Fixed some bugs in the alliance

+Fixed a bug that permitted to create an alliance while already being in
an alliance
+Fixed a bug that permitted to create an alliance with an embassy of
level 3 or lower (or even without an embassy)
+Fixed a bug that permitted to set the max numbers of players during the
creation of an alliance, by hacking the building id passed in a post
request
+Fixed some redirect issues
This commit is contained in:
iopietro
2018-04-13 02:00:37 +02:00
parent 8aac28dbc7
commit d3ae7b8b21
4 changed files with 17 additions and 13 deletions
+13 -7
View File
@@ -182,7 +182,7 @@ class Alliance {
$database->insertAlliNotice($invite['alliance'], '<a href="spieler.php?uid=' . $session->uid . '">' . addslashes($session->username) . '</a> has rejected the invitation.'); $database->insertAlliNotice($invite['alliance'], '<a href="spieler.php?uid=' . $session->uid . '">' . addslashes($session->username) . '</a> has rejected the invitation.');
} }
} }
header("Location: build.php?id=".$get['id']); header("Location: build.php?gid=18");
exit; exit;
}else{ }else{
header("Location: banned.php"); header("Location: banned.php");
@@ -241,7 +241,7 @@ class Alliance {
if($accept_error == 1){ if($accept_error == 1){
$form->addError("ally_accept", "The alliance can contain only ".$max." members at this moment."); $form->addError("ally_accept", "The alliance can contain only ".$max." members at this moment.");
}else{ }else{
header("Location: build.php?id=" . $get['id']); header("Location: build.php?gid=18");
exit; exit;
} }
} else{ } else{
@@ -254,7 +254,7 @@ class Alliance {
Function to create an alliance Function to create an alliance
*****************************************/ *****************************************/
private function createAlliance($post) { private function createAlliance($post) {
global $form, $database, $session, $bid18, $village; global $form, $database, $session, $bid18, $building;
if($session->access != BANNED){ if($session->access != BANNED){
if(!isset($post['ally1']) || $post['ally1'] == "") { if(!isset($post['ally1']) || $post['ally1'] == "") {
$form->addError("ally1", ATAG_EMPTY); $form->addError("ally1", ATAG_EMPTY);
@@ -268,14 +268,20 @@ class Alliance {
if($database->aExist($post['ally2'], "name")) { if($database->aExist($post['ally2'], "name")) {
$form->addError("ally2", ANAME_EXIST); $form->addError("ally2", ANAME_EXIST);
} }
if($session->alliance != 0){
$form->addError("ally3", ALREADY_ALLY_MEMBER);
}
if($building->getTypeLevel(18) < 3){
$form->addError("ally4", ALLY_TOO_LOW);
}
if($form->returnErrors() != 0) { if($form->returnErrors() != 0) {
$_SESSION['errorarray'] = $form->getErrors(); $_SESSION['errorarray'] = $form->getErrors();
$_SESSION['valuearray'] = $post; $_SESSION['valuearray'] = $post;
if($building->getTypeLevel(18) > 0) header("Location: build.php?gid=18");
header("Location: build.php?id=" . $post['id']); else header("Location: dorf2.php");
exit; exit;
} else { } else {
$max = $bid18[$village->resarray['f' . $post['id']]]['attri']; $max = $bid18[$building->getTypeLevel(18)]['attri'];
$aid = $database->createAlliance($post['ally1'], $post['ally2'], $session->uid, $max); $aid = $database->createAlliance($post['ally1'], $post['ally2'], $session->uid, $max);
$database->updateUserField($session->uid, "alliance", $aid, 1); $database->updateUserField($session->uid, "alliance", $aid, 1);
$database->procAllyPop($aid); $database->procAllyPop($aid);
@@ -283,7 +289,7 @@ class Alliance {
$database->createAlliPermissions($session->uid, $aid, 'Alliance founder', '1', '1', '1', '1', '1', '1', '1', '1'); $database->createAlliPermissions($session->uid, $aid, 'Alliance founder', '1', '1', '1', '1', '1', '1', '1', '1');
// log the notice // log the notice
$database->insertAlliNotice($aid, 'The alliance has been founded by <a href="spieler.php?uid=' . $session->uid . '">' . addslashes($session->username) . '</a>.'); $database->insertAlliNotice($aid, 'The alliance has been founded by <a href="spieler.php?uid=' . $session->uid . '">' . addslashes($session->username) . '</a>.');
