PHP: How to Configure and where to Place Formmail Code?

  • CGFX
  • Graduate
  • Graduate
  • User avatar
  • Posts: 161
  • Loc: Chicago, IL.

Post 3+ Months Ago

All,

On this page http://luxuryspeed.com/contactUs.php the customer wants a form created something like the below.

Please write to us with any comments, questions or segestions you migthhave.

Firstname Lastname: Editor name@website.com

Firstname Lastname: AccountingManager name@website.com

To advertise on website.comadvertise@website.com

Your Name: *


Your Email: *


Subject:


Message: *



My boss want me to use Formmail.php, but I am not a PHP programmer, he said that it is easy, but he was not able to show me.

Here is the formmail php code.
Code: [ Select ]
 
<?PHP
define('VERSION','Classic v1.07.2');
define('MANUAL','http://www.boaddrink.com/projects/phpformmail/readme.php');
define('CHECK_REFERER', true);
 
// +------------------------------------------------------------------------+
// | PHPFormMail                                                            |
// | Copyright (c) 1999 Andrew Riley (webmaster@boaddrink.com)              |
// |                                                                        |
// | This program is free software; you can redistribute it and/or          |
// | modify it under the terms of the GNU General Public License            |
// | as published by the Free Software Foundation; either version 2         |
// | of the License, or (at your option) any later version.                 |
// |                                                                        |
// | This program is distributed in the hope that it will be useful,        |
// | but WITHOUT ANY WARRANTY; without even the implied warranty of         |
// | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.   See the     |
// | GNU General Public License for more details.                           |
// |                                                                        |
// | You should have received a copy of the GNU General Public License      |
// | along with this program; if not, write to the Free Software            |
// | Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111-1307, |
// | USA.                                                                   |
// |                                                                        |
// +------------------------------------------------------------------------+
// |                                                                        |
// | If you run into any problems, pleas read the readme_formmail.txt.      |
// | If that does not help, check out http://www.boaddrink.com.             |
// |                                                                        |
// | For more info, please visit http://www.boaddrink.com or read the       |
// | readme file included.                                                  |
// +------------------------------------------------------------------------+
// |                                                                        |
// | Value array fix by: Konrad Maqestieau                                  |
// | check_recipients reset() fix by: Don                                   |
// | servertime_offset code by: desolate                                    |
// |                                                                        |
// +------------------------------------------------------------------------+
 
// To change the address the e-mail comes from use define('FROM', 'Example Name <email@example.com>');
define('FROM', null);
 
$referers = array('www.venetianinn.net', 'venetianinn.net', 'www.venetianinn.com', 'venetianinn.com');
 
// $recipient_array format is $recipient_array = array('sometext'=>'email@example.com','asdf'=>'email2@example.com');
$recipient_array = array();
 
$valid_env = array('REMOTE_HOST', 'REMOTE_ADDR', 'REMOTE_USER', 'HTTP_USER_AGENT');
 
// +------------------------------------------------------------------------+
// | STOP EDITING! The only two required variables that need to be updated  |
// | are $referers and $valid_env                                           |
// +------------------------------------------------------------------------+
 
$errors = $fieldname_lookup = array();
$invis_array = array('recipient','subject','required','redirect',
             'print_blank_fields','env_report','sort',
             'missing_fields_redirect','title','bgcolor',
             'text_color','link_color','alink_color',
             'vlink_color','background','subject','title',
             'link','css','return_link_title',
             'return_link_url','recipient_cc','recipient_bcc',
                 'priority','redirect_values','hidden','alias',
         'mail_newline', 'gmt_offset', 'alias_method',
         'subject_prefix');
 
/****************************************************************
 * fake_in_array() is only used in PHP3 since PHP4 has a native *
 * in_array.  Depending on what version of PHP you are running  *
 * the script will determine what is the best function to run   *
 * --- THER IS NO LONGER ANY REASON TO DELETE THIS FUNCTION --- *
 * Function renamed in 1.04.0                   *
 ****************************************************************/
 
function fake_in_array($needle, $haystack)
{
    $found = false;
    while (list($key,$val) = each ($haystack)) {
        if ($needle == $val)
            $found = true;
    }
    return $found;
}
 
/****************************************************************
 * check_referer() breaks up the enviromental variable      *
 * HTTP_REFERER by "/" and then checks to see if the second *
 * member of the array (from the explode) matches any of the    *
 * domains listed in the $referers array (declaired at top) *
 ****************************************************************/
 
function check_referer($referers)
{
    global $errors;
    if (count($referers)) {
        if (getenv('HTTP_REFERER')) {
            $temp = explode('/', getenv('HTTP_REFERER'));
            $found = false;
            while (list(,$stored_referer) = each($referers)) {
                if (eregi('^' . $stored_referer . '$', $temp[2]))
                    $found = true;
            }
            if (!$found) {
                $errors[] = '1|You are coming from an unauthorized domain.  Please read the manual section titled &quot;<a href="' . MANUAL . '#setting_up" target="_blank">Setting Up the PHPFormMail Script</a>&quot;.';
                error_log('[PHPFormMail] Illegal Referer. (' . getenv('HTTP_REFERER') . ')', 0);
            }
            return $found;
        } else {
            $errors[] = '0|Sorry, but I cannot figure out who sent you here.  Your browser is not sending an HTTP_REFERER.  This could be caused by a firewall or browser that removes the HTTP_REFERER from each HTTP request you submit.';
            error_log('[PHPFormMail] HTTP_REFERER not defined. Browser: ' . getenv('HTTP_USER_AGENT') . '; Client IP: ' . getenv('REMOTE_ADDR') . '; Request Method: ' . getenv('REQUEST_METHOD') . ';', 0);
            return false;
        }
    } else {
        $errors[] = '1|There are no referers defined.  All submissions will be denied.  Please read the manual section titled &quot;<a href="' . MANUAL . '#setting_up" target="_blank">Setting Up the PHPFormMail Script</a>&quot;.';
        error_log('[PHPFormMail] You have no referers defined.  All submissions will be denied.', 0);
        return false;
    }
}
 
/****************************************************************
 * check_recipients() breaks up the recipents e-mail addresses  *
 * and then crossrefrences the domains that are legal referers  *
 * Function added in 1.3.1                                      *
 ****************************************************************/
 
function check_recipients($recipient_list)
{
    global $errors, $referers;
    $recipients_ok = true;
    $recipient_list = explode(',', $recipient_list);
    while (list(,$recipient) = each($recipient_list)) {
        $recipient_domain = false;
        $recipient = trim($recipient);
        reset($referers);
        while ((list(,$stored_domain) = each($referers)) && ($recipient_domain == false)) {
            if (eregi('^[_\.a-z0-9-]*@' . $stored_domain . '$', $recipient))
                $recipient_domain = true;
        }
        if ($recipient_domain == false) {
            $recipients_ok = false;
            error_log('[PHPFormMail] Illegal Recipient: ' . $recipient . ' from ' . getenv('HTTP_REFERER'), 0);
        }
    }
    if (!$recipients_ok)
        $errors[] = '1|You are trying to send mail to a domain that is not in the allowed recipients list.   Please read the manual section titled &quot;<a href="' . MANUAL . '#setting_up" target="_blank">Setting Up the PHPFormMail Script</a>&quot;.';
    return join(',', $recipient_list);
}
 
