2 /* make sure that we are not called from outside the scripts,
3 * use a variable defined in config.php to check this
14 global $DB,$DB_user,$DB_host,$DB_database,$DB_password;
15 $DB = @mysql_connect($DB_host,$DB_user, $DB_password);
18 mysql_select_db($DB_database) or die('Could not select database');
33 function DB_quote_smart($value)
36 if (get_magic_quotes_gpc()) {
37 $value = stripslashes($value);
39 /* Quote if not a number or a numeric string */
40 if (!is_numeric($value)) {
41 $value = "'" . mysql_real_escape_string($value) . "'";
48 $result = DB_query("SELECT * FROM User");
49 while($r = DB_fetch_array($result))
58 /* use Mysql in the background */
59 function DB_query($query)
61 return mysql_query($query);
64 function DB_fetch_array($result)
66 return mysql_fetch_array($result,MYSQL_NUM);
69 function DB_insert_id()
71 return mysql_insert_id();
74 function DB_num_rows($result)
76 return mysql_num_rows($result);
78 /* end Mysql functions */
80 function DB_query_array($query)
82 $result = DB_query($query);
83 $return = DB_fetch_array($result);
88 function DB_get_passwd_by_name($name)
90 $r = DB_query_array("SELECT password FROM User WHERE fullname=".DB_quote_smart($name)."");
98 function DB_get_passwd_by_userid($id)
100 $r = DB_query_array("SELECT password FROM User WHERE id=".DB_quote_smart($id)."");
108 function DB_check_recovery_passwords($password,$email)
110 $r = DB_query_array("SELECT User.id FROM User".
111 " LEFT JOIN Recovery ON User.id=Recovery.user_id".
112 " WHERE email=".DB_quote_smart($email).
113 " AND Recovery.password=".DB_quote_smart($password).
114 " AND DATE_SUB(CURDATE(),INTERVAL 1 DAY) <= Recovery.create_date");
121 function DB_get_handid($type,$var1='',$var2='')
126 $r = DB_query_array("SELECT id FROM Hand WHERE hash=".DB_quote_smart($var1));
128 case 'gameid-position':
129 $r = DB_query_array("SELECT id FROM Hand WHERE game_id=".
130 DB_quote_smart($var1)." AND position=".
131 DB_quote_smart($var2));
133 case 'gameid-userid':
134 $r = DB_query_array("SELECT id FROM Hand WHERE game_id=".
135 DB_quote_smart($var1)." AND user_id=".
136 DB_quote_smart($var2));
146 function DB_get_pos_by_hash($hash)
148 $r= DB_query_array("SELECT position FROM Hand WHERE hash=".DB_quote_smart($hash));
156 function DB_get_status_by_hash($hash)
158 $r= DB_query_array("SELECT status FROM Hand WHERE hash=".DB_quote_smart($hash));
166 function DB_set_game_status_by_gameid($id,$status)
168 DB_query("UPDATE Game SET status='".$status."' WHERE id=".DB_quote_smart($id));
172 function DB_set_sickness_by_gameid($id,$status)
174 DB_query("UPDATE Game SET sickness='".$status."' WHERE id=".DB_quote_smart($id));
177 function DB_get_sickness_by_gameid($id)
179 $r = DB_query_array("SELECT sickness FROM Game WHERE id=".DB_quote_smart($id));
187 function DB_get_game_status_by_gameid($id)
189 $r = DB_query_array("SELECT status FROM Game WHERE id=".DB_quote_smart($id));
197 function DB_set_hand_status_by_hash($hash,$status)
199 DB_query("UPDATE Hand SET status='".$status."' WHERE hash=".DB_quote_smart($hash));
203 function DB_get_hand_status_by_userid_and_gameid($uid,$gid)
205 $r = DB_query_array("SELECT status FROM Hand WHERE user_id=".DB_quote_smart($uid).
206 " AND game_id=".DB_quote_smart($gid));
213 function DB_get_sickness_by_userid_and_gameid($uid,$gid)
215 $r = DB_query_array("SELECT sickness FROM Hand WHERE user_id=".DB_quote_smart($uid).
