" value="'.$locale['a09'].'"></td>
  </tr>
</table>
</form>
';

closetable();


opentable($locale['k00']);
if(dbcount("(*)", DB_PREFIX."komanda") > 0){
if(dbcount("(*)", DB_PREFIX."komanda", "cat_id=1") > 0) {
$kad = dbquery("SELECT * from ".DB_PREFIX."komanda WHERE cat_id = '1'");

while($kads = dbarray($kad)) {
echo '
<table border="0" cellpadding="1" cellspacing="1" align="center">
  <tr>
    <td class="tbl2" colspan="3" align="center"><h2>Administracija</h2></td>
  </tr>
  <tr>
    <td class="tbl2" colspan="3" align="center"><table border=0>';
         
         echo '<tr>
         <td><img src="'.IMAGES.'komanda/'.$kads['nuotrauka'].'" height="120" align="right"></td>
         <td>';
         
         echo $locale['k01'].' <a href="'.($kads['user_id'] == "" ? "#" : $kads['user_id']).'">'.$kads['slapyvardis'].'</a><br />';
         echo ($kads['amzius'] == "" ? "" : "".$locale['k02']." ".$kads['amzius']."<br />");
         echo ($kads['miestas'] == "" ? "" : "".$locale['k03']." ".$kads['miestas']."<br />");
         echo ($kads['laida'] == "" ? "" : "".$locale['k06']." ".$kads['laida']."<br />");
         echo $locale['k04'].' '.$kads['pareigos'].'<br />';
         echo $locale['k05'].' '.$kads['kontaktai'].'<br />';
         echo '</td>
         </tr>';
         
         echo '</table></td>
  </tr>
  <tr>
    <td class="tbl2" align="center"><form method="POST" action="admin.php'.$aidlink.'"><input type="hidden" name="id" value="'.$kads['id'].'"><input type="hidden" name="do" value="edit"><input type="submit" value="'.$locale['a15'].'" class="button"></form></td>
    <td class="tbl2" align="center"><form method="POST" action="admin.php'.$aidlink.'"><input type="hidden" name="id" value="'.$kads['id'].'"><input type="hidden" name="do" value="del"><input type="submit" value="'.$locale['a16'].'" class="button"></form></td>
  </tr>
 </table>
';
}
} else {
echo "<center>".$locale['a35']."</center>";
}

if(dbcount("(*)", DB_PREFIX."komanda", "cat_id=2") > 0) {
$kdj = dbquery("SELECT * from ".DB_PREFIX."komanda WHERE cat_id = '2'");
while($kdjs = dbarray($kdj)) {
echo '
<table border="0" cellpadding="1" cellspacing="1" align="center">
  <tr>
    <td class="tbl2" colspan="3" align="center"><h2>Administracija</h2></td>
  </tr>
  <tr>
    <td class="tbl2" colspan="3" align="center"><table border=0>';
         
         echo '<tr>
         <td><img src="'.IMAGES.'komanda/'.$kdjs['nuotrauka'].'" height="120" align="right"></td>
         <td>';
         
         echo $locale['k01'].' <a href="'.($kdjs['user_id'] == "" ? "#" : $kdjs['user_id']).'">'.$kdjs['slapyvardis'].'</a><br />';
         echo ($kdjs['amzius'] == "" ? "" : "".$locale['k02']." ".$kdjs['amzius']."<br />");
         echo ($kdjs['miestas'] == "" ? "" : "".$locale['k03']." ".$kdjs['miestas']."<br />");
         echo ($kdjs['laida'] == "" ? "" : "".$locale['k06']." ".$kdjs['laida']."<br />");
         echo $locale['k04'].' '.$kdjs['pareigos'].'<br />';
         echo $locale['k05'].' '.$kdjs['kontaktai'].'<br />';
         echo '</td>
         </tr>';
         
         echo '</table></td>
  </tr>
  <tr>
    <td class="tbl2" align="center"><form method="POST" action="admin.php'.$aidlink.'"><input type="hidden" name="id" value="'.$kdjs['id'].'"><input type="hidden" name="do" value="edit"><input type="submit" value="'.$locale['a15'].'" class="button"></form></td>
    <td class="tbl2" align="center"><form method="POST" action="admin.php'.$aidlink.'"><input type="hidden" name="id" value="'.$kdjs['id'].'"><input type="hidden" name="do" value="del"><input type="submit" value="'.$locale['a16'].'" class="button"></form></td>
  </tr>
 </table>
';
}
} else {
echo "<center>".$locale['a36']."</center>";
}
}else{
echo "<center>".$locale['a34']."</center>";
}
closetable();

require_once THEMES."templates/footer.php";
?>