/****************************************************************
 * map_recipients() takes the array and maps them to the proper *
 * e-mail addresses from $recipient_array.  If this function is *
 * called then the e-mail addresses are not checked against the *
 * referer array.                                               *
 * Function added in 1.7.0                                      *
 ****************************************************************/
 
function map_recipients($recipient_list)
{
    global $errors, $recipient_array;
    $recipients_ok = true;
    $recipient_list = explode(',',$recipient_list);
    while (list(,$val) = each($recipient_list)){
        $val = trim($val);
        if(isset($recipient_array[$val]))
            $output[] = $recipient_array[$val];
        else
            $recipients_ok = false;
    }
    if (!$recipients_ok)
        $errors[] = '1|You are trying to send mail to an address that is not listed in the recipient array.';
    if (isset($output))
        return join(',', $output);
    else
        return null;
}
 
/****************************************************************
 * decode_vars() is used to assign all of the variables passed  *
 * into the form to a generic variable.  Allthough there are    *
 * two official form actions, POST and GET, I decided to use    *
 * this variable method so if more actions are invented, I  *
 * wouldn't have to change anything.                *
 *                              *
 * In the first line, the request methood is assigned to    *
 * $request with HTTP_ and _VARS appended to it.        *
 * In the second line uses PHPs variable variable.      *
 * It's basically addressing the variable $HTTP_POST_VARS or    *
 * $HTTP_GET_VARS and returning that.  Read more about      *
 * variable variables in the PHP documentation.         *
 ****************************************************************/
 
function decode_vars()
{
    if (isset($_REQUEST))
        $request = '_' . getenv('REQUEST_METHOD');
    else
        $request = 'HTTP_' . getenv('REQUEST_METHOD') . '_VARS';
    global $$request;
    if (count($$request) > 0) {
        while (list($key, $val) = each($$request)) {
            if (is_array($val))
                $val = implode(', ',$val);
            $output[$key] = stripslashes($val);
        }
        return $output;
    } else
        return array();
}
 
 
/****************************************************************
 * error() is our generic error function.           *
 * When called, it checks for errors in the $errors array and   *
 * depending on $form["missing_fields_redirect"] will either    *
 * print out the errors by calling the function output_html()   *
 * or it will redirect to the location specified in     *
 * $form["missing_fields_redirect"].                *
 ****************************************************************/
 
function error()
{
    global $form, $natural_form, $errors;
    if (isset($form['missing_fields_redirect'])) {
        if (isset($form['redirect_values']))
            header('Location: ' . $form['missing_fields_redirect'] . '?' . getenv('QUERY_STRING') . "\r\n");
        else
            header('Location: ' . $form['missing_fields_redirect'] . "\r\n");
    } else {
        if(!isset($form['title']))
            $form['title'] = 'PHPFormMail - Error';
        $output = "<h1>The following errors were found:</h1>\n<ul>\n";
        $crit_error = 0;
        while (list(,$val) = each ($errors)) {
            list($crit,$message) = explode('|',$val);
            $output .= '  <li>' . $message . "</li>\n";
            if ($crit == 1)
                $crit_error = 1;
        }
        $output .= "</ul>\n";
        if ($crit_error == 1)
            $output .=  "<div class=\"crit\">PHPFormMail has experienced errors that must be fixed by the webmaster. Mail will NOT be sent until these issues are resolved.  Once these issues are resolved, you will have to resubmit your form to PHPFormMail for the mail to be sent.</div><div class=\"returnlink\">Please use the <a href=\"javascript&#058; history.back();\">back</a> button to return to the site.</div>\n";
        else
            $output .=  "<div class=\"returnlink\">Please use the <a href=\"javascript&#058; history.back();\">back</a> button to correct these errors.</div>\n";
        output_html($output);
    }
}
 
/****************************************************************
 * check_required() is the function that checks all required    *
 * fields to see if they are empty or match the provided regex  *
 * string (regex checking added in 1.02.0).         *
 *                              *
 * Should a required variable be empty or not match the regex   *
 * pattern, a error will be added to the global $errors array.  *
 ****************************************************************/
 
function check_required()
{
    global $form, $errors, $invis_array, $fieldname_lookup;
    $problem = true;
    if ((!isset($form['recipient'])) && (!isset($form['recipient_bcc']))) {
        $problem = false;
        $errors[] = '1|There is no recipient to send this mail to.  Please read the manual section titled &quot;<a href="' . MANUAL . '#recipient" target="_blank">Form Configuration - Recipient</a>&quot;.';
        error_log('[PHPFormMail] There is no recipient defined from ' . getenv('HTTP_REFERER'), 0);
    }
    if (isset($form['required'])) {
        $required = split(',', $form['required']);
        while (list(,$val) = each($required)) {
            $val = trim($val);
            $regex_field_name = $val . '_regex';
            if ((!isset($form[$val])) || (isset($form[$val]) && (strlen($form[$val]) < 1))) {
                $problem = false;
                if (isset($fieldname_lookup[$val]))
                    $field = $fieldname_lookup[$val];
                else
                    $field = $val;
                $errors[] = '0|Required value (<b>' . $field . '</b>) is missing.';
            } else if (isset($form[$regex_field_name])) {
                if (!eregi($form[$regex_field_name],$form[$val])) {
                    $problem = false;
                    $errors[] = '0|Required value (<b>' . $fieldname_lookup[$val] . '</b>) has an invalid format.';
                }
                $invis_array[] = $regex_field_name;
            }
        }
    }
    return $problem;
}
 
 
/****************************************************************
 * sort_fields() is responsable for sorting all fields in $form *
 * depending $form["sort"].                 *
 * There are three main sort methods: alphabetic, reverse   *
 * alphabetic, and user supplied.               *
 *                              *
 * The user supplied method is formatted "order:name,email,etc".*
 * The text "order" is required and the fields are comma    *
 * sepperated. ("order" is legacy from the PERL version.) If    *
 * the user supplied method leaves fields out of the comma  *
 * sepperated list, the remaining fields will be appended to    *
 * the end of the orderd list in the order they appear in the   *
 * form.                            *
 * Function added in 1.02.0                 *
 ****************************************************************/
 
function sort_fields()
{
    global $form;
    switch ($form['sort']) {
        case 'alphabetic':
        case 'alpha':       ksort($form);
                    break;
        case 'ralphabetic':
        case 'ralpha':      krsort($form);
                    break;
        default:        if ($col = strpos($form['sort'],':')) {
                        $form['sort'] = substr($form['sort'],($col + 1));
                        $temp_sort_arr = explode(',', $form['sort']);
                        for($x = 0; $x < count($temp_sort_arr); $x++) {
                            $out[$temp_sort_arr[$x]] = $form[$temp_sort_arr[$x]];
                            unset($form[$temp_sort_arr[$x]]);
                        }
                        $form = array_merge($out,$form);
                    }
    }
    return true;
}
 
 
/****************************************************************
 * alias_fields() creates a lookup array so we can use Aliases  *
 * for the field names.  If a alias is not available, the   *
 * lookup array is filled with the form field's name        *
 * Function added in 1.05.0                 *
 ****************************************************************/
 
function alias_fields()
{
    global $form, $fieldname_lookup;
    while (list($key,) = each($form)) {
        $fieldname_lookup[$key] = $key;
    }
    reset($form);
    if (isset($form['alias'])) {
        $aliases = explode(',', $form['alias']);
        while (list(,$val) = each($aliases)) {
            $temp = explode('=', $val);
            $fieldname_lookup[trim($temp[0])] = trim($temp[1]);
        }
    }
    return true;
}
 