216 " AND game_id=".DB_quote_smart($gid));
223 function DB_get_sickness_by_pos_and_gameid($pos,$gid)
225 $r = DB_query_array("SELECT sickness FROM Hand WHERE position=".DB_quote_smart($pos).
226 " AND game_id=".DB_quote_smart($gid));
233 function DB_get_gameid_by_hash($hash)
235 $r = DB_query_array("SELECT game_id FROM Hand WHERE hash=".DB_quote_smart($hash));
243 function DB_cancel_game($hash)
245 $gameid = DB_get_gameid_by_hash($hash);
250 /* get the IDs of all players */
251 $result = DB_query("SELECT id FROM Hand WHERE game_id=".DB_quote_smart($gameid));
252 while($r = DB_fetch_array($result))
256 $tmp = DB_query_array("SELECT id FROM Hand_Card WHERE hand_id=".DB_quote_smart($id));
257 DB_query("DELETE FROM Play WHERE hand_card_id=".DB_quote_smart($tmp[0]));
259 DB_query("DELETE FROM Hand_Card WHERE hand_id=".DB_quote_smart($id));
260 DB_query("DELETE FROM Hand WHERE id=".DB_quote_smart($id));
264 DB_query("DELETE FROM User_Game_Prefs WHERE game_id=".DB_quote_smart($gameid));
265 DB_query("DELETE FROM Trick WHERE game_id=".DB_quote_smart($gameid));
266 DB_query("DELETE FROM Game WHERE id=".DB_quote_smart($gameid));
271 function DB_get_hand($me)
275 $handid = DB_get_handid('hash',$me);
277 $result = DB_query("SELECT card_id FROM Hand_Card WHERE hand_id=".DB_quote_smart($handid)." and played='false' ");
278 while($r = DB_fetch_array($result))
284 function DB_get_all_hand($me)
288 $handid = DB_get_handid('hash',$me);
290 $result = DB_query("SELECT card_id FROM Hand_Card WHERE hand_id=".DB_quote_smart($handid));
291 while($r = DB_fetch_array($result))
297 function DB_get_cards_by_trick($id)
302 $result = DB_query("SELECT card_id,position FROM Play LEFT JOIN Hand_Card ON Hand_Card.id=Play.hand_card_id ".
303 "LEFT JOIN Hand ON Hand.id=Hand_Card.hand_id ".
305 DB_quote_smart($id)." ORDER BY sequence ASC");
306 while($r = DB_fetch_array($result))
308 $cards[$i]=array("card"=>$r[0],"pos"=>$r[1]);
316 function DB_set_solo_by_hash($hash,$solo)
318 DB_query("UPDATE Hand SET solo=".DB_quote_smart($solo)." WHERE hash=".DB_quote_smart($hash));
322 function DB_set_solo_by_gameid($id,$solo)
324 DB_query("UPDATE Game SET solo=".DB_quote_smart($solo)." WHERE id=".DB_quote_smart($id));
328 function DB_set_sickness_by_hash($hash,$sickness)
330 DB_query("UPDATE Hand SET sickness=".DB_quote_smart($sickness)." WHERE hash=".DB_quote_smart($hash));
334 function DB_get_current_trickid($gameid)
340 $result = DB_query("SELECT Trick.id,MAX(Play.sequence) FROM Play ".
341 "LEFT JOIN Trick ON Play.trick_id=Trick.id ".
342 "WHERE Trick.game_id=".DB_quote_smart($gameid)." ".
343 "GROUP BY Trick.id");
344 while( $r = DB_fetch_array($result) )
351 if(!$sequence || $sequence==4)
353 DB_query("INSERT INTO Trick VALUES (NULL,NULL,NULL, ".DB_quote_smart($gameid).",NULL)");
354 $trickid = DB_insert_id();
363 return array($trickid,$sequence,$number);
366 function DB_get_max_trickid($gameid)
368 $r = DB_query_array("SELECT MAX(id) FROM Trick WHERE game_id=".DB_quote_smart($gameid));
370 return ($r?$r[0]:NULL);
373 function DB_play_card($trickid,$handcardid,$sequence)
375 DB_query("INSERT INTO Play VALUES(NULL,NULL,NULL,".DB_quote_smart($trickid).
376 ",".DB_quote_smart($handcardid).",".DB_quote_smart($sequence).")");
378 $playid = DB_insert_id();
382 function DB_get_all_names_by_gameid($id)
386 $result = DB_query("SELECT fullname FROM Hand LEFT JOIN User ON Hand.user_id=User.id WHERE game_id=".