header("Location: build.php?id=" . $post['id']); header("Location: build.php?gid=18");
exit; exit;
} }
}else{ }else{
+2
View File
@@ -71,6 +71,8 @@ define("ATAG_EMPTY","Tag empty");
define("ANAME_EMPTY","Name empty"); define("ANAME_EMPTY","Name empty");
define("ATAG_EXIST","Tag taken"); define("ATAG_EXIST","Tag taken");
define("ANAME_EXIST","Name taken"); define("ANAME_EXIST","Name taken");
define("ALREADY_ALLY_MEMBER","You're already in an alliance");
define("ALLY_TOO_LOW", "You must have a level 3 or greater alliance");
define("NOT_OPENED_YET","Server not started yet."); define("NOT_OPENED_YET","Server not started yet.");
define("REGISTER_CLOSED","The register is closed. You can't register to this server."); define("REGISTER_CLOSED","The register is closed. You can't register to this server.");
define("NAME_EMPTY","Please insert name"); define("NAME_EMPTY","Please insert name");
+2 -2
View File
@@ -22,7 +22,7 @@ echo "
<tr> <tr>
<th>".NAME."</th> <th>".NAME."</th>
<td>".$alliance->allianceArray['name']."</td> <td>".$alliance->allianceArray['name']."</td>
<span class=\"error\">".$form->getError("ally3")."</span>
</tr> </tr>
<tr> <tr>
<td class=\"empty\" colspan=\"2\"></td> <td class=\"empty\" colspan=\"2\"></td>
@@ -36,7 +36,6 @@ echo "
?> ?>
<table cellpadding="1" cellspacing="1" id="join"> <table cellpadding="1" cellspacing="1" id="join">
<form method="post" action="build.php"> <form method="post" action="build.php">
<input type="hidden" name="id" value="<?php echo $id ?>">
<input type="hidden" name="a" value="2"> <input type="hidden" name="a" value="2">
<thead><tr> <thead><tr>
@@ -56,6 +55,7 @@ echo "
} }
?> ?>
</tr></tbody></table> </tr></tbody></table>
<p class="error"><?php echo $form->getError("ally4"); ?></p>
<?php <?php
if($alliance->gotInvite) { if($alliance->gotInvite) {
echo "<p class=\"error2\" style=\"color: #DD0000\">".$form->getError("ally_accept")."</p>"; echo "<p class=\"error2\" style=\"color: #DD0000\">".$form->getError("ally_accept")."</p>";
-4
View File
@@ -1,7 +1,6 @@
<?php if($session->access!=BANNED){ ?> <?php if($session->access!=BANNED){ ?>
<table cellpadding="1" cellspacing="1" id="found"> <table cellpadding="1" cellspacing="1" id="found">
<form method="post" action="build.php"> <form method="post" action="build.php">
<input type="hidden" name="id" value="<?php echo $id ?>">
<input type="hidden" name="ft" value="ali1"> <input type="hidden" name="ft" value="ali1">
<thead><tr> <thead><tr>
<th colspan="2"><?php echo FOUND_ALLIANCE; ?></th> <th colspan="2"><?php echo FOUND_ALLIANCE; ?></th>
@@ -11,7 +10,6 @@
<td class="tag"> <td class="tag">
<input class="text" name="ally1" value="<?php echo $form->getValue("ally1"); ?>" maxlength="15"> <input class="text" name="ally1" value="<?php echo $form->getValue("ally1"); ?>" maxlength="15">
<span class="error"><?php echo $form->getError("ally1"); ?></span> <span class="error"><?php echo $form->getError("ally1"); ?></span>
</td> </td>
</tr> </tr>
<tr> <tr>
@@ -29,7 +27,6 @@
<?php }else{ ?> <?php }else{ ?>
<table cellpadding="1" cellspacing="1" id="found"> <table cellpadding="1" cellspacing="1" id="found">
<form method="post" action="build.php"> <form method="post" action="build.php">
<input type="hidden" name="id" value="<?php echo $id ?>">
<input type="hidden" name="ft" value="ali1"> <input type="hidden" name="ft" value="ali1">
<thead><tr> <thead><tr>
<th colspan="2"><?php echo FOUND_ALLIANCE; ?></th> <th colspan="2"><?php echo FOUND_ALLIANCE; ?></th>
@@ -39,7 +36,6 @@
<td class="tag"> <td class="tag">
<input class="text" name="ally1" disabled="disabled" value="<?php echo $form->getValue("ally1"); ?>" maxlength="8"> <input class="text" name="ally1" disabled="disabled" value="<?php echo $form->getValue("ally1"); ?>" maxlength="8">
<span class="error"><?php echo $form->getError("ally1"); ?></span> <span class="error"><?php echo $form->getError("ally1"); ?></span>
</td> </td>
</tr> </tr>
<tr> <tr>