 
/****************************************************************
 * send_mail() the function that parses the data into SMTP  *
 * format and sends the e-mail.                 *
 ****************************************************************/
 
function send_mail()
{
    global $form, $invis_array, $valid_env, $fieldname_lookup, $errors;
   
    $email_replace_array = "\r|\n|to:|cc:|bcc:";
   
    if (!isset($form['subject']))
            $form['subject'] = 'WWW Form Submission';
    if (isset($form['subject_prefix']))
            $form['subject'] = $form['subject_prefix'] . $form['subject'];
    if (!isset($form['email']))
            $form['email'] = 'email@example.com';
   
    switch ($form['mail_newline']) {
        case 2:     $mail_newline = "\r";
                break;
        case 3:     $mail_newline = "\r\n";
                break;
        default:    $mail_newline = "\n";
    }
   
    if (isset($form['gmt_offset']) && ereg('^(\-|\+)?([0-9]{1}|(1{1}[0-2]{1}))$', $form['gmt_offset'])) {
        $mkseconds = mktime(gmdate('H') + $form['gmt_offset']);
        $mail_date = gmdate('F jS, Y', $mkseconds) . ' at ' . gmdate('h:iA', $mkseconds) . ' (GMT ' . $form['gmt_offset'] . ').';
    } else
        $mail_date = date('F jS, Y') . ' at ' . date('h:iA (T).');
   
    if (isset($form['realname']))
        $realname = eregi_replace($email_replace_array,'',$form['realname']);
    elseif (isset($form['firstname']) || isset($form['lastname']))
        $realname = eregi_replace($email_replace_array,'',trim($form['firstname'] . ' ' . $form['lastname']));
 
    $mailbody = 'Below is the result of your feedback form.  It was submitted by' . $mail_newline;
    if (isset($realname))
        $mailbody.= $realname . ' (' . $form['email'] . ') on ' . $mail_date . $mail_newline . $mail_newline;
    else
        $mailbody.= $form['email'] . ' on ' . $mail_date . $mail_newline . $mail_newline;
 
    reset($form);
   
    while (list($key,$val) = each($form)) {
        if ((!in_array($key,$invis_array)) && ((isset($form['print_blank_fields'])) || ($val))) {
                if(($form['alias_method'] == 'email') || ($form['alias_method'] == 'both'))
                    $mailbody .= $fieldname_lookup[$key];
                else
                    $mailbody .= $key;
                $mailbody .= ': ' . $val . $mail_newline;
        }
    }
   
    if (isset($form['env_report'])) {
        $temp_env_report = explode(',', $form['env_report']);
        $mailbody .= $mail_newline . $mail_newline . '-------- Env Report --------' . $mail_newline;
        while (list(,$val) = each($temp_env_report)) {
            if (in_array($val,$valid_env))
                    $mailbody .= eregi_replace($email_replace_array,'',$val) . ': ' . eregi_replace($email_replace_array,'',getenv($val)) . $mail_newline;
        }
    }
 
    if (!isset($form['recipient']))
        $form['recipient'] = '';
 
    // Append lines to $mail_header that you wish to be
    // added to the headers of the e-mail. (SMTP Format
    // with newline char ending each line)
 
    $mail_header = 'Return-Path: ' . eregi_replace($email_replace_array,'',$return_path) . $mail_newline;
    if (FROM != null)
        $mail_header .= 'From: ' . FROM . $mail_newline;
    $mail_header .= 'Reply-to: ';
    if (isset($realname))
        $mail_header .= $realname . ' <' . eregi_replace($email_replace_array,'',$form['email']) . '>' . $mail_newline;
    else
        $mail_header .= eregi_replace($email_replace_array,'',$form['email']) . $mail_newline;
    if (isset($form['recipient_cc']))
        $mail_header .= 'Cc: ' . eregi_replace($email_replace_array,'',$form['recipient_cc']) . $mail_newline;
    if (isset($form['recipient_bcc']))
        $mail_header .= 'Bcc: ' . eregi_replace($email_replace_array,'',$form['recipient_bcc']) . $mail_newline;
    if (isset($form['priority']))
        $mail_header .= 'X-Priority: ' . ereg_replace($email_replace_array,'',$form['priority']) . $mail_newline;
    else
        $mail_header .= 'X-Priority: 3' . $mail_newline;
    $mail_header .= 'X-Mailer: PHPFormMail ' . VERSION . ' (http://www.boaddrink.com)' . $mail_newline;
    $mail_header .= 'X-Sender-IP: ' . eregi_replace($email_replace_array,'',getenv('REMOTE_ADDR')) . $mail_newline;
    $mail_header .= 'X-Referer: ' . eregi_replace($email_replace_array,'',getenv('HTTP_REFERER')) . $mail_newline;
   
    $form['subject'] = eregi_replace($email_replace_array,'',$form['subject']);
   
    if (eregi("MIME-|Content-|boundary", $mail_header . $mailbody . $form['subject']) == 0) {
        $mail_header .= 'Content-Type: text/plain; charset=utf-8' . $mail_newline;
        $mail_status = mail(eregi_replace($email_replace_array,'',$form['recipient']), $form['subject'], $mailbody, $mail_header);
        if (!$mail_status) {
            $errors[] = '1|Message could not be sent due to an error while trying to send the mail.';
            error_log('[PHPFormMail] Mail could not be sent due to an error while trying to send the mail.');
        } else {
            error_log('[PHPFormMail] Normal e-mail sent from IP ' . getenv('REMOTE_ADDR'));
        }
    } else {
            $mail_status = true;
            error_log('[PHPFormMail] Injection characters found from IP ' . getenv('REMOTE_ADDR') . '. Silently dropped');
    }
    return $mail_status;
}
 
 
/****************************************************************
 * output_html() is used to output all HTML to the browser. *
 * This function is called if there is an error or for the  *
 * "Thank You" page if neither are declaired as redirects.  *
 *                              *
 * While called output_html() it actually outputs valid XHTML   *
 * 1.0 documents.                       *
 * Function added in 1.02.0                 *
 ****************************************************************/
 
function output_html($body)
{
    global $form;
   
    $bgcolor    = isset($form['bgcolor']) ? ('background-color: ' . htmlspecialchars($form['bgcolor']) . ';') : ('background-color: #FFF;');
    $background = isset($form['background']) ? ('background-image: url(' . htmlspecialchars($form['background']) . ');') : NULL;
    $text_color = isset($form['text_color']) ? ('color: ' . htmlspecialchars($form['text_color']) . ';') : ('color: #000;');
    $link_color = isset($form['link_color']) ? ('color: ' . htmlspecialchars($form['link_color']) . ';') : NULL;
    $alink_color    = isset($form['alink_color']) ? ('color: ' . htmlspecialchars($form['alink_color']) . ';') : NULL;
    $vlink_color    = isset($form['vlink_color']) ? ('color: ' . htmlspecialchars($form['vlink_color']) . ';') : NULL;
   