387 DB_quote_smart($id)." ORDER BY position ASC");
388 while($r = DB_fetch_array($result))
394 function DB_get_all_userid_by_gameid($id)
398 $result = DB_query("SELECT user_id FROM Hand WHERE game_id=".
399 DB_quote_smart($id)." ORDER BY position ");
400 while($r = DB_fetch_array($result))
406 function DB_get_hash_from_game_and_pos($id,$pos)
408 $r = DB_query_array("SELECT hash FROM Hand WHERE game_id=".DB_quote_smart($id)." and position=".DB_quote_smart($pos));
416 function DB_get_hash_from_gameid_and_userid($id,$user)
418 $r = DB_query_array("SELECT hash FROM Hand WHERE game_id=".DB_quote_smart($id)." and user_id=".DB_quote_smart($user));
426 function DB_get_all_names()
430 $result = DB_query("SELECT fullname FROM User");
431 while($r = DB_fetch_array($result))
437 function DB_get_names_of_last_logins($N)
441 $result = DB_query("SELECT fullname FROM User ORDER BY last_login DESC LIMIT $N");
442 while($r = DB_fetch_array($result))
448 function DB_get_names_of_new_logins($N)
452 $result = DB_query("SELECT fullname FROM User ORDER BY create_date DESC, id DESC LIMIT $N");
453 while($r = DB_fetch_array($result))
459 function DB_update_game_timestamp($gameid)
461 DB_query("UPDATE Game SET mod_date = CURRENT_TIMESTAMP WHERE id=".DB_quote_smart($gameid));
466 function DB_update_user_timestamp($userid)
468 DB_query("UPDATE User SET last_login = CURRENT_TIMESTAMP WHERE id=".DB_quote_smart($userid));
472 function DB_get_user_timestamp($userid)
474 $r = DB_query_array("SELECT last_login FROM User WHERE id=".DB_quote_smart($userid));
481 function DB_get_user_timezone($userid)
483 $r = DB_query_array("SELECT timezone FROM User WHERE id=".DB_quote_smart($userid));
488 return "Europe/London";
491 function DB_insert_comment($comment,$playid,$userid)
493 DB_query("INSERT INTO Comment VALUES (NULL,NULL,NULL,$userid,$playid, ".DB_quote_smart($comment).")");
498 function DB_insert_note($comment,$gameid,$userid)
500 DB_query("INSERT INTO Notes VALUES (NULL,NULL,NULL,$userid,$gameid, ".DB_quote_smart($comment).")");
505 function DB_get_notes_by_userid_and_gameid($userid,$gameid)
509 $result = DB_query("SELECT comment FROM Notes WHERE user_id=".DB_quote_smart($userid) .
