Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Snitz Forums 2000 MOD-Group
 MOD Add-On Forum (W/O Code)
 Warn Members Mod 2.00
 New Topic  Reply to Topic
 Printer Friendly
Previous Page | Next Page
Author Previous Topic Topic Next Topic
Page: of 4

AnonJr
Moderator

United States
5768 Posts

Posted - 15 July 2006 :  10:45:44  Show Profile  Visit AnonJr's Homepage  Reply with Quote
Personally, I'd go a head and run all your Form variables through ChkString. Its safer and precludes certain problems with potential SQL injection attacks.

Also, I think for what you're doing ChkString should be:
ChkString(Request.Form("strWarnMessage"),"sqlstring")
Or at least for when you are placing it in the SQL String.<

Edited by - AnonJr on 15 July 2006 10:46:36
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 15 July 2006 :  10:52:18  Show Profile  Visit modifichicci's Homepage  Reply with Quote
Yes you are right, but that string is quite sure i think as only administrator or moderator can write.. but i'll change it ( but in post_info message is checked with
txtMessage = ChkString(Request.Form("Message"),"message")
)<

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 15 July 2006 :  11:01:22  Show Profile  Visit AnonJr's Homepage  Reply with Quote
I'll double check, but I think the option "message" is being used when it is sent back to the browser and the option "sqlstring" is for when the text is inserted into a SQL String...<
Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 15 July 2006 :  11:04:33  Show Profile  Visit AnonJr's Homepage  Reply with Quote
Hmmm. Never noticed it... in other areas items that are being passed to the SQL String are checked like I put above, but the message isn't in that particular case.<
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 15 July 2006 :  12:31:14  Show Profile  Visit modifichicci's Homepage  Reply with Quote
Done zip updated, thanks.

Change
txtMessage = ChkString(Request.Form("strWarnMessage"),"message")

to
txtMessage = ChkString(Request.Form("strWarnMessage"),"sqlstring")

both in admin_warning and pop_warning
<

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page

Shaggy
Support Moderator

Ireland
6780 Posts

Posted - 17 July 2006 :  05:13:22  Show Profile  Reply with Quote
quote:
Originally posted by AnonJr
I'll double check, but I think the option "message" is being used when it is sent back to the browser and the option "sqlstring" is for when the text is inserted into a SQL String...
"sqlstring" is used when insterting a string in the database, "message" is used to parse any forum code in a string when adding it to the database. For the most part, "display" will be used when writing values from the database with seperate function (formatstr) used to parse any additional forum code.

<

Search is your friend
“I was having a mildly paranoid day, mostly due to the
fact that the mad priest lady from over the river had
taken to nailing weasels to my front door again.”
Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 17 July 2006 :  12:21:01  Show Profile  Visit AnonJr's Homepage  Reply with Quote
Thanks for the clarification. Now I need to copy that down somewhere before my short-term-memory-thing kicks in... <
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 17 July 2006 :  13:32:19  Show Profile  Visit modifichicci's Homepage  Reply with Quote
The same for me...<

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page

Simko
Starting Member

25 Posts

Posted - 07 October 2006 :  04:04:23  Show Profile  Reply with Quote
I'll install this mod to the newest version of snitz forums which I'm currently modify. I'd like to send the warning via PM, not E-mail, cause via PM the User will recognice earlier. Could someone maybe give me the codes for the sites I need there to send the warning via PM?<

Edited by - Simko on 07 October 2006 04:05:01
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 07 October 2006 :  05:06:35  Show Profile  Visit modifichicci's Homepage  Reply with Quote
You have first to install the PM mod, and then to modify the code of inc_warnmembers_email.asp to set for a PM..<

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page

Simko
Starting Member

25 Posts

Posted - 07 October 2006 :  11:46:00  Show Profile  Reply with Quote
Thanks, I've installed the mod, but I'm pretty new to this... sorry :-) What do I have to change here

________________

Thanks AnonJr... I really don't know what to change, even it is only a "relatively small chunk of code", if I knew it, I wouldn't post in here and asking for help...
<

Edited by - Simko on 07 October 2006 13:32:10
Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 07 October 2006 :  12:50:35  Show Profile  Visit AnonJr's Homepage  Reply with Quote
Just a helpful hint, if you need us to look at a file (as opposed to a relatively small chunk of code) its usually considered good etiquette to post a link to a .txt version of the file instead of posting the entire contents...<
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 07 October 2006 :  15:16:04  Show Profile  Visit modifichicci's Homepage  Reply with Quote
It's not to change, we have to write the code to send PM to user...
It's not quite difficult, but it needs time..

But why Pm and not email?
If user doesn't come in forum he doesn't read the pm...<

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page

Simko
Starting Member

25 Posts

Posted - 07 October 2006 :  15:26:47  Show Profile  Reply with Quote
Thanks for answering modifichicci. The user will see the PM earlier than the E-mail (most of them just delete such E-mails and never read them...). Yeah, you are right, if the user doesn't come the the forum, he doesn't read the PM, but then theres no need to read the warning, if he doesn't come back ever :-) Would be nice if you can write a script for that.<
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 07 October 2006 :  16:04:54  Show Profile  Visit modifichicci's Homepage  Reply with Quote
Next days... I'll give a look at it.<

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page
Page: of 4 Previous Topic Topic Next Topic  
Previous Page | Next Page
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.14 seconds. Powered By: Snitz Forums 2000 Version 3.4.07