    print "<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Transitional//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd\">\n";
    print "<html xmlns=\"http://www.w3.org/1999/xhtml\" xml:lang=\"en-US\" lang=\"en-US\">\n";
    print "<head>\n";
    print "  <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\" />\n";
    print "  <meta name=\"robots\" content=\"noindex,nofollow\" />\n";
    print "  <title>" . htmlspecialchars($form['title']) . "</title>\n";
    print "  <style type=\"text/css\">\n";
    print "    BODY {" . trim($bgcolor . ' ' . $text_color . ' ' . $background) . "}\n";
    if (isset($link_color))
        print "    A {" . $link_color . "}\n";
    if (isset($alink_color))
        print "    A:active {" . $alink_color . "}\n";
    if (isset($vlink_color))
        print "    A:visited {" . $vlink_color . "}\n";
    print "    h1 {font-size: 14pt; font-weight: bold; margin-bottom: 20pt}\n";
    print "    .crit {font-size: 12pt; font-weight: bold; color: #F00; margin-bottom: 10pt;}\n";
    print "    .returnlink {font-size: 12pt; margin-top: 20pt; margin-bottom: 20pt;}\n";
    print "    .validbutton {margin-top: 20pt; margin-bottom: 20pt;}\n";
    print "  </style>\n";
    if (isset($form['css']))
        print "  <link rel=\"stylesheet\" href=\"" . htmlspecialchars($form['css']) . "\">\n";
    print "</head>\n\n";
    print "<body>\n";
    print "<!-- PHPFormMail from http://www.boaddrink.com -->\n";
    print $body;
    print "<div class=\"validbutton\"><a href=\"http://validator.w3.org/check/referer\" target=\"_blank\"><img src=\"http://www.w3.org/Icons/valid-xhtml10\" style=\"border:0;width:88px;height:31px\" alt=\"Valid XHTML 1.0!\" /></a></div>\n";
    print "</body>\n";
    print "</html>";
}
 
 
$form = decode_vars();
 
if (count($form) > 0) {
   
    // PFMA remove if block
    // Determine (based on the PHP version) if we should use the native
    // PHP4 in_array or the coded fake_in_array
 
    if (phpversion() >= '4.0.0')
        $in_array_func = 'in_array';
    else
        $in_array_func = 'fake_in_array';
 
    if($use_field_alias = isset($form['alias']))
        alias_fields();
   
    if(CHECK_REFERER == true)
        check_referer($referers);
    else
        error_log('[PHPFormMail] HTTP_REFERER checking is turned off.  Referer: ' . getenv('HTTP_REFERER') . '; Client IP: ' . getenv('REMOTE_ADDR') . ';', 0);
 
    // This is used for another variable function call
    if ((count($recipient_array) > 0) == true)
        $recipient_function = 'map_recipients';
    else
        $recipient_function = 'check_recipients';
   
    if (isset($form['recipient']))
        $form['recipient'] = $recipient_function($form['recipient']);
    if (isset($form['recipient_cc']))
        $form['recipient_cc'] = $recipient_function($form['recipient_cc']);
    if (isset($form['recipient_bcc']))
        $form['recipient_bcc'] = $recipient_function($form['recipient_bcc']);
   
    check_required();
   
    if (!$errors) {
 
        if (isset($form['sort']))
            sort_fields();
 
        if (isset($form['hidden'])) {
            // PFMA REMOVE 1
            $form['hidden'] = str_replace(' ', '', $form['hidden']);
            $form['hidden'] = explode(',', $form['hidden']);
            // PFMA ADD $form['hidden'] = array_map('trim', $form['hidden']);
        }
 
        if (send_mail()) {
            if (isset($form['redirect'])) {
                if (isset($form['redirect_values']))
                    header('Location: ' . $form['redirect'] . '?' . getenv('QUERY_STRING') . "\r\n");
                else
                    header('Location: ' . $form['redirect'] . "\r\n");
            } else {
                if (!isset($form['title']))
                    $form['title'] = 'PHPFormMail - Form Results';
                $output = "<h1>The following information has been submitted:</h1>\n";
                reset($form);
                while (list($key,$val) = each($form)) {
                    if ((!$in_array_func($key,$invis_array)) && ((isset($form['print_blank_fields'])) || ($val))) {
                        $output .= '<div class="field"><b>';
                        if(($use_field_alias) && ($form['alias_method'] != 'email'))
                            $output .= htmlspecialchars($fieldname_lookup[$key]);
                        else
                            $output .= htmlspecialchars($key);
                        if ((isset($form['hidden'])) && ($in_array_func($key,$form['hidden'])))
                            $output .= ":</b> <i>(hidden)</i></div>\n";
                        else
                            $output .= ':</b> ' . nl2br(htmlspecialchars(stripslashes($val))) . "</div>\n";
                    }
                }
                if (isset($form['return_link_url']) && isset($form['return_link_title']))
                    $output .= '<div class="returnlink"><a href="' . $form["return_link_url"] . '">'. $form["return_link_title"] . "</a></div>\n";
                output_html($output);
            }
        }
    }
} else {
    $errors[] = '0|Nothing was sent by a form. (No data was sent by POST or GET method.)  There is nothing to process here.';
    error_log('[PHPFormMail] No data sent by POST or GET method. (' . getenv('HTTP_REFERER') . ')', 0);
}
 
if (count($errors) > 0)
    error();
 