510 " AND game_id=".DB_quote_smart($gameid));
512 while($r = DB_fetch_array($result))
519 function DB_get_gametype_by_gameid($id)
521 $r = DB_query_array("SELECT type FROM Game WHERE id=".DB_quote_smart($id));
529 function DB_set_gametype_by_gameid($id,$p)
531 DB_query("UPDATE Game SET type='".$p."' WHERE id=".DB_quote_smart($id));
535 function DB_get_solo_by_gameid($id)
537 $r = DB_query_array("SELECT solo FROM Game WHERE id=".DB_quote_smart($id));
546 function DB_get_startplayer_by_gameid($id)
548 $r = DB_query_array("SELECT startplayer FROM Game WHERE id=".DB_quote_smart($id));
556 function DB_set_startplayer_by_gameid($id,$p)
558 DB_query("UPDATE Game SET startplayer='".$p."' WHERE id=".DB_quote_smart($id));
562 function DB_get_player_by_gameid($id)
564 $r = DB_query_array("SELECT player FROM Game WHERE id=".DB_quote_smart($id));
571 function DB_set_player_by_gameid($id,$p)
573 DB_query("UPDATE Game SET player='".DB_quote_smart($p)."' WHERE id=".DB_quote_smart($id));
579 function DB_get_ruleset_by_gameid($id)
581 $r = DB_query_array("SELECT ruleset FROM Game WHERE id=".DB_quote_smart($id));
589 function DB_get_session_by_gameid($id)
591 $r = DB_query_array("SELECT session FROM Game WHERE id=".DB_quote_smart($id));
599 function DB_get_max_session()
601 $r = DB_query_array("SELECT MAX(session) FROM Game");
609 function DB_get_hashes_by_session($session,$user)
613 $result = DB_query("SELECT Hand.hash FROM Hand".
614 " LEFT JOIN Game ON Game.id=Hand.game_id ".
615 " WHERE Game.session=".DB_quote_smart($session).
616 " AND Hand.user_id=".DB_quote_smart($user).
617 " ORDER BY Game.create_date ASC");
618 while($t = DB_fetch_array($result))
624 function DB_get_ruleset($dullen,$schweinchen,$call)
628 $result = DB_query("SELECT id FROM Rulesets WHERE".
629 " dullen=".DB_quote_smart($dullen)." AND ".
630 " call=".DB_quote_smart($call)." AND ".
631 " schweinchen=".DB_quote_smart($schweinchen));
633 $r = DB_fetch_array($result);
636 return $r[0]; /* found ruleset */
640 $result = DB_query("INSERT INTO Rulesets VALUES (NULL, NULL, ".
641 DB_quote_smart($dullen).",".
642 DB_quote_smart($schweinchen).",".
643 DB_quote_smart($call).
646 return DB_insert_id();
649 return -1; /* something went wrong */
652 function DB_get_party_by_hash($hash)
654 $r = DB_query_array("SELECT party FROM Hand WHERE hash=".DB_quote_smart($hash));
662 function DB_get_party_by_gameid_and_userid($gameid,$userid)
664 $r = DB_query_array("SELECT party FROM Hand".
665 " WHERE game_id=".DB_quote_smart($gameid).
666 " AND user_id=".DB_quote_smart($userid));
673 function DB_set_party_by_hash($hash,$party)
675 DB_query("UPDATE Hand SET party=".DB_quote_smart($party)." WHERE hash=".DB_quote_smart($hash));
679 function DB_get_PREF($myid)
682 $r = DB_query_array("SELECT value from User_Prefs".
683 " WHERE user_id='$myid' AND pref_key='cardset'" );
686 /* licence only valid until then */
687 if($r[0]=="altenburg" && (time()-strtotime( "2009-12-31 23:59:59")<0) )
688 $PREF["cardset"]="altenburg";
690 $PREF["cardset"]="english";
693 $PREF["cardset"]="english";
696 $r = DB_query_array("SELECT value FROM User_Prefs".
697 " WHERE user_id='$myid' AND pref_key='email'" );
700 if($r[0]=="emailaddict")
701 $PREF["email"]="emailaddict";
703 $PREF["email"]="emailnonaddict";
706 $PREF["email"]="emailnonaddict";
709 $r = DB_query_array("SELECT value FROM User_Prefs".
710 " WHERE user_id='$myid' AND pref_key='autosetup'" );
714 $PREF['autosetup']='yes';
716 $PREF['autosetup']='no';
719 $PREF['autosetup']='no';
724 function DB_get_RULES($gameid)
726 $r = DB_query_array("SELECT * FROM Rulesets".
727 " LEFT JOIN Game ON Game.ruleset=Rulesets.id ".
728 " WHERE Game.id='$gameid'" );
730 $RULES["dullen"] = $r[2];
731 $RULES["schweinchen"] = $r[3];
732 $RULES["call"] = $r[4];
737 function DB_get_email_pref_by_hash($hash)
739 $r = DB_query_array("SELECT value FROM Hand".
740 " LEFT JOIN User_Prefs ON Hand.user_id=User_Prefs.user_id".
741 " WHERE hash='$hash' AND pref_key='email'" );
744 if($r[0]=="emailaddict")
745 return "emailaddict";
747 return "emailnonaddict";
750 return "emailnonaddict";
753 function DB_get_email_pref_by_uid($uid)
755 $r = DB_query_array("SELECT value FROM User_Prefs ".
756 " WHERE user_id='$uid' AND pref_key='email'" );
759 if($r[0]=="emailaddict")
760 return "emailaddict";
762 return "emailnonaddict";
765 return "emailnonaddict";
768 function DB_get_unused_randomnumbers($userstr)
770 $r = DB_query_array(" SELECT randomnumbers FROM Game".
771 " WHERE randomnumbers NOT IN".
772 " (SELECT randomnumbers FROM Game".
773 " LEFT JOIN Hand ON Game.id=Hand.game_id".
774 " WHERE user_id IN (". $userstr .")".
775 " GROUP BY randomnumbers".
783 function DB_get_number_of_passwords_recovery($user)
785 $r = DB_query_array("SELECT COUNT(*) FROM Recovery ".
786 " WHERE user_id=$user ".
787 " AND DATE_SUB(CURDATE(),INTERVAL 1 DAY) <= create_date".
788 " GROUP BY user_id " );
795 function DB_set_recovery_password($user,$newpw)
797 DB_query("INSERT INTO Recovery VALUES(NULL,".DB_quote_smart($user).
798 ",".DB_quote_smart($newpw).",NULL)");
802 function DB_get_card_name($card)
804 $r = DB_query_array("SELECT strength,suite FROM Card WHERE id='$card'");
807 return $r[0]." of ".$r[1];
809 return "Error during get_card_name ".$card;
812 function DB_get_current_playid($gameid)
814 $trick = DB_get_max_trickid($gameid);
816 if(!$trick) return NULL;
818 $r = DB_query_array("SELECT id FROM Play WHERE trick_id='$trick' ORDER BY create_date DESC LIMIT 1");
826 function DB_get_call_by_hash($hash)
828 $r = DB_query_array("SELECT point_call FROM Hand WHERE hash='$hash'");
836 function DB_get_partner_call_by_hash($hash)
838 $partner = DB_get_partner_hash_by_hash($hash);
842 $r = DB_query_array("SELECT point_call FROM Hand WHERE hash='$partner'");
851 function DB_get_partner_hash_by_hash($hash)
853 $gameid = DB_get_gameid_by_hash($hash);
854 $party = DB_get_party_by_hash($hash);
856 $r = DB_query_array("SELECT hash FROM Hand WHERE game_id='$gameid' AND party='$party' AND hash<>'$hash'");
864 function DB_format_gameid($gameid)
866 $session = DB_get_session_by_gameid($gameid);
868 /* get number of game */
869 $r = DB_query_array("SELECT COUNT(*),create_date FROM Game".
870 " WHERE session='$session' ".
871 " AND TIMEDIFF(create_date, (SELECT create_date FROM Game WHERE id='$gameid'))<=0 ".
872 " GROUP by session");
873 return $session.".".$r[0];
876 function DB_get_reminder($user,$gameid)
878 $r = DB_query_array("SELECT COUNT(*) FROM Reminder ".
879 " WHERE user_id=$user ".
880 " AND game_id=$gameid ".
881 " AND DATE_SUB(CURDATE(),INTERVAL 1 DAY) <= create_date".
882 " GROUP BY user_id " );
889 function DB_set_reminder($user,$gameid)
891 DB_query("INSERT INTO Reminder ".
892 " VALUES(NULL, ".DB_quote_smart($user).", ".DB_quote_smart($gameid).
897 function DB_is_session_active($session)
899 $r = DB_query_array("SELECT COUNT(*) FROM Game ".
900 " WHERE session=$session ".