?>
 
 
  1.  
  2. <?PHP
  3. define('VERSION','Classic v1.07.2');
  4. define('MANUAL','http://www.boaddrink.com/projects/phpformmail/readme.php');
  5. define('CHECK_REFERER', true);
  6.  
  7. // +------------------------------------------------------------------------+
  8. // | PHPFormMail                                                            |
  9. // | Copyright (c) 1999 Andrew Riley (webmaster@boaddrink.com)              |
  10. // |                                                                        |
  11. // | This program is free software; you can redistribute it and/or          |
  12. // | modify it under the terms of the GNU General Public License            |
  13. // | as published by the Free Software Foundation; either version 2         |
  14. // | of the License, or (at your option) any later version.                 |
  15. // |                                                                        |
  16. // | This program is distributed in the hope that it will be useful,        |
  17. // | but WITHOUT ANY WARRANTY; without even the implied warranty of         |
  18. // | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.   See the     |
  19. // | GNU General Public License for more details.                           |
  20. // |                                                                        |
  21. // | You should have received a copy of the GNU General Public License      |
  22. // | along with this program; if not, write to the Free Software            |
  23. // | Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111-1307, |
  24. // | USA.                                                                   |
  25. // |                                                                        |
  26. // +------------------------------------------------------------------------+
  27. // |                                                                        |
  28. // | If you run into any problems, pleas read the readme_formmail.txt.      |
  29. // | If that does not help, check out http://www.boaddrink.com.             |
  30. // |                                                                        |
  31. // | For more info, please visit http://www.boaddrink.com or read the       |
  32. // | readme file included.                                                  |
  33. // +------------------------------------------------------------------------+
  34. // |                                                                        |
  35. // | Value array fix by: Konrad Maqestieau                                  |
  36. // | check_recipients reset() fix by: Don                                   |
  37. // | servertime_offset code by: desolate                                    |
  38. // |                                                                        |
  39. // +------------------------------------------------------------------------+
  40.  
  41. // To change the address the e-mail comes from use define('FROM', 'Example Name <email@example.com>');
  42. define('FROM', null);
  43.  
  44. $referers = array('www.venetianinn.net', 'venetianinn.net', 'www.venetianinn.com', 'venetianinn.com');
  45.  
  46. // $recipient_array format is $recipient_array = array('sometext'=>'email@example.com','asdf'=>'email2@example.com');
  47. $recipient_array = array();
  48.  
  49. $valid_env = array('REMOTE_HOST', 'REMOTE_ADDR', 'REMOTE_USER', 'HTTP_USER_AGENT');
  50.  
  51. // +------------------------------------------------------------------------+
  52. // | STOP EDITING! The only two required variables that need to be updated  |
  53. // | are $referers and $valid_env                                           |
  54. // +------------------------------------------------------------------------+
  55.  
  56. $errors = $fieldname_lookup = array();
  57. $invis_array = array('recipient','subject','required','redirect',
  58.              'print_blank_fields','env_report','sort',
  59.              'missing_fields_redirect','title','bgcolor',
  60.              'text_color','link_color','alink_color',
  61.              'vlink_color','background','subject','title',
  62.              'link','css','return_link_title',
  63.              'return_link_url','recipient_cc','recipient_bcc',
  64.                  'priority','redirect_values','hidden','alias',
  65.          'mail_newline', 'gmt_offset', 'alias_method',
  66.          'subject_prefix');
  67.  
  68. /****************************************************************
  69.  * fake_in_array() is only used in PHP3 since PHP4 has a native *
  70.  * in_array.  Depending on what version of PHP you are running  *
  71.  * the script will determine what is the best function to run   *
  72.  * --- THER IS NO LONGER ANY REASON TO DELETE THIS FUNCTION --- *
  73.  * Function renamed in 1.04.0                   *
  74.  ****************************************************************/
  75.  
  76. function fake_in_array($needle, $haystack)
  77. {
  78.     $found = false;
  79.     while (list($key,$val) = each ($haystack)) {
  80.         if ($needle == $val)
  81.             $found = true;
  82.     }
  83.     return $found;
  84. }
  85.  
  86. /****************************************************************
  87.  * check_referer() breaks up the enviromental variable      *
  88.  * HTTP_REFERER by "/" and then checks to see if the second *
  89.  * member of the array (from the explode) matches any of the    *
  90.  * domains listed in the $referers array (declaired at top) *
  91.  ****************************************************************/
  92.  
  93. function check_referer($referers)
  94. {
  95.     global $errors;
  96.     if (count($referers)) {
  97.         if (getenv('HTTP_REFERER')) {
  98.             $temp = explode('/', getenv('HTTP_REFERER'));
  99.             $found = false;
  100.             while (list(,$stored_referer) = each($referers)) {
  101.                 if (eregi('^' . $stored_referer . '$', $temp[2]))
  102.                     $found = true;
  103.             }
  104.             if (!$found) {
  105.                 $errors[] = '1|You are coming from an unauthorized domain.  Please read the manual section titled &quot;<a href="' . MANUAL . '#setting_up" target="_blank">Setting Up the PHPFormMail Script</a>&quot;.';
  106.                 error_log('[PHPFormMail] Illegal Referer. (' . getenv('HTTP_REFERER') . ')', 0);
  107.             }
  108.             return $found;
  109.         } else {
  110.             $errors[] = '0|Sorry, but I cannot figure out who sent you here.  Your browser is not sending an HTTP_REFERER.  This could be caused by a firewall or browser that removes the HTTP_REFERER from each HTTP request you submit.';
  111.             error_log('[PHPFormMail] HTTP_REFERER not defined. Browser: ' . getenv('HTTP_USER_AGENT') . '; Client IP: ' . getenv('REMOTE_ADDR') . '; Request Method: ' . getenv('REQUEST_METHOD') . ';', 0);
  112.             return false;
  113.         }
  114.     } else {
  115.         $errors[] = '1|There are no referers defined.  All submissions will be denied.  Please read the manual section titled &quot;<a href="' . MANUAL . '#setting_up" target="_blank">Setting Up the PHPFormMail Script</a>&quot;.';
  116.         error_log('[PHPFormMail] You have no referers defined.  All submissions will be denied.', 0);
  117.         return false;
  118.     }
  119. }
  120.  
  121. /****************************************************************
  122.  * check_recipients() breaks up the recipents e-mail addresses  *
  123.  * and then crossrefrences the domains that are legal referers  *
  124.  * Function added in 1.3.1                                      *
  125.  ****************************************************************/
  126.  
  127. function check_recipients($recipient_list)
  128. {
  129.     global $errors, $referers;
  130.     $recipients_ok = true;
  131.     $recipient_list = explode(',', $recipient_list);
  132.     while (list(,$recipient) = each($recipient_list)) {
  133.         $recipient_domain = false;
  134.         $recipient = trim($recipient);
  135.         reset($referers);
  136.         while ((list(,$stored_domain) = each($referers)) && ($recipient_domain == false)) {
  137.             if (eregi('^[_\.a-z0-9-]*@' . $stored_domain . '$', $recipient))
  138.                 $recipient_domain = true;
  139.         }
  140.         if ($recipient_domain == false) {
  141.             $recipients_ok = false;
  142.             error_log('[PHPFormMail] Illegal Recipient: ' . $recipient . ' from ' . getenv('HTTP_REFERER'), 0);
  143.         }
  144.     }
  145.     if (!$recipients_ok)
  146.         $errors[] = '1|You are trying to send mail to a domain that is not in the allowed recipients list.   Please read the manual section titled &quot;<a href="' . MANUAL . '#setting_up" target="_blank">Setting Up the PHPFormMail Script</a>&quot;.';
  147.     return join(',', $recipient_list);
  148. }
  149.  
  150. /****************************************************************
  151.  * map_recipients() takes the array and maps them to the proper *
  152.  * e-mail addresses from $recipient_array.  If this function is *
  153.  * called then the e-mail addresses are not checked against the *
  154.  * referer array.                                               *
  155.  * Function added in 1.7.0                                      *
  156.  ****************************************************************/
  157.  
  158. function map_recipients($recipient_list)
  159. {
  160.     global $errors, $recipient_array;
  161.     $recipients_ok = true;
  162.     $recipient_list = explode(',',$recipient_list);
  163.     while (list(,$val) = each($recipient_list)){
  164.         $val = trim($val);
  165.         if(isset($recipient_array[$val]))
  166.             $output[] = $recipient_array[$val];
  167.         else
  168.             $recipients_ok = false;
  169.     }
  170.     if (!$recipients_ok)
  171.         $errors[] = '1|You are trying to send mail to an address that is not listed in the recipient array.';
  172.     if (isset($output))
  173.         return join(',', $output);
  174.     else
  175.         return null;
  176. }
  177.  
  178. /****************************************************************
  179.  * decode_vars() is used to assign all of the variables passed  *
  180.  * into the form to a generic variable.  Allthough there are    *
  181.  * two official form actions, POST and GET, I decided to use    *
  182.  * this variable method so if more actions are invented, I  *
  183.  * wouldn't have to change anything.                *
  184.  *                              *
  185.  * In the first line, the request methood is assigned to    *
  186.  * $request with HTTP_ and _VARS appended to it.        *
  187.  * In the second line uses PHPs variable variable.      *
  188.  * It's basically addressing the variable $HTTP_POST_VARS or    *
  189.  * $HTTP_GET_VARS and returning that.  Read more about      *
  190.  * variable variables in the PHP documentation.         *
  191.  ****************************************************************/
  192.  
  193. function decode_vars()
  194. {
  195.     if (isset($_REQUEST))
  196.         $request = '_' . getenv('REQUEST_METHOD');
  197.     else
  198.         $request = 'HTTP_' . getenv('REQUEST_METHOD') . '_VARS';
  199.     global $$request;
  200.     if (count($$request) > 0) {
  201.         while (list($key, $val) = each($$request)) {
  202.             if (is_array($val))
  203.                 $val = implode(', ',$val);
  204.             $output[$key] = stripslashes($val);
  205.         }
  206.         return $output;
  207.     } else
  208.         return array();
  209. }
  210.  
  211.  
  212. /****************************************************************
  213.  * error() is our generic error function.           *
  214.  * When called, it checks for errors in the $errors array and   *
  215.  * depending on $form["missing_fields_redirect"] will either    *
  216.  * print out the errors by calling the function output_html()   *
  217.  * or it will redirect to the location specified in     *
  218.  * $form["missing_fields_redirect"].                *
  219.  ****************************************************************/
  220.  
  221. function error()
  222. {
  223.     global $form, $natural_form, $errors;
  224.     if (isset($form['missing_fields_redirect'])) {
  225.         if (isset($form['redirect_values']))
  226.             header('Location: ' . $form['missing_fields_redirect'] . '?' . getenv('QUERY_STRING') . "\r\n");
  227.         else
  228.             header('Location: ' . $form['missing_fields_redirect'] . "\r\n");
  229.     } else {
  230.         if(!isset($form['title']))
  231.             $form['title'] = 'PHPFormMail - Error';
  232.         $output = "<h1>The following errors were found:</h1>\n<ul>\n";
  233.         $crit_error = 0;
  234.         while (list(,$val) = each ($errors)) {
  235.             list($crit,$message) = explode('|',$val);
  236.             $output .= '  <li>' . $message . "</li>\n";
  237.             if ($crit == 1)
  238.                 $crit_error = 1;
  239.         }
  240.         $output .= "</ul>\n";
  241.         if ($crit_error == 1)
  242.             $output .=  "<div class=\"crit\">PHPFormMail has experienced errors that must be fixed by the webmaster. Mail will NOT be sent until these issues are resolved.  Once these issues are resolved, you will have to resubmit your form to PHPFormMail for the mail to be sent.</div><div class=\"returnlink\">Please use the <a href=\"javascript&#058; history.back();\">back</a> button to return to the site.</div>\n";
  243.         else
  244.             $output .=  "<div class=\"returnlink\">Please use the <a href=\"javascript&#058; history.back();\">back</a> button to correct these errors.</div>\n";
  245.         output_html($output);
  246.     }
  247. }
  248.  
  249. /****************************************************************
  250.  * check_required() is the function that checks all required    *
  251.  * fields to see if they are empty or match the provided regex  *
  252.  * string (regex checking added in 1.02.0).         *
  253.  *                              *
  254.  * Should a required variable be empty or not match the regex   *
  255.  * pattern, a error will be added to the global $errors array.  *
  256.  ****************************************************************/
  257.  
  258. function check_required()
  259. {
  260.     global $form, $errors, $invis_array, $fieldname_lookup;
  261.     $problem = true;
  262.     if ((!isset($form['recipient'])) && (!isset($form['recipient_bcc']))) {
  263.         $problem = false;
  264.         $errors[] = '1|There is no recipient to send this mail to.  Please read the manual section titled &quot;<a href="' . MANUAL . '#recipient" target="_blank">Form Configuration - Recipient</a>&quot;.';
  265.         error_log('[PHPFormMail] There is no recipient defined from ' . getenv('HTTP_REFERER'), 0);
  266.     }
  267.     if (isset($form['required'])) {
  268.         $required = split(',', $form['required']);
  269.         while (list(,$val) = each($required)) {
  270.             $val = trim($val);
  271.             $regex_field_name = $val . '_regex';
  272.             if ((!isset($form[$val])) || (isset($form[$val]) && (strlen($form[$val]) < 1))) {
  273.                 $problem = false;
  274.                 if (isset($fieldname_lookup[$val]))
  275.                     $field = $fieldname_lookup[$val];
  276.                 else
  277.                     $field = $val;
  278.                 $errors[] = '0|Required value (<b>' . $field . '</b>) is missing.';
  279.             } else if (isset($form[$regex_field_name])) {
  280.                 if (!eregi($form[$regex_field_name],$form[$val])) {
  281.                     $problem = false;
  282.                     $errors[] = '0|Required value (<b>' . $fieldname_lookup[$val] . '</b>) has an invalid format.';
  283.                 }
  284.                 $invis_array[] = $regex_field_name;
  285.             }
  286.         }
  287.     }
  288.     return $problem;
  289. }
  290.  
  291.  
  292. /****************************************************************
  293.  * sort_fields() is responsable for sorting all fields in $form *
  294.  * depending $form["sort"].                 *
  295.  * There are three main sort methods: alphabetic, reverse   *
  296.  * alphabetic, and user supplied.               *
  297.  *                              *
  298.  * The user supplied method is formatted "order:name,email,etc".*
  299.  * The text "order" is required and the fields are comma    *
  300.  * sepperated. ("order" is legacy from the PERL version.) If    *
  301.  * the user supplied method leaves fields out of the comma  *
  302.  * sepperated list, the remaining fields will be appended to    *