901 " AND status<>'gameover' ");
908 function DB_get_score_by_gameid($gameid)
910 /* returns the points of a game from the point of the re parth (<0 if they lost) */
911 $queryresult = DB_query("SELECT COUNT(*),party FROM Score ".
912 " WHERE game_id=$gameid ".
917 while($r = DB_fetch_array($queryresult) )
921 else if ($r[1] == "contra")
925 return ($re - $contra);
928 function DB_get_gameids_of_finished_games_by_session($session)
932 if($session==0) /* return all games */
933 $queryresult = DB_query("SELECT id FROM Game ".
934 " WHERE status='gameover' ".
935 " ORDER BY create_date ASC");
936 else /* return games in a session */
937 $queryresult = DB_query("SELECT id FROM Game ".
938 " WHERE session=$session ".
939 " AND status='gameover' ".
940 " ORDER BY create_date ASC");
943 while($r = DB_fetch_array($queryresult) )
952 function DB_get_card_value_by_cardid($id)
954 $r = DB_query_array("SELECT points FROM Card ".
963 function DB_get_userid($type,$var1="",$var2="")
965 /* get the userid of a user
966 * this can be done several ways, which are all handled below
967 * if a email/password combination is given and it doesn't work, we also
968 * need to check the recovery table for additional passwords
976 $result = DB_query("SELECT id FROM User WHERE fullname=".DB_quote_smart($var1));
979 $result = DB_query("SELECT user_id FROM Hand WHERE hash=".DB_quote_smart($var1));
982 $result = DB_query("SELECT id FROM User WHERE password=".DB_quote_smart($var1));
985 $result = DB_query("SELECT id FROM User WHERE email=".DB_quote_smart($var1));
987 case 'email-password':
988 $result = DB_query("SELECT id FROM User WHERE email=".DB_quote_smart($var1)." AND password=".DB_quote_smart($var2));
989 $r = DB_fetch_array($result);
990 /* test if a recovery password has been set */
993 echo "testing alternative password";
994 $result = DB_query("SELECT User.id FROM User".
995 " LEFT JOIN Recovery ON User.id=Recovery.user_id".
996 " WHERE email=".DB_quote_smart($var1).
997 " AND Recovery.password=".DB_quote_smart($var2).
998 " AND DATE_SUB(CURDATE(),INTERVAL 1 DAY) <= Recovery.create_date");
1001 case 'gameid-position':
1002 $result = DB_query("SELECT user_id FROM Hand WHERE game_id=".
1003 DB_quote_smart($var1)." AND position=".
1004 DB_quote_smart($var2));
1009 $r = DB_fetch_array($result);
1017 function DB_get_email($type,$var1='',$var2='')
1019 /* return the email of a user
1020 * this is used for sending out emails, but also for
1021 * testing the login for example
1026 $result = DB_query("SELECT email FROM User WHERE fullname=".DB_quote_smart($var1)."");
1029 $result = DB_query("SELECT email FROM User WHERE id=".DB_quote_smart($var1)."");
1032 $result = DB_query("SELECT User.email FROM User ".
1033 "LEFT JOIN Hand ON Hand.user_id=User.id ".
1034 "WHERE Hand.hash=".DB_quote_smart($var1)."");
1036 case 'position-gameid':
1037 $result = DB_query("SELECT email FROM User ".
1038 "LEFT JOIN Hand ON User.id=Hand.user_id ".
1039 "LEFT JOIN Game ON Game.id=Hand.game_id ".
1040 "WHERE Game.id=".DB_quote_smart($var2)." ".
1041 "AND Hand.position=".DB_quote_smart($var1)."");
1045 $r = DB_fetch_array($result);
1053 function DB_get_name($type,$var1='')
1055 /* get the full name of a user
1056 * a user can be uniquely identified several ways
1061 $r = DB_query_array("SELECT fullname FROM Hand LEFT JOIN User ON Hand.user_id=User.id WHERE hash=".DB_quote_smart($var1));
1064 $r = DB_query_array("SELECT fullname FROM User WHERE email=".DB_quote_smart($var1));
1067 $r = DB_query_array("SELECT fullname FROM User WHERE id=".DB_quote_smart($var1));