  303.  * the end of the orderd list in the order they appear in the   *
  304.  * form.                            *
  305.  * Function added in 1.02.0                 *
  306.  ****************************************************************/
  307.  
  308. function sort_fields()
  309. {
  310.     global $form;
  311.     switch ($form['sort']) {
  312.         case 'alphabetic':
  313.         case 'alpha':       ksort($form);
  314.                     break;
  315.         case 'ralphabetic':
  316.         case 'ralpha':      krsort($form);
  317.                     break;
  318.         default:        if ($col = strpos($form['sort'],':')) {
  319.                         $form['sort'] = substr($form['sort'],($col + 1));
  320.                         $temp_sort_arr = explode(',', $form['sort']);
  321.                         for($x = 0; $x < count($temp_sort_arr); $x++) {
  322.                             $out[$temp_sort_arr[$x]] = $form[$temp_sort_arr[$x]];
  323.                             unset($form[$temp_sort_arr[$x]]);
  324.                         }
  325.                         $form = array_merge($out,$form);
  326.                     }
  327.     }
  328.     return true;
  329. }
  330.  
  331.  
  332. /****************************************************************
  333.  * alias_fields() creates a lookup array so we can use Aliases  *
  334.  * for the field names.  If a alias is not available, the   *
  335.  * lookup array is filled with the form field's name        *
  336.  * Function added in 1.05.0                 *
  337.  ****************************************************************/
  338.  
  339. function alias_fields()
  340. {
  341.     global $form, $fieldname_lookup;
  342.     while (list($key,) = each($form)) {
  343.         $fieldname_lookup[$key] = $key;
  344.     }
  345.     reset($form);
  346.     if (isset($form['alias'])) {
  347.         $aliases = explode(',', $form['alias']);
  348.         while (list(,$val) = each($aliases)) {
  349.             $temp = explode('=', $val);
  350.             $fieldname_lookup[trim($temp[0])] = trim($temp[1]);
  351.         }
  352.     }
  353.     return true;
  354. }
  355.  
  356.  
  357. /****************************************************************
  358.  * send_mail() the function that parses the data into SMTP  *
  359.  * format and sends the e-mail.                 *
  360.  ****************************************************************/
  361.  
  362. function send_mail()
  363. {
  364.     global $form, $invis_array, $valid_env, $fieldname_lookup, $errors;
  365.    
  366.     $email_replace_array = "\r|\n|to:|cc:|bcc:";
  367.    
  368.     if (!isset($form['subject']))
  369.             $form['subject'] = 'WWW Form Submission';
  370.     if (isset($form['subject_prefix']))
  371.             $form['subject'] = $form['subject_prefix'] . $form['subject'];
  372.     if (!isset($form['email']))
  373.             $form['email'] = 'email@example.com';
  374.    
  375.     switch ($form['mail_newline']) {
  376.         case 2:     $mail_newline = "\r";
  377.                 break;
  378.         case 3:     $mail_newline = "\r\n";
  379.                 break;
  380.         default:    $mail_newline = "\n";
  381.     }
  382.    
  383.     if (isset($form['gmt_offset']) && ereg('^(\-|\+)?([0-9]{1}|(1{1}[0-2]{1}))$', $form['gmt_offset'])) {
  384.         $mkseconds = mktime(gmdate('H') + $form['gmt_offset']);
  385.         $mail_date = gmdate('F jS, Y', $mkseconds) . ' at ' . gmdate('h:iA', $mkseconds) . ' (GMT ' . $form['gmt_offset'] . ').';
  386.     } else
  387.         $mail_date = date('F jS, Y') . ' at ' . date('h:iA (T).');
  388.    
  389.     if (isset($form['realname']))
  390.         $realname = eregi_replace($email_replace_array,'',$form['realname']);
  391.     elseif (isset($form['firstname']) || isset($form['lastname']))
  392.         $realname = eregi_replace($email_replace_array,'',trim($form['firstname'] . ' ' . $form['lastname']));
  393.  
  394.     $mailbody = 'Below is the result of your feedback form.  It was submitted by' . $mail_newline;
  395.     if (isset($realname))
  396.         $mailbody.= $realname . ' (' . $form['email'] . ') on ' . $mail_date . $mail_newline . $mail_newline;
  397.     else
  398.         $mailbody.= $form['email'] . ' on ' . $mail_date . $mail_newline . $mail_newline;
  399.  
  400.     reset($form);
  401.    
  402.     while (list($key,$val) = each($form)) {
  403.         if ((!in_array($key,$invis_array)) && ((isset($form['print_blank_fields'])) || ($val))) {
  404.                 if(($form['alias_method'] == 'email') || ($form['alias_method'] == 'both'))
  405.                     $mailbody .= $fieldname_lookup[$key];
  406.                 else
  407.                     $mailbody .= $key;
  408.                 $mailbody .= ': ' . $val . $mail_newline;
  409.         }
  410.     }
  411.    
  412.     if (isset($form['env_report'])) {
  413.         $temp_env_report = explode(',', $form['env_report']);
  414.         $mailbody .= $mail_newline . $mail_newline . '-------- Env Report --------' . $mail_newline;
  415.         while (list(,$val) = each($temp_env_report)) {
  416.             if (in_array($val,$valid_env))
  417.                     $mailbody .= eregi_replace($email_replace_array,'',$val) . ': ' . eregi_replace($email_replace_array,'',getenv($val)) . $mail_newline;
  418.         }
  419.     }
  420.  
  421.     if (!isset($form['recipient']))
  422.         $form['recipient'] = '';
  423.  
  424.     // Append lines to $mail_header that you wish to be
  425.     // added to the headers of the e-mail. (SMTP Format
  426.     // with newline char ending each line)
  427.  
  428.     $mail_header = 'Return-Path: ' . eregi_replace($email_replace_array,'',$return_path) . $mail_newline;
  429.     if (FROM != null)
  430.         $mail_header .= 'From: ' . FROM . $mail_newline;
  431.     $mail_header .= 'Reply-to: ';
  432.     if (isset($realname))
  433.         $mail_header .= $realname . ' <' . eregi_replace($email_replace_array,'',$form['email']) . '>' . $mail_newline;
  434.     else
  435.         $mail_header .= eregi_replace($email_replace_array,'',$form['email']) . $mail_newline;
  436.     if (isset($form['recipient_cc']))
  437.         $mail_header .= 'Cc: ' . eregi_replace($email_replace_array,'',$form['recipient_cc']) . $mail_newline;
  438.     if (isset($form['recipient_bcc']))
  439.         $mail_header .= 'Bcc: ' . eregi_replace($email_replace_array,'',$form['recipient_bcc']) . $mail_newline;
  440.     if (isset($form['priority']))
  441.         $mail_header .= 'X-Priority: ' . ereg_replace($email_replace_array,'',$form['priority']) . $mail_newline;
  442.     else
  443.         $mail_header .= 'X-Priority: 3' . $mail_newline;
  444.     $mail_header .= 'X-Mailer: PHPFormMail ' . VERSION . ' (http://www.boaddrink.com)' . $mail_newline;
  445.     $mail_header .= 'X-Sender-IP: ' . eregi_replace($email_replace_array,'',getenv('REMOTE_ADDR')) . $mail_newline;
  446.     $mail_header .= 'X-Referer: ' . eregi_replace($email_replace_array,'',getenv('HTTP_REFERER')) . $mail_newline;
  447.    
  448.     $form['subject'] = eregi_replace($email_replace_array,'',$form['subject']);
  449.    
  450.     if (eregi("MIME-|Content-|boundary", $mail_header . $mailbody . $form['subject']) == 0) {
  451.         $mail_header .= 'Content-Type: text/plain; charset=utf-8' . $mail_newline;
  452.         $mail_status = mail(eregi_replace($email_replace_array,'',$form['recipient']), $form['subject'], $mailbody, $mail_header);
  453.         if (!$mail_status) {
  454.             $errors[] = '1|Message could not be sent due to an error while trying to send the mail.';
  455.             error_log('[PHPFormMail] Mail could not be sent due to an error while trying to send the mail.');
  456.         } else {
  457.             error_log('[PHPFormMail] Normal e-mail sent from IP ' . getenv('REMOTE_ADDR'));
  458.         }
  459.     } else {
  460.             $mail_status = true;
  461.             error_log('[PHPFormMail] Injection characters found from IP ' . getenv('REMOTE_ADDR') . '. Silently dropped');
  462.     }
  463.     return $mail_status;
  464. }
  465.  
  466.  
  467. /****************************************************************
  468.  * output_html() is used to output all HTML to the browser. *
  469.  * This function is called if there is an error or for the  *
  470.  * "Thank You" page if neither are declaired as redirects.  *
  471.  *                              *
  472.  * While called output_html() it actually outputs valid XHTML   *
  473.  * 1.0 documents.                       *
  474.  * Function added in 1.02.0                 *
  475.  ****************************************************************/
  476.  
  477. function output_html($body)
  478. {
  479.     global $form;
  480.    
  481.     $bgcolor    = isset($form['bgcolor']) ? ('background-color: ' . htmlspecialchars($form['bgcolor']) . ';') : ('background-color: #FFF;');
  482.     $background = isset($form['background']) ? ('background-image: url(' . htmlspecialchars($form['background']) . ');') : NULL;
  483.     $text_color = isset($form['text_color']) ? ('color: ' . htmlspecialchars($form['text_color']) . ';') : ('color: #000;');
  484.     $link_color = isset($form['link_color']) ? ('color: ' . htmlspecialchars($form['link_color']) . ';') : NULL;
  485.     $alink_color    = isset($form['alink_color']) ? ('color: ' . htmlspecialchars($form['alink_color']) . ';') : NULL;
  486.     $vlink_color    = isset($form['vlink_color']) ? ('color: ' . htmlspecialchars($form['vlink_color']) . ';') : NULL;
  487.    
  488.     print "<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Transitional//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd\">\n";
  489.     print "<html xmlns=\"http://www.w3.org/1999/xhtml\" xml:lang=\"en-US\" lang=\"en-US\">\n";
  490.     print "<head>\n";
  491.     print "  <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\" />\n";
  492.     print "  <meta name=\"robots\" content=\"noindex,nofollow\" />\n";
  493.     print "  <title>" . htmlspecialchars($form['title']) . "</title>\n";
  494.     print "  <style type=\"text/css\">\n";
  495.     print "    BODY {" . trim($bgcolor . ' ' . $text_color . ' ' . $background) . "}\n";
  496.     if (isset($link_color))
  497.         print "    A {" . $link_color . "}\n";
  498.     if (isset($alink_color))
  499.         print "    A:active {" . $alink_color . "}\n";
  500.     if (isset($vlink_color))
  501.         print "    A:visited {" . $vlink_color . "}\n";
  502.     print "    h1 {font-size: 14pt; font-weight: bold; margin-bottom: 20pt}\n";
  503.     print "    .crit {font-size: 12pt; font-weight: bold; color: #F00; margin-bottom: 10pt;}\n";
  504.     print "    .returnlink {font-size: 12pt; margin-top: 20pt; margin-bottom: 20pt;}\n";
  505.     print "    .validbutton {margin-top: 20pt; margin-bottom: 20pt;}\n";
  506.     print "  </style>\n";
  507.     if (isset($form['css']))
  508.         print "  <link rel=\"stylesheet\" href=\"" . htmlspecialchars($form['css']) . "\">\n";
  509.     print "</head>\n\n";
  510.     print "<body>\n";
  511.     print "<!-- PHPFormMail from http://www.boaddrink.com -->\n";
  512.     print $body;
  513.     print "<div class=\"validbutton\"><a href=\"http://validator.w3.org/check/referer\" target=\"_blank\"><img src=\"http://www.w3.org/Icons/valid-xhtml10\" style=\"border:0;width:88px;height:31px\" alt=\"Valid XHTML 1.0!\" /></a></div>\n";
  514.     print "</body>\n";
  515.     print "</html>";
  516. }
  517.  
  518.  
  519. $form = decode_vars();
  520.  
  521. if (count($form) > 0) {
  522.    
  523.     // PFMA remove if block
  524.     // Determine (based on the PHP version) if we should use the native
  525.     // PHP4 in_array or the coded fake_in_array
  526.  
  527.     if (phpversion() >= '4.0.0')
  528.         $in_array_func = 'in_array';
  529.     else
  530.         $in_array_func = 'fake_in_array';
  531.  
  532.     if($use_field_alias = isset($form['alias']))
  533.         alias_fields();
  534.    
  535.     if(CHECK_REFERER == true)
  536.         check_referer($referers);
  537.     else
  538.         error_log('[PHPFormMail] HTTP_REFERER checking is turned off.  Referer: ' . getenv('HTTP_REFERER') . '; Client IP: ' . getenv('REMOTE_ADDR') . ';', 0);
  539.  
  540.     // This is used for another variable function call
  541.     if ((count($recipient_array) > 0) == true)
  542.         $recipient_function = 'map_recipients';
  543.     else
  544.         $recipient_function = 'check_recipients';
  545.    
  546.     if (isset($form['recipient']))
  547.         $form['recipient'] = $recipient_function($form['recipient']);
  548.     if (isset($form['recipient_cc']))
  549.         $form['recipient_cc'] = $recipient_function($form['recipient_cc']);
  550.     if (isset($form['recipient_bcc']))
  551.         $form['recipient_bcc'] = $recipient_function($form['recipient_bcc']);
  552.    
  553.     check_required();
  554.    
  555.     if (!$errors) {
  556.  
  557.         if (isset($form['sort']))
  558.             sort_fields();
  559.  
  560.         if (isset($form['hidden'])) {
  561.             // PFMA REMOVE 1
  562.             $form['hidden'] = str_replace(' ', '', $form['hidden']);
  563.             $form['hidden'] = explode(',', $form['hidden']);
  564.             // PFMA ADD $form['hidden'] = array_map('trim', $form['hidden']);
  565.         }
  566.  
  567.         if (send_mail()) {
  568.             if (isset($form['redirect'])) {
  569.                 if (isset($form['redirect_values']))
  570.                     header('Location: ' . $form['redirect'] . '?' . getenv('QUERY_STRING') . "\r\n");
  571.                 else
  572.                     header('Location: ' . $form['redirect'] . "\r\n");
  573.             } else {
  574.                 if (!isset($form['title']))
  575.                     $form['title'] = 'PHPFormMail - Form Results';
  576.                 $output = "<h1>The following information has been submitted:</h1>\n";
  577.                 reset($form);
  578.                 while (list($key,$val) = each($form)) {
  579.                     if ((!$in_array_func($key,$invis_array)) && ((isset($form['print_blank_fields'])) || ($val))) {
  580.                         $output .= '<div class="field"><b>';
  581.                         if(($use_field_alias) && ($form['alias_method'] != 'email'))
  582.                             $output .= htmlspecialchars($fieldname_lookup[$key]);
  583.                         else
  584.                             $output .= htmlspecialchars($key);
  585.                         if ((isset($form['hidden'])) && ($in_array_func($key,$form['hidden'])))
  586.                             $output .= ":</b> <i>(hidden)</i></div>\n";
  587.                         else
  588.                             $output .= ':</b> ' . nl2br(htmlspecialchars(stripslashes($val))) . "</div>\n";
  589.                     }
  590.                 }
  591.                 if (isset($form['return_link_url']) && isset($form['return_link_title']))
  592.                     $output .= '<div class="returnlink"><a href="' . $form["return_link_url"] . '">'. $form["return_link_title"] . "</a></div>\n";
  593.                 output_html($output);
  594.             }
  595.         }
  596.     }
  597. } else {
  598.     $errors[] = '0|Nothing was sent by a form. (No data was sent by POST or GET method.)  There is nothing to process here.';
  599.     error_log('[PHPFormMail] No data sent by POST or GET method. (' . getenv('HTTP_REFERER') . ')', 0);
  600. }
  601.  
  602. if (count($errors) > 0)
  603.     error();
  604.  
  605. ?>
  606.  
  607.  


Now how do I configure to please the customer, and where do I place what and where?


Thank you,

cgfx?
  • Bogey
  • Genius
  • Genius
  • Bogey
  • Posts: 8413
  • Loc: USA

Post 3+ Months Ago

Check if this helps you any.
  • CGFX
  • Graduate
  • Graduate
  • User avatar
  • Posts: 161
  • Loc: Chicago, IL.

Post 3+ Months Ago

Bogey,

Thank you again, I can actually build nice forms in HTML or Flash even.
It's the getting them to communicate with the server is what I don't understand. All the POST and weather to send it to the Web Address, Email Address, or the CGI-BIN so the receiver can open it and read it?

cgfX
  • Bogey
  • Genius
  • Genius
  • Bogey
  • Posts: 8413
  • Loc: USA

Post 3+ Months Ago

That doesn't tell you how to create the form... that tells you how to use the PHP script. The formmail code uses the form for everything... configuration and everything else...

Post Information

  • Total Posts in this topic: 4 posts
  • Users browsing this forum: No registered users and 123 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
cron
 

© 1998-2014. Ozzu® is a registered trademark of Unmelted, LLC.